Network and Security Engineer at ONB
Real User
Top 10
Efficient, useful email filtering, and detailed documentation
Pros and Cons
  • "The most valuable feature of Sophos UTM is the efficiency and mail filtering module."
  • "Sophos UTM could improve the way the configuration has to be done. I have to do the configuration through the command line interface but if it could be done through the graphical user interface it would be much better."

What is our primary use case?

We use Sophos UTM for firewall management and for some of the other modules it provides, such as email and firewall proxies.

What is most valuable?

The most valuable feature of Sophos UTM is the efficiency and mail filtering module.

What needs improvement?

Sophos UTM could improve the way the configuration has to be done. I have to do the configuration through the command line interface but if it could be done through the graphical user interface it would be much better.

For how long have I used the solution?

I have been using Sophos UTM for approximately three years.

Buyer's Guide
Sophos UTM
June 2024
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2024.
793,295 professionals have used our research since 2012.

What do I think about the stability of the solution?

Sophos UTM is a highly stable solution. It has high availability.

What do I think about the scalability of the solution?

We have approximately more than 1,000 employees in my company using the solution.

Which solution did I use previously and why did I switch?

I have used Fortinet previously and I found it to be easier to deploy and maintain than Sophos UTM

How was the initial setup?

The initial setup of Sophos UTM is straightforward. Additionally, the configuration is simple. When we first did the deployment it took approximately two days.

The configuration of this solution is easier than some of the competitors. In some of the other solutions, when there is synchronization between two firewalls there are times you need to break all the configurations and start from the beginning.

What about the implementation team?

When we did the first installation of the solution we used a third party to assist. However, we now do the full implementation of the solution using our team.

What's my experience with pricing, setup cost, and licensing?

The price of the license for Sophos UTM is approximately $5,500. The solution is less expensive than competitors.

What other advice do I have?

The maintenance of the solution is easy, the documentation is very rich in content, and the report information is good. 

I rate Sophos UTM an eight out of ten.

Which deployment model are you using for this solution?

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Owner / Network Security Engineer at Texarkana IT
Real User
You can lock networks down tight with this if you know what you're doing
Pros and Cons
  • "The intrusion prevention is great, and I like dual virus scanning on the network layer because we scan it through Avira and Sophos. Web filtering is also a fantastic option for clients who want to really lock down internet access."
  • "When we call support, we get put on hold for a long time."

What is our primary use case?

We use Sophos UTM as an on-premise firewall.

What is most valuable?

All of Sophos UTM's features are valuable. The intrusion prevention is great, and I like dual virus scanning on the network layer because we scan it through Avira and Sophos. Web filtering is also a fantastic option for clients who want to really lock down internet access. And of course, it has the basic firewall features like port blocking and all of the stuff that most standard firewalls include.

For how long have I used the solution?

I've been using Sophos UTM for over 12 years. I started using the solution before it became Sophos. It was originally called the Astaro Security Gateway, and then Sophos acquired Astaro and renamed it Sophos UTM.

What do I think about the stability of the solution?

Very stable. Very good.

What do I think about the scalability of the solution?

I have Sophos UTM deployed for all my IT clients. There are 40 of them in the field serving about 500 users total.

How are customer service and support?

We get put on hold for a long time. Otherwise, I'm not unhappy with their support at all. 

How was the initial setup?

If you have a networking background and understand how to configure it, it's very straightforward. Somebody off the street can't just come in and do it, but yeah, it's pretty straightforward.

What other advice do I have?

