Sophos XG vs WatchGuard Firebox comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 10, 2022
 

Categories and Ranking

Fortinet FortiGate
Sponsored
Ranking in Firewalls
2nd
Average Rating
8.4
Number of Reviews
314
Ranking in other categories
Software Defined WAN (SD-WAN) Solutions (2nd), WAN Edge (1st)
Sophos XG
Ranking in Firewalls
7th
Average Rating
8.2
Number of Reviews
194
Ranking in other categories
No ranking in other categories
WatchGuard Firebox
Ranking in Firewalls
13th
Average Rating
8.4
Number of Reviews
83
Ranking in other categories
Unified Threat Management (UTM) (4th)
 

Mindshare comparison

As of July 2024, in the Firewalls category, the mindshare of Fortinet FortiGate is 22.6%, up from 18.8% compared to the previous year. The mindshare of Sophos XG is 13.3%, up from 9.3% compared to the previous year. The mindshare of WatchGuard Firebox is 3.4%, up from 2.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Firewalls
Unique Categories:
Software Defined WAN (SD-WAN) Solutions
19.7%
WAN Edge
21.4%
No other categories found
Unified Threat Management (UTM)
23.4%
 

Q&A Highlights

it_user1397058 - PeerSpot reviewer
Jan 04, 2021
 

Featured Reviews

FirasHamdan - PeerSpot reviewer
Apr 13, 2023
Reliable with lots of features and good security
We primarily use the solution for security purposes and for UTM web profile applications There are a variety of features on offer.  It helps protect endpoints.  The wireless control is helpful. It is scalable and extends well. The solution is stable and reliable. Technical support is helpful and…
SF
May 23, 2019
Offers a high level of visibility of what's happening on your network or on your client machines
There was a big issue with the Cyberoam and with the SG units as well, i.e. the previous Sophos UTM model. With Sophos XG, you get the chance to block what sites operate on SSL or that operate with HTTPS, without the need of extracting and distributing a certificate. On older Cyberoam and Sophos SG old versions, if you wanted to block something like YouTube or Facebook or any other websites that operate with HTTPS, you had to extract the certificate. Then you had to export that certificate. Then you had to re-import that certificate in all the user browsers. The only problem was if you needed to use an active directory where those certificates would be automatically thrown into the user browsers once they logged in to the domain. For a scenario like mine where you don't have a group policy, it is a disaster and ends up with you setting the rules to block certain websites with HTTPS on the firewall, even while they are not being blocked so that the user will still have access to them. This problem is now 100% sorted out with Sophos XG. Now you can actually block whatever you want, whether it's using HTTPS or HTTP keys from the firewall without the need for extracting certificates. That's a major improvement. That problem with the HTTPS settings was a huge issue. I know other people must be enjoying that it's sorted out now. It was a serious and major issue for Sophos. The only issue that Sophos XG now needs to improve is the product's reporting capabilities.
MS
Jan 12, 2023
It's easy to connect to the VPN and allows remote work
Our primary use cases for WatchGuard Firebox are routing and VPN, including the integrated firewall. We do not use the SSO system or any other router features WatchGuard Firebox was able to help our organization during the pandemic as we were obligated to work from home. We were working remotely,…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The technical support is great."
"The user interface (UI) is very, very good."
"The GUI is good."
"The features that I have found most valuable are the SD-WAN and their IP4 policy."
"The solution is extremely reliable."
"FortiGate improved our security. It's one of the best hardware firewalls."
"The pricing is great and very reasonable."
"It's an easy solution to set up."
"We are able to trace any user and pinpoint any vulnerability or any malicious software. We are able to synchronize between the local and active directories so we can catch users easily through their login names and IDs."
"One of the most valuable features is the VPN."
"Some of the most valuable features are filtering and application control. The DDoS detection also shows traffic jamming and traffic shaping."
"The most significant aspect is the protection it offers."
"We find it easy to use. Its internal configuration is very easy. It is not complicated in terms of use and configuration. It has been fairly stable, and it is also scalable."
"In my experience, the solution was easy to use, has lots of features, and is easy to configure."
"The solution comes with a common bundle which comprises all the feature."
"One feature of Sophos XG that I found incredibly beneficial for threat prevention is its endpoint protection."
"All of the features have been valuable. There's nothing on my M270 that I'm not using. If you have remote access, you can see how many users are coming from the outside world to be connected to the systems, through the virus systems that we have behind the firewall, in order to gain access to their files and do their work. We can also see how long they stay online and whether these connections are closed forcefully or for any other reasons, such as a glitch or some kind of misbehavior, to see if internet traffic is optimized and if that particular traffic is under company policies, concerning which websites were visited."
"Because we bought two firewalls... we need a central place to manage the policies and deploy them to both devices. It's good that it provides a system management console that is able to manipulate and manage policies in one place and deploy them to different locations."
"I could still keep the data rates really high, up near the two gigahertz data speeds, without compromise on the security perimeters being acted simultaneously."
"I like that this product has very few issues."
"It saves us time in the respect that we now have the template built for it so we can get in and get it done. We've had much less problem supporting Voice over IP technologies from different companies. Because our client base has grown over the years, we're probably saving 20 to 30 man-hours a month now that we've got this on a good stable level."
"As a whole, it has a very low requirement for ongoing interaction. It's very self-sufficient. If properly patched, it has very high reliability. The total cost of ownership once deployed is very low."
"HostWatch makes it so I can see, in real-time, activity in the event that there is something weird happening on the network. This simplifies my job."
"​Efficient to setup, run, and maintain. Saving man hours and cost in the process."
 

