Dana Bailes - PeerSpot reviewer
Network Administrator at a manufacturing company with 51-200 employees
Real User
Great web and email filtering with reasonable pricing
Pros and Cons
  • "We've found the technical support to be helpful."
  • "The ease of use could be a bit better."

What is our primary use case?

We primarily use the solution for a number of use cases, including the firewall, web filtering, email filtering, and email encryption. UTM does it all. The only thing that we don't use it for is web application and protection. We don't really have any web servers in-house.

What is most valuable?

The web and email filtering are the two biggest and most valuable aspects of the solution for us.  

The solution overall has just been a good, cost-effective solution for us.

The solution offers a lot of functionality.

The solution scales well.

We've found the technical support to be helpful.

The stability and performance are quite good.

What needs improvement?

The ease of use could be a bit better. It's something they could work on.

The ease of configuration could be improved. It's not as simple as it could be just yet. However, it's kind of the nature of it.

They're kind of difficult to get set up sometimes.

Some of the detail in the web filter and the email filtering could be better outlined in the reporting. It is not as good as the two separate standalone solutions we used previously. However, it does also gives us a lot of other stuff that those two solutions didn't. It's a trade-off.

For how long have I used the solution?

I've been using the solution for the last five years at this point.

Buyer's Guide
Sophos UTM
March 2024
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,886 professionals have used our research since 2012.

What do I think about the stability of the solution?

The stability and performance are good. The solution is reliable. There are no bugs or glitches. It doesn't crash or freeze. It's good.

What do I think about the scalability of the solution?

We've been using the same hardware for five years and it's always had a very good performance. I would say it scales pretty well. We have around 80 users on the solution currently. We've had double that. Actually, until COVID hit, we did have double that, as of a year ago.

How are customer service and support?

We've been very happy with Sophos, despite the fact that most of their support is based out of Europe. When you get them on the phone, they're actually very good. Their support is very good. We've been happy with them, and have no concerns about renewing the maintenance.

Which solution did I use previously and why did I switch?

We currently use a few Cusco solutions. We had a SurfControl web filter previously - a standalone server for that. We also had an email filtering package, that was on a separate server by itself. We found that the Sophos UTM did both of those things, and it gave us a firewall, and it saved us money. That's largely why we switched. The downside to Sophos is the reporting wasn't as good, however, everything else was better.

There was nothing wrong with the other solutions that we had other than it would cost us twice as much money to get a lot fewer capabilities. We don't really have the manpower to fully utilize those other solutions in great detail, which is why a simple web filter and email filter that was built into the Sophos solution worked for us. Plus, it does a lot more than that. We could run everything through it. We could - and we may do this - move away from using the Cisco solutions altogether, and just use the two Sophos firewalls. Once we get the XG up and running, we can upgrade the UTM to XG also and have the two XG firewalls in our two locations, and use it for the LAN connection between the locations. I don't know that we'll do that, however, it's definitely something that we can do. It's just a lot of additional capability and flexibility. 

How was the initial setup?

While the configuration can sometimes be tricky, it was pretty much straightforward to initially set everything up. It helped that we had paid support through Sophos, so their technicians helped us get it up and running.

The deployment took a couple of weeks in total. It wasn't too big of a deal.

We don't really have any staff dedicated to deployment and maintenance. I tend to handle those aspects myself.

I've watched a few webinars, even on implementation, and it's just that a lot of the stuff is really different. You need to work on it a bit to get the hang of everything.

What about the implementation team?

We had Sophos directly assist us. They were great at helping us implement everything. We physically got it in place, and then got it up and running, and then finished it off with some assistance from Sophos.

What's my experience with pricing, setup cost, and licensing?

We've found the solution to be cost-effective overall.

Normally we do a three-year license with maintenance on a firewall.

Beyond the standard maintenance fee, the solution doesn't require any other licensing costs.

What other advice do I have?

We are a manufacturing company. We're not a technology company. We don't need to have the very latest state-of-the-art technology, however, we want to try to be close to it. For us, Sophos is perfect.

We also plan to use Sophos XG, however, we haven't implemented it yet. We're hoping it might be easier to configure and set up than UTM.