I would rate Sophos UTM a strong eight. I'm not giving it a ten because they're putting all their efforts into the XG model, so the UTM model will probably be phased out before long. I love the security of the XG. It's better with artificial intelligence and all of this type of stuff, and you can manage it from the Sophos Central Cloud. But Astaro ASG, now Sophos UTM, was the first unified threat management system and everybody else was copycatted it. I think its web filtering's great. If there are any security vulnerabilities, it's the fault of the administrator configuring the product, not the solution itself. You can lock networks down tight with this if you know what you're doing.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Sophos UTM
June 2024
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: June 2024.
793,295 professionals have used our research since 2012.
Manager IT and Security at Health Street
Real User
Enables us to fully isolate an infected server or workstation with the click of a button
Pros and Cons
  • "The isolation of infected machines is a big feature. Also, the ability to detect external sources that change files on a file server is really big."
  • "It does have built-in policies, which enable you to disable USB devices, etc. It would be nice if they had more policies because there are not that many of them."

What is our primary use case?

Threat management for servers is our primary use case. We're not using it on all workstations, just a few. We're primarily using it on servers.

The version we're using is fully in the cloud, not on-prem.

How has it helped my organization?

We don't have to worry about viruses anymore. Before Sophos, we didn't have anti-virus at all because we're a newer company and we're just now starting to get into business-level stuff. When we installed it on a few of the users' machines, we saw that they did have very minor infections - they downloaded something they shouldn't have, something that could have hurt the computer. We were able say, "Well, we're glad they didn't click on that."

What is most valuable?

The isolation of infected machines is a big feature. Also, the ability to detect external sources that change files on a file server is really big.

The third key feature is something called EDR. It's a type of advanced file analysis. If you aren't sure what a file is you can click on it and it will upload a sample to Sophos and it will respond saying, "That's malicious," or "Not malicious." You can see every individual file and registry key that that file has ever interacted with, and what they did. It will show you every single thing it's done to the machine so you can clean up everything or check everything that it has ever touched. You don't have to worry about, "Oh, did I clean everything up?"

What needs improvement?

It does have built-in policies which enable you to disable USB devices, etc. It would be nice if they had more policies because there are not that many of them.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

In terms of stability, it's definitely top-notch, a market leader. The ability to do things and the availability of it being online aren't an issue.

What do I think about the scalability of the solution?

It seems very scalable. All you do is install the client, and it pulls it in. You don't have to actually have more Sophos servers running. It all goes back to their central, cloud-based platform, which is nice.

How is customer service and technical support?

I haven't had to use Sophos' technical support.

How was the initial setup?

The initial integration and configuration of Sophos in our AWS environment was incredibly easy. They give you a license key and a file. You download that file on the operating system type that you're trying to install it on. Install it and it's done. There's nothing else at all to do. It gets auto-configured for you.

What was our ROI?

We haven't seen ROI because we just got it two or three months ago. Over time we will.

What's my experience with pricing, setup cost, and licensing?

The biggest issue with Sophos is the pricing. It's definitely more expensive. We looked at Webroot, which is a big alternative, and Sophos was almost three times the price of Webroot. That's a pretty big difference.

We actually went with both Webroot and Sophos. We went with Webroot for most of the client machines. We're only using Sophos for the servers and the really important client machines, like the ones the managers use. That way, we can split our cost up a little bit.

Which other solutions did I evaluate?

We looked at Webroot, primarily. That was pretty much the only one we evaluated that was even close to being a competitor. We did look at a few others, but we didn't even do the trials because \Webroot and Sophos offered so much more.

Webroot seemed really nice for Windows, but we have a lot of Macs. Our servers are Windows, and we definitely went with Sophos for the servers because it has a little bit more capability with Webroot.

An example would be that if you have a file server, it will actually detect if a source is changing stuff on the file server. Suppose that a client was connected to them. That client wouldn't even need protection. Sophos is smart enough to understand, "Hey, a client just uploaded this virus." Webroot wouldn't do that. Sophos also lets us do full isolations of the servers or workstations. So if something gets infected, we can isolate that machine with the click of a button, clean it up, and then release it back into the network. That's not something Webroot was capable of handling either. Those were two big things to us because both of those features stop viruses from spreading.

Everyone's going to get infected at some point. We just want to stop the spread as soon as possible.

What other advice do I have?