Cons

"There are just some services that aren't available. For example, the Ethernet or point-to-point protocols. They could add these services to their product offering - especially services for ISPs."
"This product could be improved with Active directory integration and better handling in IPsec and GRE Tunnels."
"The integration with third-party tools may be something that they should work on."
"Some of the web policy reports could be improved."
"I would like to see improvements in the product's application rules."
"The solution could have licensing fees reduced in the future."
"We would like to see a better training platform implemented."
"FortiGate can improve its token system, as it requires a purchase before use."
"The product's technical support services could be better."
"In the next release, I would like to see improvements to simplify the interface and more policy deployments."
"The uploading and downloading of reports should be included."
"It would be better if they made their own hardware like Palo Alto and Fortinet. They use their own ASICs and claim it is more secure."
"The SD-WAN capability is not as good as it is in FortiGate, and is something that should be improved."
"While it is a secure solution, I believe it could be improved."
"The response time could stand improvement."
"I can't use the product's application control feature, making it a disadvantage of the solution where improvements are required."
"The solution can improve by adding a feature to tag a MAC address of a computer system in the policy and more IP configuration settings."
"The VPN aspect of the WatchGuard Firebox is an area that could potentially benefit from improvement. We encountered difficulties while attempting to integrate Windows 11 laptops into the system, which resulted in unreliable connections. After some research, we discovered that this was primarily due to compatibility issues with Windows 11 and required a patch. However, it was still a challenge as it seemed that even when we tried to keep the laptops on Windows 10, they still exhibited the same issues as Windows 11 machines. Despite WatchGuard attributing the problem to Microsoft, we were eventually able to find a solution and all the machines are now functioning seamlessly."
"One area for improvement could be making the interface even more user-friendly."
"I would like to see more simplified management of the firewall... It's a complicated system to use."
"This solution needs the option to add an external hard drive."
"I would like to see more training become available for us."
"The few issues that we have had, such as not knowing where to go, they have been answered quickly."
"Reporting is something you've got to set up separately. It's one of those things that you've got to put some time into. One of the options is to set up a local report server, which is what I did. It's not great. It's okay... Some of the stuff is a little complicated to get up and running. Once you do, it becomes very user-friendly and easy to work with, but I find there are some implementation headaches with some of their stuff."
 