Our antivirus, actually, was the antivirus that was managed by the UTM. Now they've since retired that capability, and they've gone to endpoint security software being managed in the cloud. Sophos Central can manage all of the Sophos security products, including all the firewalls, the endpoint security. Basically, you end up with one web interface for all of your security stuff. That's actually going to be a big feature, especially moving forward with XG, due to the fact that, if XG detects anything fishy going on, you can shut down individual client networks, and not allow any traffic to go through.

 Our Exchange ActiveSync is actually behind a Cisco firewall. We have a Cisco ASA also.

We use the latest version of the solution.

I'd rate the solution at an eight out of ten. We've largely been satisfied with the product.

As a company, you're looking to get the best solution out there. Once you have something in place, and it's worked well for you, and it hasn't cost you any excess money, you don't need to have too much contact with anyone. I rarely contact Sophos. That's a good indication of how good the product is working for us. If I was looking for something new, or if when maintenance comes up, and we've had hardware that's been in operation for a while, maybe we just need something new. Then you look and see if there's something out there that works better for you. That's basically it. We're not looking for anything new. We've actually been very happy with Sophos. I liked the way that there's a lot of good stuff there.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Technician at Wm tech
Real User
User-friendly interface, useful documentation, and great support
Pros and Cons
  • "The most valuable feature of Sophos UTM is the simple-to-use interface."
  • "Sophos UTM could improve if there was no limitation on users."

What is our primary use case?

I am an implementor and I provide support for customers' use cases. The solution is used as a load balancer, and for VPN access.

What is most valuable?

The most valuable feature of Sophos UTM is the simple-to-use interface.

What needs improvement?

Sophos UTM could improve if there was no limitation on users.

For how long have I used the solution?

I have been using Sophos UTM for approximately six months.

What do I think about the stability of the solution?

I rate the stability of Sophos UTM a ten out of ten.

What do I think about the scalability of the solution?

I rate the scalability of Sophos UTM a ten out of ten.

How are customer service and support?

The support from Sophos UTM is good.

I rate the support of Sophos UTM an eight out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The implementation of Sophos UTM is simple. The documentation of the solution is satisfactory.

I rate the initial setup of Sophos UTM an eight out of ten.

What about the implementation team?

We use two engineers for the deployment of Sophos UTM.

What's my experience with pricing, setup cost, and licensing?

The price of the solution is high. The price from USD to my currency is expensive.

I rate the price of Sophos UTM a five out of ten.

What other advice do I have?

This is a good solution and they should try it.

I rate Sophos UTM a ten out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: implementer
PeerSpot user
Buyer's Guide
Sophos UTM
March 2024
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,886 professionals have used our research since 2012.
Account Executive at a tech services company with 11-50 employees
MSP
Top 10
Highly granular, communicates with other Sophos solutions, and offers good performance
Pros and Cons
  • "The initial setup is pretty straightforward."
  • "I don't really have any notes for improvements."

What is our primary use case?

We primarily use the solution for firewalls. 

What is most valuable?

The firewall in general is very good. It is comparable to other firewalls. 

Since any environment needs a firewall, it's been helpful in its ability to be highly granular in its configurations. 

Sophos is a security-focused company, which I like. I like that all Sophos products can essentially talk to each other. For example, if a computer has the Sophos antivirus, and it detects something, it actually talks to the Sophos firewall and says, "Hey, I think something is going wrong on this computer." Then, the firewall goes, "You know what? I'm going to shut it down for a while. I'm going to close off all incoming and outgoing connections from that unit until an IT admin comes in and tells me to release it."

It's very scalable.

The solution is stable. 

The initial setup is pretty straightforward. 

What needs improvement?

I don't really have any notes for improvements. I don't need additional features. 

For how long have I used the solution?

I've been using the solution for three or more years. 

What do I think about the stability of the solution?

The solution's stability is excellent, and it is reliable. There are no bugs or glitches, and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution is very scalable and easily expands. 

Which solution did I use previously and why did I switch?

I'm also familiar with Meraki. Sophos, however, has the ability to talk to other Sophos products. 