If you're running a full Windows-based shop you're going to have a lot more options, so make sure you shop around. If you're running a Mac-based shop like we are, Sophos is definitely the way to go. Just make sure you can afford it.

Regarding how well Sophos integrates with other products, so far we haven't integrated it with anything. We have it on the servers and we have it scanning our Amazon accounts, but that's it. The integration with Amazon is cool. Maybe they could work on that because it seems like a newer feature. You can see what's available but not really do anything yet.

For the features, how well it works, and how easy it is to use, I would give Sophos a ten out of ten. Overall, I would give it a nine because it is very costly compared to all competitors.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
It manager at MMA2
Top 5
Simple setup, flexible reports, and high availability
Pros and Cons
  • "The most valuable feature of Sophos UTM is reporting, it is flexible. I can monitor the end user's devices, even when they are not on my network. It has good drill-down capabilities."
  • "The reporting could improve by providing information on where, or from which device attacks are coming from. We are already given the country where the attack is coming from but more information would be beneficial."

What is our primary use case?

This solution can be deployed on-premise and on the cloud.

What is most valuable?

The most valuable feature of Sophos UTM is reporting, it is flexible. I can monitor the end user's devices, even when they are not on my network. It has good drill-down capabilities.

What needs improvement?

The reporting could improve by providing information on where, or from which device attacks are coming from. We are already given the country where the attack is coming from but more information would be beneficial.

For how long have I used the solution?

I have been using Sophos UTM for approximately five years.

What do I think about the stability of the solution?

The stability of Sophos UTM is good.

I rate the stability of Sophos UTM an eight out of ten.

What do I think about the scalability of the solution?

Sophos UTM is scalable.

I rate the scalability of Sophos UTM an eight out of ten.

How are customer service and support?

I have used the support from Sophos UTM a few times. My experience was good. However, the resolution time can improve.

I rate the support of Sophos UTM a seven out of ten.

How would you rate customer service and support?


How was the initial setup?

The initial setup of Sophos UTM is simple. It can be down within one hour.

I rate the initial setup of Sophos UTM a seven out of ten.

What's my experience with pricing, setup cost, and licensing?

The solution is affordable compared to others, such as FortiGate. The price is important.

I rate the price of Sophos UTM a seven out of ten.

What other advice do I have?

I rate Sophos UTM an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Administrator at Vegol
Real User
Top 20
User-friendly with lots of online documentation and the ability to expand
Pros and Cons
  • "The solution is stable."
  • "The support could be better."

What is our primary use case?

The solution is used mainly for user management and access control. 

What is most valuable?

It's a little bit easier to use. It's user-friendly, and then there's a lot of documentation for it online, so it's easy to manage without necessarily dealing with a big learning curve. It is easy to understand, basically.

If you need to troubleshoot, everything is basically on Google. 

The solution is stable. 

It's a scalable product.

What needs improvement?

The support could be better.

They need to improve their email protection. Their email protection is horrible. They have an email protection license that is paid for. However, they need to improve on email protection capabilities.

They need to have proper reporting. What they offer no is weird. I need to get another application to give me a clear diagram of my network. This should instead come directly from Sophos. 

For how long have I used the solution?

I've been using the solution for two years now. 

What do I think about the stability of the solution?

The product is stable and reliable. There are no bugs or glitches. It doesn't crash or freeze. 

It is redundant enough. I don't have any issues with it.

What do I think about the scalability of the solution?

The solution scales well. 

We have about 500 people on the product right now. We also have 100 users on the VPN.

How are customer service and support?

It is better to Google rather than use technical support. 

They are slow to respond and then the response doesn't exactly give you what you want.

I understand they can't give you a solution to something that you'd expect them to. They try to give you something. You're going to go to Google and find the information on Google faster and easier anyway. 

Which solution did I use previously and why did I switch?

We worked with Cisco mainly in the past. When we went to renew with Cisco, we found the pricing to be quite high. We're happy now with Sophos. We have no interest in switching to anything else.

