Try our new research platform with insights from 80,000+ expert users
it_user701427 - PeerSpot reviewer
Snr Dev Ops Engineer at a tech services company
Real User
Define your requirements and find what best suits you
Pros and Cons
  • "It allows our developers to be able to securely log into servers to deploy and manage software."
  • "It has allowed us to design a bespoke cloud space for our clients, while still having an excellent level of protection."
  • "There is absolutely no support when using AWS. If you buy the on-premise Sophos solution, you get support."
  • "It is a pretty straightforward setup, but it should be some sort of documentation that takes you step-by-step to help set it up for your VPC."

What is our primary use case?

We have quite a lot of web service hosting, either websites or hosting APIs. We use Sophos as a two-factor authentication process. So, if they are outside or working in a remote office, they will need to use the Sophos VPN, which is gotten from the Sophos UTM, then ideally they will be developers. However, they can also be BI guys, DevOps people, etc. 

Sophos UTM allows you to compartmentalize different sections or different people, having those people connect to different services.

We use it for primarily for two-factor authentication, for VPN to allow employees security access the servers and to ensure people do not access things they should not have access to.

How has it helped my organization?

  • It has allowed us to have one solution for our AWS needs.
  • It allows our developers to be able to securely log into servers to deploy and manage software.
  • It has allowed us to design a bespoke cloud space for our clients, while still having an excellent level of protection.

What is most valuable?

  • The combination of server protection
  • Seamless incorporation with AWS
  • Its VPN feature

What needs improvement?

You (currently) need to buy the Sophos software per availability, zone, and per VPC. It should offer an account-based solution.

When you buy a Sophos license, you have to buy a license for each location. We have clients in the US. We have clients in Ireland. We have clients in the UK. With GD-PI coming, the clients' data needs to stay in-house, so when you buy the Sophos license, it only works for the UK. Then, you have to buy another in the USA and another one in Ireland, then you have to have a VPN tunnel between all of them to have them talk to each other because Sophos blocks them talking to each other.

So, ideally, a multi-VPC or a multi-talented Sophos would be great because it would take away the fact that you need to build a tunnel and you have one management console for all your different locations. Instead of having three different locations with three different IP addresses and having to add users to probably two out of three, sometimes all three, having just one centralized location would be good.

Buyer's Guide
Sophos UTM
October 2025
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,837 professionals have used our research since 2012.

What do I think about the stability of the solution?

No, we did not. Backups were done daily, and its Linux backend gave us no issues.

What do I think about the scalability of the solution?

Adding new servers was seamless. Adding new users and allowing for VPN access was also fantastic.

How are customer service and support?

For the AWS version, it was atrocious. None really. For the bespoke cloud space that we designed though, they were very good.

To further clarify, there is absolutely no support when using AWS. If you buy the on-premise Sophos solution, you get support and you get all the stuff. Whereas if you are using the AWS version, you do not. So, you kind of have to research. There's something simple really which affects Sophos quite a bit during setup. 

Which solution did I use previously and why did I switch?

No, we didn't. It was our first choice and it was definitely a good one.

How was the initial setup?

For a user who hasn't done it before, it may be a bit complex but with a general understanding of networks, it was fine.

However, when you build everything up using the AWS version (setup), it actually does not work until you write it on the Sophos UTM and in the networking, you have to change the source destination check. You have to do that at the end of it, but there is nowhere in the documentation or anything where it tells you that. It was just somebody happened to find that out. It is a pretty straightforward setup, but it should be some sort of documentation that takes you step-by-step to help set it up for your VPC. There really is not that much difference setting it up in different VPCs, but there is not enough information out there. It is a very good solution that a lot of people would be using more of except you are doing different things, and you have to try and figure it out yourself. 

The support, there is none; AWS themselves, they support it the best, because they have some knowledge of it, but they do not fully support it because it is not their product. It is a third-party product.

What's my experience with pricing, setup cost, and licensing?

Licensing is a bit complicated, as it is based on products -- so define your requirements and find what best suits you, as you do not need the whole suite of software they provide.

For AWS, it is pretty straightforward. You buy it, then you have all your licenses that you need, approximately 60 or 70, or it might even be unlimited. However, that is for one margin to expand to different margins. If you have an on-premise AWS, or one of our clients wanted on-premise AWS Assistant, the problem is to build the Sophos UTM on it. We get the software, then the licensing was not explained well because when you buy the licenses, you buy five (or 50) licenses, that is for the first module. So if you expand to second module, you have to buy more licenses of that. 