Meraki would be all isolated, meaning you have a different antivirus. It'll try to block and scan and do its thing, however, the firewall will always allow the connection to go through. Nothing is stopping it from isolating it. From a Sophos perspective, every single thing talks to each other, whether it's Sophos Central, Sophos email security, Sophos antivirus, or Sophos firewall.

They all talk to each other and look at how attackers come in because attackers don't just, poof, appear on a computer. There's a route it needs to take and different layers of protection it has to go through. If all of your layers, your roads, and everything is all Sophos, they all jive, and that's great.

How was the initial setup?

The ease of setup is dependent on the level of technical expertise. If you are a qualified tech, all firewalls should be pretty simple to deploy, depending on the environment. It's simple enough to implement in general. 

What was our ROI?

We have witnessed a positive ROI while using the solution. 

What's my experience with pricing, setup cost, and licensing?

Price-wise, you get the bang for your buck. You get a huge value set. Ask for HA, high availability, since a lot of Sophos resellers sell two firewalls, the second one being free. Then, you only pay for one license. If your first firewall fails, the license migrates to the second one.

What other advice do I have?

We are using a variety of different versions of the solution right now. 

It's really, really cool to look into Sophos. I highly recommend it. From an infrastructure, stability, and security perspective in terms of configuring in a granular way, Sophos does it all. It's a really good product and something to look into. 

It's also a lot cheaper than Meraki. It does way more than Meraki. Dollar to dollar, Sophos will likely beat Meraki. For example, with Meraki, you're going to be paying two or three times more for nothing spectacular, nothing different. You just get a portal. It's okay. With Sophos, you do have to know what you're doing, however, any network admin should be able to figure it out. It's not like an ancient hieroglyphic language. It's quite straightforward.

I'd rate it nine out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Occupational safety technician at Concremat
Real User
Top 5
Good web filtering with a fine initial setup and the ability to increase usage
Pros and Cons
  • "The initial setup has been fine."
  • "We need a better VPN client for the customers."

What is our primary use case?

We primarily use the solution for the firewall and VPN.

What is most valuable?

The web filtering is great.

The initial setup has been fine. 

You can increase usage if you need to.

What needs improvement?

The VPN could be better. We need a better VPN client for the customers.

We'd like better logging. 

For how long have I used the solution?

I've used the solution for six years.

What do I think about the scalability of the solution?

We have about 3,000 users on the product right now. We do have plans to increase usage in the future.

How are customer service and support?

Technical support has been fine. We are satisfied with the level of service we get. 

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We also use Fortinet and pfSense.

How was the initial setup?

The initial setup is very simple and straightforward. It's not overly difficult or complex to set up. 

What's my experience with pricing, setup cost, and licensing?

The licensing is paid on a yearly basis. You just need to pay the standard licensing fee. There are no extra costs. 

What other advice do I have?

I'd rate the solution a seven out of ten. It's been okay.

We are a partner of the product.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
General manager at DotCom, Lda.
Real User
It's a complete firewall covering all layers of protection
Pros and Cons
  • "The three most important features for us are web protection, web server protection, and network protection."
  • "Sophos UTM sometimes falls short in high-availability environments. They used to launch firmware that didn't work very well in a high-availability environment."

What is our primary use case?

Sophos UTM is a complete firewall we use to protect from internet threats and check traffic from our network to the internet. It's a firewall covering all layers of protection.

Sophos has some plugins that run on the cloud, but it's transparent to the end-user. For example, there is something to identify threats on an email system called SenseStorm, which is connected to the Sophos Cloud and identifies new threats then spreads the same pattern to all Sophos installations in real-time. I can say that almost 100 percent of our customer companies who have a file solution use Sophos.

What is most valuable?

The three most important features for us are web protection, web server protection, and network protection.

What needs improvement?

Sophos UTM sometimes falls short in high-availability environments. They used to launch firmware that didn't work very well in a high-availability environment. 

For how long have I used the solution?

I've been using Sophos UTM for the last five years, but we started using Astaro Security Gateway, the predecessor to Sophos UTM, in 2002.

What do I think about the stability of the solution?

Sophos UTM is a strong solution. I give it a 10 out of 10 for stability.

What do I think about the scalability of the solution?

Sophos UTM is scalable.