Pricing and Cost Advice

"Its price is reasonable. They have a clear pricing policy. It is not complicated by the number of VPN users at a time. We know what the price is. The yearly subscription for the security license is rather high, but it is all included for whatever number of users you have and the kind of functions you need."
"Our licensing costs are on a yearly basis."
"Fortinet FortiGate is expensive."
"The price is fair for what we get with FortiGate."
"Setup costs and pricing depends on many variables, but it's mostly affordable."
"It's very affordable."
"The beauty is the price performance ratio is great with FortiGate. It provides all the features we needed and the price is comparable with others' firewalls. The price is quite competitive with the firewalls with similar features."
"Easy to understand licensing requirements."
"The price of the solution is reasonable when comparing it to other solutions."
"Over the last two years of the COVID-19 crises, most users required an SSL VPN license, something for which SonicWall charges but which Sophos offers for free."
"Sophos XG can be considered as an averagely-priced tool in the market."
"The price is not reasonable."
"We bought the three-year license, and there are no additional costs."
"Sophos XG isn't expensive compared to Check Point."
"Sophos XG is not an expensive solution. If you are willing to pay more, then there is the Check Point firewall which is the best out of all the vendors."
"The price is good and licensing fees are billed on a yearly basis."
"WatchGuard offers competitive pricing with attractive margins, benefiting both the company and its partners."
"The price is so small that I don't pay attention to it anymore. I think we pay a few thousand dollars for two to three years, so about $100 per month. That's for all of our users. There is an additional cost if we want to go with a deeper licensing model, but we just pay for antivirus, IPS, and main product support."
"The price of the WatchGuard Firebox is reasonable."
"Each one, for the primary unit, was $8,600 and the High Availability unit was $2,000. That's with three years of subscription and support and the Total Security Suite."
"Cheap."
"The cost was somewhere in the vicinity of $2,000 to $3,000 for each one..."
"They license it. When we buy it, we buy it with a three-year license. That's the most cost-effective way to do it. So, if you're going to buy it, then buy it with the three-year licensing."
"The licensing can be a one-time purchase unless you need the extra services for example twenty-four seven support."
report
Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
15%
Manufacturing Company
6%
Comms Service Provider
6%
Computer Software Company
17%
Comms Service Provider
7%
Manufacturing Company
7%
Government
6%
Computer Software Company
18%
Comms Service Provider
8%
Government
6%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the better NGFW: Fortinet Fortigate or Cisco Firepower?
When you compare these firewalls you can identify them with different features, advantages, practices and usage a...
What is the biggest difference between Sophos XG and FortiGate?
From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know...
What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite ...
Which is better - Palo Alto Networks NG Firewalls or Sophos XG?
Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat si...
What are the main differences in features between Sophos XG and FortiGate 80F?
Hi Arvind P , The Sophos XG firewall has a number of models right from XG86 to XG135w under the 1U Desktop Form Fact...
What Is The Biggest Difference Between Sophos UTM and Sophos XG?
The Sophos UTM is a UTM and Sophos XG is the NGFW. First, you must know about the difference between a UTM and NGFW. ...
What is your primary use case for WatchGuard Firebox?
We are providing our services to all WatchGuard customers in the region.
What is your primary use case for WatchGuard Firebox?
We just use it as a secondary WiFi device. We're a small office and we needed to set up a WiFi device for a few of ou...
What is your primary use case for WatchGuard Firebox?
We're a hospital and we use it for developing our incoming and outgoing policies, and we also use it for VPN.
 

Also Known As

FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
No data available
No data available
 

Overview

 

Sample Customers

1. Amazon Web Services 2. Microsoft 3. IBM 4. Cisco 5. Dell 6. HP 7. Oracle 8. Verizon 9. AT&T 10. T-Mobile 11. Sprint 12. Vodafone 13. Orange 14. BT Group 15. Telstra 16. Deutsche Telekom 17. Comcast 18. Time Warner Cable 19. CenturyLink 20. NTT Communications 21. Tata Communications 22. SoftBank 23. China Mobile 24. Singtel 25. Telus 26. Rogers Communications 27. Bell Canada 28. Telkom Indonesia 29. Telkom South Africa 30. Telmex 31. Telia Company 32. Telkom Kenya
Information Not Available
Ellips, Diecutstickers.com, Clarke Energy, NCR, Wrest Park, Homeslice Pizza, Fortessa Tableware Solutions, The Phoenix Residence
Find out what your peers are saying about Sophos XG vs. WatchGuard Firebox and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.