Again, it is one of those things where it is not well explained. Unless you are in the United States, or you have to use Sophos, you can't contact Sophos directly. You have to use a third-party company, and they all have different ways of how they explain their licensing. So, we have clients that want the database on-premise, and we went to get the Sophos licensing system and stuff like that. It was just they were doing it a different way to who we had in Ireland, so the conformity is a bit iffy. 

It is one of those things where it is not very well explained, so it is a lot of grunt work, a lot research has to be done before you progress, and there are the pitfalls that you encounter. There are quite a few of them. Once you get it working, it is a fantastic product. It is just getting it that is the issue. 

Which other solutions did I evaluate?

We looked at a few, but I can't remember right now.

What other advice do I have?

Great product which works without issues or downtime.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user693984 - PeerSpot reviewer
Consultant at a manufacturing company with 1,001-5,000 employees
Real User
Supports all the traditional firewall components, but the install was slow due to the GUI
Pros and Cons
  • "The UTM features are reasonably strong and the patterns are updated on a regular basis"
  • "The lack of import/export functions for network and service options drives me mad."

What is our primary use case?

  • Providing the firewall to my small business office. We run it on a fanless PC and a supporting 50Mb/s VDSL connection.
  • Supports 10 devices and has 40 rules.
  • Using UTM and IPS extensively.

What is most valuable?

  • Using the Home version to help Sophos develop the XG. I have not used the earlier UTM, which colleagues have recommended.
  • The UTM features are reasonably strong and the patterns are updated on a regular basis
  • Supports all the traditional firewall components

How has it helped my organization?

Not applicable.

What needs improvement?

  • The lack of import/export functions for network and service options drives me mad.
  • No route to NULL
  • No Dshield.org integration

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No.

What do I think about the scalability of the solution?

Not applicable. 

How are customer service and technical support?

Not applicable.

Which solution did I use previously and why did I switch?

Originally Cisco 871 IOS IP Advanced Security, then Juniper SSG20, which was getting old and service contracts were too expensive.

How was the initial setup?

Slow because of GUI and lack of .csv style object import.

What about the implementation team?

In-house

What was our ROI?

Not applicable.

What's my experience with pricing, setup cost, and licensing?

If you can afford it, go for a small Check Point, as it is easier to manage.

Which other solutions did I evaluate?

Linux ipchains and modern equivalents.

What other advice do I have?

Takes awhile to build a comprehensive rule set because of the relatively slow Web GUI.

If you build, backup, restore and reconfig between the boxes.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Sophos UTM
October 2025
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
872,837 professionals have used our research since 2012.
PeerSpot user
Network Engineer II at a legal firm with 1,001-5,000 employees
Vendor
Configuring the network was the easiest part of implementation, but the internet failover needs to work better.
Pros and Cons
  • "If a computer does get infected the Sophos appliance lets us know via it's Advanced Threat Protection so we can get a much faster response time."
  • "As it stands right now, when we have an internet failure on WAN1, it takes several minutes before our WAN2 connection picks up the traffic"

What is most valuable?

  • Firewall
  • NAT
  • Intrusion prevention
  • Site-to-Site VPN
  • Web filter
  • Anti-virus

How has it helped my organization?

Before using the Sophos appliance, we consistently struggled with users clicking on things they shouldn't be. This led to virus/malware infections that seemed to propagate through the network at an alarming speed. Since we incorporated the appliance into our network, we don't have to worry as much since it does in-line virus checking, and if a computer does get infected the Sophos appliance lets us know via it's Advanced Threat Protection so we can get a much faster response time.

What needs improvement?

I wish the internet failover worked better. As it stands right now, when we have an internet failure on WAN1, it takes several minutes before our WAN2 connection picks up the traffic, with many things not working until I manually fail over to the other WAN.

For how long have I used the solution?

I've used it for seven years.

What was my experience with deployment of the solution?

Initially, we had issues configuring the web filter and getting the right policies applied to the right users. After several calls to Sophos, they were able to assist us in getting to where we wanted to be. Other than that, deployment was easy as long as you pay attention to what you are doing and have the setup guide handy for any questions you have.

