it_user701427 - PeerSpot reviewer
Snr Dev Ops Engineer at a tech services company
Real User
Define your requirements and find what best suits you
Pros and Cons
  • "It allows our developers to be able to securely log into servers to deploy and manage software."
  • "It has allowed us to design a bespoke cloud space for our clients, while still having an excellent level of protection."
  • "There is absolutely no support when using AWS. If you buy the on-premise Sophos solution, you get support."
  • "It is a pretty straightforward setup, but it should be some sort of documentation that takes you step-by-step to help set it up for your VPC."

What is our primary use case?

We have quite a lot of web service hosting, either websites or hosting APIs. We use Sophos as a two-factor authentication process. So, if they are outside or working in a remote office, they will need to use the Sophos VPN, which is gotten from the Sophos UTM, then ideally they will be developers. However, they can also be BI guys, DevOps people, etc. 

Sophos UTM allows you to compartmentalize different sections or different people, having those people connect to different services.

We use it for primarily for two-factor authentication, for VPN to allow employees security access the servers and to ensure people do not access things they should not have access to.

How has it helped my organization?

  • It has allowed us to have one solution for our AWS needs.
  • It allows our developers to be able to securely log into servers to deploy and manage software.
  • It has allowed us to design a bespoke cloud space for our clients, while still having an excellent level of protection.

What is most valuable?

  • The combination of server protection
  • Seamless incorporation with AWS
  • Its VPN feature

What needs improvement?

You (currently) need to buy the Sophos software per availability, zone, and per VPC. It should offer an account-based solution.

When you buy a Sophos license, you have to buy a license for each location. We have clients in the US. We have clients in Ireland. We have clients in the UK. With GD-PI coming, the clients' data needs to stay in-house, so when you buy the Sophos license, it only works for the UK. Then, you have to buy another in the USA and another one in Ireland, then you have to have a VPN tunnel between all of them to have them talk to each other because Sophos blocks them talking to each other.

So, ideally, a multi-VPC or a multi-talented Sophos would be great because it would take away the fact that you need to build a tunnel and you have one management console for all your different locations. Instead of having three different locations with three different IP addresses and having to add users to probably two out of three, sometimes all three, having just one centralized location would be good.

Buyer's Guide
Sophos UTM
March 2024
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,886 professionals have used our research since 2012.

What do I think about the stability of the solution?

No, we did not. Backups were done daily, and its Linux backend gave us no issues.

What do I think about the scalability of the solution?

Adding new servers was seamless. Adding new users and allowing for VPN access was also fantastic.

How are customer service and support?

For the AWS version, it was atrocious. None really. For the bespoke cloud space that we designed though, they were very good.

To further clarify, there is absolutely no support when using AWS. If you buy the on-premise Sophos solution, you get support and you get all the stuff. Whereas if you are using the AWS version, you do not. So, you kind of have to research. There's something simple really which affects Sophos quite a bit during setup. 

Which solution did I use previously and why did I switch?

No, we didn't. It was our first choice and it was definitely a good one.

How was the initial setup?

For a user who hasn't done it before, it may be a bit complex but with a general understanding of networks, it was fine.

However, when you build everything up using the AWS version (setup), it actually does not work until you write it on the Sophos UTM and in the networking, you have to change the source destination check. You have to do that at the end of it, but there is nowhere in the documentation or anything where it tells you that. It was just somebody happened to find that out. It is a pretty straightforward setup, but it should be some sort of documentation that takes you step-by-step to help set it up for your VPC. There really is not that much difference setting it up in different VPCs, but there is not enough information out there. It is a very good solution that a lot of people would be using more of except you are doing different things, and you have to try and figure it out yourself. 

The support, there is none; AWS themselves, they support it the best, because they have some knowledge of it, but they do not fully support it because it is not their product. It is a third-party product.

What's my experience with pricing, setup cost, and licensing?

Licensing is a bit complicated, as it is based on products -- so define your requirements and find what best suits you, as you do not need the whole suite of software they provide.