How was the initial setup?

The initial setup is very easy. The interface makes it simple.

I'm not sure how long the deployment took exactly.

We have four people that are able to handle maintenance. 

What about the implementation team?

I was able to set it up myself, however, you do really need to know it or work with someone who does.

What's my experience with pricing, setup cost, and licensing?

The cost could be considered reasonable based on other plans. However, when I was looking at when you renew our licenses, the pricing is a little bit weird. When you renew your license, the licenses are at the cost of buying a new device in your plan. I haven't renewed yet. However, I would need to figure out that aspect. 

I can't recall the exact costs of the product as it's been a while since we originally licensed it. 

Compared to Juniper, the difference is the pricing. It's more affordable than Cisco or Juniper, actually.

What other advice do I have?

I'm a user and a consultant.

I'd advise potential new users that they should let someone that knows how to do it set it up fast. You should work with someone that knows how to do it.

I'd rate it an eight out of ten. 

Which deployment model are you using for this solution?

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Hassan Moussafir - PeerSpot reviewer
Information Security Senior Expert at Wafaassurance
Real User
Stable with great technical support and an easy initial setup process
Pros and Cons
  • "Technical support is very responsive."
  • "The integration capabilities could be better."

What is our primary use case?

We implemented the solution into our infrastructure here in the insurance company, to protect the flow between the company and its partner.

What is most valuable?

The solution is quite stable. 

The scalability has been great.

The initial setup is straightforward.

Technical support is very responsive.

What needs improvement?

The integration capabilities could be better.

For how long have I used the solution?

I originally implemented the solution when it was Cyberoam. After that, we migrated to Sophos UTM. I've used the solution since 2011.

What do I think about the stability of the solution?

The solution is stable and reliable. There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

The scalability is great. If a company needs to expand it, it can do so. It's not a problem.

We currently have 800 people using the solution.

How are customer service and technical support?

We do pay for Sophos' support and we find them to be quite helpful and responsive. We're satisfied with the level of assistance we receive. 

Which solution did I use previously and why did I switch?

We have used other solutions. We have various levels of firewalls. 

How was the initial setup?

The implementation process is straightforward. It's not overly difficult. A company shouldn't have any issues with the process. 

It's a good idea if you are migrating from another solution, to do a review of security policy. That way, you can better optimize for security when you set everything up.

We have a team of six that can handle implementation and maintenance duties. We have two managers. One covers organizational security and the other cover operational security.

What's my experience with pricing, setup cost, and licensing?

We do pay extra for Sophos support services.

The license is easy to acquire and implement. 

Which other solutions did I evaluate?

I'm currently performing a benchmarking of the other solutions against Sophos.

What other advice do I have?

We're a custoer and an end-user.

When Cyberoam was acquired by Sophos, we migrated to the new hardware and new solution in Sophos.

We've been very happy with its capabilities. We would rate the solution at a nine out of ten.

I'd recommend, if a company sincerely wants to try out Sophos, that they test everything before implementation. It will help them understand what the solution can do and how to implement it into their infrastructure. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Engineer at Wise Communication
Real User
Top 20
The graphics are very intuitive and the log provides a lot of information
Pros and Cons
  • "An easy solution to learn because the graphics are very intuitive."
  • "Doesn't provide antivirus for individual computers."

What is our primary use case?

We mostly use UTM for the protection of our network and the web. Some of our customers use it for email protection. We work mainly with governmental organizations. Our company was initially a distributor of the forerunner to UTM, a company called Astaro. We provide UTM to our customers and we are now partners with Sophos. 

What is most valuable?

It's an easy solution to learn because the graphics are very intuitive. I really like the log because of the amount of information it provides.

What needs improvement?

Sophos' new generation firewall is missing the link that provides antivirus for each computer. It would be helpful if they could add that element. The technical support used to be excellent but recently they don't seem to be able to solve our problems. 