What do I think about the stability of the solution?

The appliance has been very stable, only being rebooted to apply patches for security vulnerabilities, which fortunately is not very often.

What do I think about the scalability of the solution?

The UTM 220 has served our purposes very well, it has allowed us to scale up on the computing side as well as the server side with no issues at all.

How are customer service and technical support?

Customer Service:

Their customer service is fantastic.

Technical Support:

I have never had an issue go unanswered when I've had to involve Sophos technical support. Above all, it's their technical expertise that truly sets them apart from other vendors we have tried.

Which solution did I use previously and why did I switch?

We did originally try to use PFSense. The software was hard to use, and the level of technical expertise was not good. Ultimately, after several demos of both products, we decided that Astaro (at the time we purchased our original device) was the right vendor to work with. Since that time, Sophos purchased Astaro and it would appear that they kept a lot of the same people working on these devices because the transition was smooth, and the level of knowledge never faltered.

How was the initial setup?

The initial setup was very straightforward. I will say that you do need to have a certain level of knowledge to set up the more advanced functions. Configuring the network was the easiest part, and the firewall was very straightforward once you figured out exactly what rules you needed to put in place. NAT was a bit confusing to start with, but once you went through the process it was easy. Intrusion prevention was easy to set up, flip the switch to the on position and decide what rules you want to apply. Web filtering took a few calls to Sophos to set up properly, as we were trying to set up filtering policies based on Active Directory groups, and were not successful in the initial configuration, but we did finally get this implemented.

What about the implementation team?

I implemented the product in-house. The one bit of advice that I can give is to organize yourself prior to deployment. Determine what services you want to utilize in your environment, and focus your learning to those parts of the guide, this will make your deployment much easier.

What was our ROI?

Our return on investment is the fact that we are protecting the business' data, lowering administrative costs, and are better able to manage every bit of our network security.

What's my experience with pricing, setup cost, and licensing?

The licensing model is very straightforward, it's a bit pricey, but for what you get, it's well worth it.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Quality Officer at a tech services company with 10,001+ employees
Consultant
Top 20
I know I am secure against threats from the internet

What is most valuable?

The IPS and endpoint protection function.

A standard Firewall of an access router, monitoring up to OSI level 4, is unacceptable anymore these days. The endpoint protection solution is integrated, thus running along with the notification function.

How has it helped my organization?

All the necessary functions being incorporated into one solution with notifications configured, I know I am secure against threats from the internet. (Up to the limits of the solution in the constantly evolving and dangerous Internet).

What needs improvement?

  • A cleaning up function to remove unused references.
  • A dashboard to show that the various parts of the solution really do their tasks and not only have been activated or configured (e.g., From the live log of the IPS function it is difficult to understand if the solution (snort) is running or experiences a problem and has stopped working.
  • The possibility to add the sandbox (and possible future) function, paid for, to the free Home version.

For how long have I used the solution?

I've used this solution for three years.

What do I think about the stability of the solution?

Some with the IPS function (snort).

In my case, when restarting the system (because of an update), I doubt that snort starts correctly and do a manual restart of the IPS function (see my answer for 'Room for Improvement').

What do I think about the scalability of the solution?

No, I use the solution in a VMware environment with Intel Network interface cards.

How are customer service and technical support?

As a free home user, I have not used the support services up until now.

Once, I did upload an Office document that appeared to give a false positive, but never got a notification. I understand this because of the priorities that have to be given, but I would have liked to receive a (even small) reaction.

Which solution did I use previously and why did I switch?

I did take a look at other open source solutions, but found the Sophos UTM, being the best professional free for Home UTM solutions, full blown, and updated daily, to be the best solution.

How was the initial setup?

The setup wizard provided me with just enough insight into the basics of the solution -- to be able to start using the solution fully after some self-study and exploration of the various knowledge bases and forums.

What's my experience with pricing, setup cost, and licensing?

I looked at some open source variants but being able to use the best professional (free for the home version) product with regular updates -- convinced me to use the Sophos UTM solution at Home.

Which other solutions did I evaluate?

The instability and best effort service of a community of the open source solution did not give the right trust to depend on in the battle against the negative sides of the worldwide internet

What other advice do I have?

Start simple and step-by-step, and start using the product fully.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user700155 - PeerSpot reviewer
Network & System Engineer at a tech services company
Consultant
Sophos is number two on the market, and from my experience, even if there are some drawbacks, they have workaround solutions in the product.