For AWS, it is pretty straightforward. You buy it, then you have all your licenses that you need, approximately 60 or 70, or it might even be unlimited. However, that is for one margin to expand to different margins. If you have an on-premise AWS, or one of our clients wanted on-premise AWS Assistant, the problem is to build the Sophos UTM on it. We get the software, then the licensing was not explained well because when you buy the licenses, you buy five (or 50) licenses, that is for the first module. So if you expand to second module, you have to buy more licenses of that. 

Again, it is one of those things where it is not well explained. Unless you are in the United States, or you have to use Sophos, you can't contact Sophos directly. You have to use a third-party company, and they all have different ways of how they explain their licensing. So, we have clients that want the database on-premise, and we went to get the Sophos licensing system and stuff like that. It was just they were doing it a different way to who we had in Ireland, so the conformity is a bit iffy. 

It is one of those things where it is not very well explained, so it is a lot of grunt work, a lot research has to be done before you progress, and there are the pitfalls that you encounter. There are quite a few of them. Once you get it working, it is a fantastic product. It is just getting it that is the issue. 

Which other solutions did I evaluate?

We looked at a few, but I can't remember right now.

What other advice do I have?

Great product which works without issues or downtime.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Network & Hardware Administrator at Nile Projects & Trading Co.
Real User
Creates secure IPsec and SSL VPN high availability connections between head office and branches
Pros and Cons
  • "It allows me to easily connect with more than forty-five remote sites and more than fifty remote users between IPsec and SSL VPN, applying the web filter and application filter to ensure a secure connection."
  • "I would like to see the SD-WAN feature improved."

What is our primary use case?

We use this solution for IPsec & site-to-site SSL VPN.

My environment involves connecting all of our branches with the head office through one Sophos XG 210 device. This is done using IPsec and SSL VPN, after which we apply a web filter, as well as an application filter to ensure that we are getting a secure connection.

How has it helped my organization?

It allows me to easily connect with more than forty-five remote sites and more than fifty remote users between IPsec and SSL VPN, applying the web filter and application filter to ensure a secure connection.

This solution also gives me varieties of VPN policies for good data encryption.

What is most valuable?

The most valuable features of this solution are:

  • High Availability between IPsec site tunnels provides a valid continuous connection and ensures we have no downtime affecting our business.
  • Log Viewer allows me to monitor all incoming and outgoing traffic, as well as view and block vulnerabilities.

What needs improvement?

I would like to see the SD-WAN feature improved. I want to manage many lines and load-balance them, getting high availability by making SLA tests according to:

  1. Check interval.
  2. Failures before inactive.
  3. Restore link after.
  4. SD-WAN Rules to control bandwidth, download and upload stream.

For how long have I used the solution?

We have been using this solution for more than four years.

Which solution did I use previously and why did I switch?

I switched to Sophos as it is more reliable.

What's my experience with pricing, setup cost, and licensing?

This solution is less expensive than FortiGate. 

Which other solutions did I evaluate?

We did not evaluate other solutions prior to choosing this one.

Disclosure: My company has a business relationship with this vendor other than being a customer: Sophos XG
PeerSpot user
Buyer's Guide
Sophos UTM
March 2024
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,886 professionals have used our research since 2012.
PeerSpot user
Senior Technical Consultant with 51-200 employees
MSP
Sophos UTM vs. Fortinet FortiGate

I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main hang-ups will be with the VIP/load balancing and SSL. For some reason that completely escapes me, both of these vendors make getting valid certificates onto their boxes unnecessarily difficult -- the Fortinet appliances more so than the Sophos UTM appliances. At one point a Fortinet engineer had to write an entire manual on how to get an SSL certificate uploaded successfully on the 4.x firmware.