How was the initial setup?

The initial setup is somewhat tricky. You need to understand networking concepts well, and the company must have good policies for internet access. However, it's not that complicated. I would say it's an intermediate difficulty, but I also have a lot of experience with this solution. It might be challenging for a new technician. We do all the deployment in-house, and it takes about three business days. Our team consists of two technicians and me, the manager. 

What's my experience with pricing, setup cost, and licensing?

Sophos UTM isn't cheap. It's in the middle, so not the cheapest, but not the most expensive. It's average. If you buy the full suite, you don't need to pay for add-ons, but if you buy some partial products, you have to pay to deploy more features.

What other advice do I have?

I rate Sophos UTM 10 out of 10. It's the most reliable solution in the firewall market. Considering the price and quality of the product, Sophos UTM is the best solution.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Real User
Offers secure and Scalable Firewall Security
Pros and Cons
  • "The features that I've known to be most valuable are both the web security features as well as the web firewall capabilities. As a partner of Sophos firewall, we have some clients and they are using Sophos firewall UTM and we are using it as well."
  • "The only time we face a problem or issues is when we place a ticket. We have found that response is very slow."

What is our primary use case?

We use this solution for communication endpoint, encryption, and network security. We are focused on providing security software to the small to mid-market enterprises; the essence of our delivery is internet security.

What is most valuable?

The features that I've known to be the most valuable are both the web security features as well as the web firewall capabilities. As a partner of Sophos firewall, we have some clients that are using Sophos firewall UTM and we use it as well.

What needs improvement?

One additional feature that should be included in the next release is
synchronized security, which would enable all the security to work together as a system. Another suggestion is to add advanced threat protection (ATP) to defend against sophisticated Malware. Seeing these additional improvements would be a great thing going forward.  

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

The product is stable. It's a product that our clients are able to use and enjoy. We haven't had many complaints about the product at all. Internally we haven't experienced any problems. 

What do I think about the scalability of the solution?

The scalability is also fine. Currently, we have 20 employees using the product to date and only one employee needed to maintain the product. At the moment we don't have any plans to increase usage in the company. Not now, next year maybe.

How are customer service and technical support?

We train our employee's on technical support. I don't need any outside technical support.

The only time we faced a problem or issue is when we place a ticket. We have found that the response is very slow. That seems to be our biggest problem.

Which solution did I use previously and why did I switch?

We previously used Cyberoam but Sophos acquired Cyberoam. That's why we migrated to Sophos.

How was the initial setup?

The initial setup was done with our engineers, they also set up that server firewall. The setup was straightforward.

What about the implementation team?

The deployment took one month. We're a support base reseller. Our in-house team took care of it. We don't use anyone from the outside, we can deploy the product on our own.

What's my experience with pricing, setup cost, and licensing?

Everything involving pricing and licensing is maintained by our Bangladesh Sophos country managers. The pricing is okay and the licensing is also included in the price.

What other advice do I have?

Sophos UTM is a good product for security purposes and maybe if Sophos provided another company option to implement their products then I would say that Sophos UTM is great.

On a scale of one to ten with 10 being the best, I would give this solution a nine out of 10. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Bob Alfson - PeerSpot reviewer
Bob AlfsonSophos Certified UTM Architect, Sophos Certified XG Engineer at MediaSoft, Inc.
User

A few observations on an otherwise-accurate review...

The quickest way to get Sophos Support is by submitting a case via MyUTM, SophServ or at secure2.sophos.com Calling is the slowest way to open a case.

I wonder if Mr. Khan's review doesn't apply to the XG Firewall which is a new Sophos product based on the GUI that Cyberoam developed.

Cheers - Bob

Data Department Manager at BTC Networks
Real User
As both a firewall and UTM it's perfect, however, sometimes with setting up the spam filters there is an issue.

How has it helped my organization?

As we are a solution provider and not product oriented, we give the best solution for our customers, with a good price. We are the number one company in the region, BTC, and operate in Egypt, Iraq, Jordan, Lebanon, and Saudi Arabia.

What is most valuable?

As both a firewall and UTM it's perfect.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Customer Service:

For me, the customer satisfaction, and awareness, is the most important thing. I usually train all my clients on their chosen system.