What is most valuable?

RED remote Ethernet Device layer 2 site-to-site tunnel.

RED is a layer 2 tunnel based on SSL protocol that you can establish tunnel, with or without static public IP form provider and this is a feature you will not see among another vendor.

How has it helped my organization?

I have done hundreds of setups of this solution.

What needs improvement?

Sophos is number two on the market, and from my experience, even if there are some drawbacks, they have workaround solutions in the product. Every day, Sophos makes developments in the firmware that are free if you have a valid license.

For how long have I used the solution?

I've used this solution for five years.

What do I think about the stability of the solution?

No.

What do I think about the scalability of the solution?

No, correct sizing will fit.

How is customer service and technical support?

Fast response time. Easy management, good support.

What's my experience with pricing, setup cost, and licensing?

Pricing is competitive.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Business Owner at a tech services company with 1-10 employees
Real User
Top 20
The technical support is really good and the representatives are very responsive.

What is most valuable?

Reverse proxy, SSL VPN, web & email protection


For me, those features were most valuable from a security point of view;


• Reverse proxy is very important for shielding application frameworks.


• For VPN, we all knew that PPTP was broken and is not secure anymore. For Ipsec, you need to have opened ports, and if you are in a hotel who only has ports 80 and 443 opened, you can’t do anything.

SSLVPN is one of the solutions. Yes, you can use DirectAccess, but there are some limitations, too.

For DirectAccess, you need to have all those computers joined in one domain.

• Web & email protection is a nice feature because you have all of those controls in one dashboard. This is of course for small and maybe some mid-size companies. For larger and enterprise, it’s another story.

How has it helped my organization?

Less and faster administration, full control of traffic, and a lot of futures included in the base price.

What needs improvement?

The goal for small companies is to have one administration dashboard -- from where you can manage antivirus for computers, firewalls, IDS, IPS, mobile phones, tablets, etc.

Sophos UTM is on the right path to getting there.

For how long have I used the solution?

Sophos UTM 135 = two years.
Sophos UTM 115 = one year.

What do I think about the stability of the solution?

No problems with stability.

What do I think about the scalability of the solution?

No problems with scalability.

How are customer service and technical support?

The technical support is really good and the representatives are very responsive.

Which solution did I use previously and why did I switch?

Cisco (didn’t achieve expectations), Microsoft TMG (end of life).

How was the initial setup?

The setup is straightforward, but I suggest hiring an expert for integration. This is your first line of defense, and there is no room for mistakes.

What's my experience with pricing, setup cost, and licensing?

Sophos UTM’s are not the cheapest but they are not the most expensive. Create a checklist of what you need, and go through it with a sales representative. They will advise the right license for your company and I’m sure you can get some discount.

Which other solutions did I evaluate?

What other advice do I have?

Create a checklist with your requirements, test the solution, and if it passes everything, implement it.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user701457 - PeerSpot reviewer
IT Infrastructure Architect at a retailer with 10,001+ employees
Vendor
A firewall that allows for web filtering and application control.

How has it helped my organization?

The Sophos UTM planform has allowed us to improve or implement the following security practices:

  • Details Web filtering and user access Control
  • SaaS QoS
  • Network segmentation with firewall and IPS
  • WiFi protection
  • Web Application Proxy everywhere, inside and out
  • WAN expansion with SSL VPN and IPsec VPN over the Internet
  • Two Factor Authentication requirement for PCI compliance
  • Reduced the need for expensive MPLS deployments

What is most valuable?

The UTM/SG platform starts off with the basic functionality of being a good Firewall, adding the additional modules opens up the products set and allows for full web filtering and application control, reverse proxy, APT detection, IPS, VPNs, User portal etc.

The licensing model works very nicely to allow you to get the right protection at the right price point for the right deployment size.

In the increasingly cloud focused word the Sophos UTM’s ability to deliver Safe web access, Web Filter and Cloud Application control has gone from being a nice to have to being a must have for any size company or organization. The rich access logs it records allows you to get real insight into what your users and devices are accessing on the cloud. Native reporting is basic, but can easily be improved by adding Fastvue Sophos Reporter.

What needs improvement?