For how long have I used the solution?

I've been using this solution for 20 years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable although we generally work with smaller organizations. 

How are customer service and support?

The technical support used to be excellent but it's no longer as good as it was and we've had some problems getting solutions to the issues that we're having.

How would you rate customer service and support?


How was the initial setup?

The initial setup is straightforward. We provide one or two engineers for implementation as well as ongoing support following deployment. 

What's my experience with pricing, setup cost, and licensing?

Licensing can be purchased for one, two, or three years but I'm unaware of the cost. The solution can be downloaded for free if it's for home use which is a good way of testing before implementation.

What other advice do I have?

I recommend testing this product before purchase. It's a good solution and I rate it 10 out of 10. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
IT Manager at Manual Workers Union
Real User
Great features with easy centralized reporting and good performance
Pros and Cons
  • "So far, the solution has been problem-free."
  • "We'd like to see them offer their services on mobile devices like tablets. I'm not sure if that's an option or not."

What is our primary use case?

The features that we're currently using are mainly just for the endpoint protection, which is for the service and the workstations. We basically use it for the servers, the main servers, and then from there for the client, which is basically the laptops and the PCs.

How has it helped my organization?

The fact that it's not heavy on the machines has really helped. It's basically lightweight. One advantage is that we, having a cloud solution, do not require a physical machine that we have to administer on our network.

What is most valuable?

The fact that it's on the cloud means we don't have to administer it on our network or deal with a physical machine, which saves us money.

The solution has many great features.

From the console, we can start different scannings on different machines. We enjoy the centralized reporting part of it. 

The initial setup is simple.

We enjoy its general stability.

The solution can scale.

So far, the solution has been problem-free.

What needs improvement?

We don't need any extra features. We only use it for the servers and the workstations. We'd like to see them offer their services on mobile devices like tablets. I'm not sure if that's an option or not.

For how long have I used the solution?

I've been using the solution for over a year now.

What do I think about the stability of the solution?

It's been very stable. In fact, we haven't had any complaints or any issues with it. There are no bugs or glitches. It doesn't crash or freeze. The performance is great.

What do I think about the scalability of the solution?

The scalability is quite good.

Right now, we have 40 users.

We will definitely scale in the future. As we get new employees, we just request additional licenses.

How are customer service and support?

I've never had any issues.

Which solution did I use previously and why did I switch?

I also use FortiGate.

How was the initial setup?

The implementation process was straightforward. What basically happens is that you just have to pick that certain client from the console and then you just install it on the machines. From there, of course, you handle connectivity after that. It's pretty straightforward.

A full deployment on one machine took less than 20 minutes. The thing is, if you have fast internet, it can even be much less.

Maintenance is very simple. Support is inbuilt from the manufacturer's side. Therefore, internally, if there are any issues on the client machine, you just reinstall it. There isn't much to do really, in terms of maintenance, except maybe the licenses. It's hosted on the cloud and updates are automatic, and are available from the portal.

What about the implementation team?

We did not need a reseller or consultant's assistance. It was all handled internally.

What was our ROI?

I haven't really explored ROI. I only have worked with it for slightly over a year. Maybe we need to start looking at it. 

That said, so far, we are protected and we haven't been hit so far. We're getting the returns from it in that sense.

What's my experience with pricing, setup cost, and licensing?

Having a cloud option is a real cost saving. 

In terms of licensing, we pay on yearly basis. From there, what happens, in the last month, we request a quotation for renewal, and then from there we just pay through the local reseller. 

We're thinking of maybe dealing with the supplier, the manufacturer, directly, however, right now, we're still using the local supplier for licensing and payments. 

What other advice do I have?

We are on the latest version of the solution.

We are customers.

I would rate the solution at a nine out of ten. We are very happy with it. I would recommend it to others.

I'd advise new users that, if they are going to go with the cloud option, that issues related to maintenance is actually handled within the cloud. The rollout is pretty smooth.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2024
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.