Technical Support:

10/10.

Which solution did I use previously and why did I switch?

As we are a service provider, we offer various other products to our customer:

  • Astaro ASG
  • Avaya/Netscreen
  • Fortinet
  • HP Switches & WiFi
  • Juniper SSG
  • Juniper SRX 210 & 240
  • Juniper WXC
  • Sophos next generation SG, including RED, SG, and WiFi
  • Telindus Crocus E1Q

How was the initial setup?

For me, the installation and setup is simple. I work hard to do the simulation for the customer, and discuss all the requirements before implementation with the client.

What about the implementation team?

In one project I implemented Sophos for was a bank. I had to involve the Sophos team as the client was asking for WAF in transparent mode with HTTPS inspection. They were 10/10.

Which other solutions did I evaluate?

Prior to Sophos, it was mainly Juniper and Fortinet.

What other advice do I have?

Give us 10 minutes of your time, and we will show you the differences. When I do presentations, I give potential clients demo access to the solution(s) I am presenting.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Architecture and DevOps at hc1.com
Real User
It has allowed us to have a solution that we can maintain and not have to babysit all the time
Pros and Cons
  • "It has made our organization more secure, because we are using a VPN. We are not accessing services directly. It allows us to segregate some of the traffic for individuals which may be more of a developer role rather than an operational role needing access to developer resources, but not necessarily production operational resources."
  • "It makes it a lot easier for us to maintain things. Prior to it, things were more difficult. This means less time on us. We can focus on other things. The recovery is more in man-hours for us than anything else."
  • "The documentation during the AWS integration was a little fuzzy on getting it to work with how the whole public exposure versus private exposure, then routing some of the traffic."

What is our primary use case?

Our Sophos UTM provides a secure VPN solution. It allows us to have a VPN solution that limits access to certain sensitive areas in our environment.

How has it helped my organization?

It has made our organization more secure, because we are using a VPN. We are not accessing services directly. It allows us to segregate some of the traffic for individuals which may be more of a developer role rather than an operational role needing access to developer resources, but not necessarily production operational resources.

Previously, it was all intermixed, and access was kept under control by other means. This makes it easier and more streamlined.

What is most valuable?

  1. The VPN side of it.
  2. The ease of configuration of the VPN.
  3. Some of the end user self-serviceability of it without having to have a whole lot of touch from our operational group

What needs improvement?

The UI on it could stand a little improvement. In some areas, it is a little slow and clunky. It is sometimes not easy to find something. However, once you get used to it, it is pretty normal to use.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

We haven't had an issue with it yet. 

Any given day, we have easily ten to 15 users on it constantly, plus some other ancillary services which go across the VPN to access resources in our environment.

What do I think about the scalability of the solution?

It works for what we have, as we only need a couple of them. Scalability-wise, we don't need a whole lot. 

How is customer service and technical support?

We have used technical support one time for a weird upgrade issue. Their response was good.

How was the initial setup?

It integrated well with AWS. The documentation was a little fuzzy on getting it to work with how the whole public exposure versus private exposure, then routing some of the traffic. However, once you read the documentation carefully, it comes out well. This goes back to the UI issue.

What was our ROI?

It makes it a lot easier for us to maintain things. Prior to it, things were more difficult. This means less time on us. We can focus on other things. The recovery is more in man-hours for us than anything else.

What's my experience with pricing, setup cost, and licensing?

Purchasing through the AWS Marketplace is pretty straightforward. Because were entirely on AWS and don't have anything anywhere else. It made the most sense for us as a one stop shop.

The pricing is pretty reasonable. I don't think that it is overly expensive.

Which other solutions did I evaluate?

We looked at a couple other products. However, overall, Sophos UTM seemed to fit the bill. It has allowed us to have a solution that we can maintain and not have to babysit all the time.

What other advice do I have?

It is definitely worth looking at. It is a pretty good product.

It is integrated with our LDAP solution, and that integration is okay. Any LDAP integration can be hit or miss. It doesn't matter what it is, because it's LDAP. Since we use LDAP as a service, it's a little different, but it does work well.

We use it for the AWS version.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2024
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.