At Enterprise level the SUM (UTM Manager) needs to be updated to reflect all of the capabilities

At the Reporting level for user internet browsing the On-box Reporting is very basic and even adding the Sophos iView only give you limited improvement. Having said that, Fastvue’s Sophos Reporter provides all of this and more and integrates seamlessly with the UTM platform to unlock all of the log data’s value.

The SG platform does however not scale to a large enterprise deployment. You can deploy at scale but this is where the platform shows its age and limitations. For Large and Enterprise the better option is to go with the Sophos XG Platform.

What do I think about the stability of the solution?

Major firmware release can sometimes be buggy initially but are soon pathed and stabilized. My advice would be to sit tight for 9.x release for about a week before implementing 9.x.yyy releases often fix bug without introducing stability issues.

What do I think about the scalability of the solution?

The platform scales-out in a great way, if your deployment is basic and you do not exceed the capabilities of the current SUM. Several companies run large UTM connected networks with hundreds of site across multiple countries.

The platform scales up admirably in the format of the large tin deployments such as the SG550 or SG650 models. They are ably to handles massive throughput rates on the firewall modules but the Proxy and WAF modules cap out at a 10 000+ users or devices depending on the traffic, of course.

How was the initial setup?

For anyone with Proxy and firewall experience the setup is pretty straight forward with a wizard that will get you up and running in no time. The UTM / SG is also available in Hardware Software / Hyper-V/ AWS / ESXi / Oracle Virtual Box so you can set up a test or lab environment on almost anything to get started.

What's my experience with pricing, setup cost, and licensing?

The licensing options with virtual are great and scaling up and down is typically not an issue if you reseller is involved. Sometimes buying the hardware makes more sense than going virtual. The hardware is great and unlike the virtual licensing is unrestricted by user numbers. There are huge numbers of OS models that range from very small to very large. You will likely find a good fit for your deployment.

A great benefit is that you can migrate your Sophos SG license to a Sophos XG license in the future. You can safely Deploy on SG and later migrate over to the newer XG platform when you are ready. It offers a great feature set at a good price point.

Which other solutions did I evaluate?

Various other platforms were evaluated before choosing the Sophos SG including CheckPoint – UTM1, FortiGate, and Sophos XG (Beta – at the time). All have their own areas where they shine and should be short listed candidate for anyone looking to implement a UTM.

What other advice do I have?

Sophos is a great security partner for any organization. Investing in their suite of products gives you a good cohesive strategy for security. Adding Fastvue Sophos Reporter allows you to get better visibility into how well your UTM is protecting your environment as well as adding the ability to add real time alerts. It really adds additional features to the product without increasing the cost much and a relatively short ROI is often realized.

Disclosure: My company has a business relationship with this vendor other than being a customer. Through various methods, I have business relationship with Sophos and their reseller network. They are great guys who care more about making the internet a safer place than just extracting the maximum amount of revenue from you. Sophos listens to their customers and adds features as we request them. It really makes you feel like you have a security partner and not just a product supplier.
PeerSpot user
PeerSpot user
Senior IT Support Engineer at a religious institution with 51-200 employees
Vendor
The email alert on event triggers is a valuable feature. The ability to disconnect the VPN connection needs to improve.

What is most valuable?

The most valuable features are:

  • Ease of configuration of the firewall rules and routing.

  • The email alert on event triggers.

  • Internal storage for logging, as you do not have to get another server to store the logs.

What needs improvement?

The ability to disconnect the VPN connection needs to improve. Currently, in order to disconnect an existing VPN connection of a device, the admin needs to change the password of the user.

For how long have I used the solution?

I have used this solution for two and a half years.

What do I think about the stability of the solution?

We encountered stability issues more on the Web Filtering feature where certain valid websites are blocked or the video cannot be played and it requires extra exceptional configuration.

What do I think about the scalability of the solution?

There were no scalability issues.

How are customer service and technical support?

I would rate the technical support a 8/10.

Which solution did I use previously and why did I switch?

Previously, we were using WatchGuard UTM. The pricing and ease of use of the configuration were the reasons as to why we moved over to this solution.

How was the initial setup?

Setup is straightforward.

What's my experience with pricing, setup cost, and licensing?

From time to time, there is a promotion and it is more cost effective to get the 3 years subscription licensing upfront.

Which other solutions did I evaluate?

We looked at Fortinet.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.
Updated: October 2025
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.