Sophos: The one feature that is missing (and this makes some amount of sense) from the Sophos appliance is BITS caching for updates. Other than that, Sophos offers a full replacement for TMG on UTM9. The XG platform also offers a replacement for the TMG; however, some of the rumblings about upcoming releases suggests that Sophos is going to give XG the Apple iOS treatment and "streamline" the interface...potentially cutting out/hiding some functionality. On the effectiveness of the NGFW, Sophos is mostly good but has a few issues blocking all pieces of an application. For instance, we had to build custom blocking rules for OpenVPN (the vpn was being used to bypass the content filter) because the default Application Control wasn't effectively blocking the application.

Fortinet: If it wasn't for Fortinet's terrible tech support we would still be deploying Fortigates exclusively. So perhaps that answers your last question right upfront. FortiWeb is not absolutely required for what you are proposing; however, the FortiWeb does make the transition from TMG much easier as the FortiWeb is purpose-built to do what you are requiring. Related, the AD-integration used with Fortinet is one of the strongest implementations we have used: The SSO agents ability to poll data from the DCs without an agent allows the use of SSO with non-Windows machines that are bound to AD, which we have used extensively at both educational institutions and shops running CentOS. Transitioning to Fortinet is relatively simple: The UI makes a lot more sense than it did in the old 4.x releases, the firewall rules are straight-forward, and the reverse proxy settings are well-documented.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user326337 - PeerSpot reviewer
it_user326337Customer Success Manager at PeerSpot
Consultant

Mark, how has your experience with Firewall security been since this past January?

See all 5 comments
RobertMaalouf - PeerSpot reviewer
Network and Security Specialist at Tetracom S.A.L
Real User
It blocks malware and other unauthorized apps
Pros and Cons
  • "Installing Sophos UTM is straightforward. The deployment itself doesn't take long, but you have to spend some time planning and waiting for the hardware to be delivered."
  • "Sophos customer support could use some improvement."

What is our primary use case?

We use Sophos UTM for multi-site VPN, quarantine, sandboxing, and IPF. It blocks malware and other unauthorized apps. 

For how long have I used the solution?

I've been using Sophos UTM for more than four years.

What do I think about the stability of the solution?

Sophos UTM is stable and ready for customization. 

What do I think about the scalability of the solution?

Sophos UTM is scalable. We have around 100 users, including engineers, managers, and computer scientists. We plan to increase our usage in the future. 

How are customer service and support?

Sophos customer support could use some improvement. 

Which solution did I use previously and why did I switch?

We were using something else, but we switched to Sophos because it's politically neutral. 

How was the initial setup?

Installing Sophos UTM is straightforward. The deployment itself doesn't take long, but you have to spend some time planning and waiting for the hardware to be delivered. 

What's my experience with pricing, setup cost, and licensing?

Sophos UTM should be more open-source and reduce its license cost. 

What other advice do I have?

I rate Sophos UTM 10 out of 10. If you're considering Sophos UTM, I would say go for it. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Director with 11-50 employees
Real User
Secure and stable with an easy initial setup
Pros and Cons
  • "With Sophos, we have not had any incidents this year. The security provided has been good. It has proven to be okay for our needs."
  • "The solution needs to do better at covering mobile devices, although they may have an integrated solution for that purpose."

What is most valuable?

During the pandemic, telework grew, however, so did attacks. There was a higher degree of ransomware and so on. With Sophos, we have not had any incidents this year. The security provided has been good. It has proven to be okay for our needs.

The initial setup is very simple.

The solution is stable.

the scalability is good.

What needs improvement?

The solution needs to do better at covering mobile devices, although they may have an integrated solution for that purpose. 

I don't really know how it behaves when it comes to web server protection. We have no web servers of our own. I don't know how it behaves if we open our servers to the outside. My sense is that the degree of protection must be higher.

For how long have I used the solution?

We haven't used the solution for very long. We've been using it for less than a year at this point. 

What do I think about the stability of the solution?

The stability has been good. There are no bugs or glitches. It doesn't crash or freeze. It's reliable. 

What do I think about the scalability of the solution?

The scalability on offer is quite good. If a company needs to expand, it can do so. 

We are not a big company. We have about 70 or so people. 

How are customer service and support?

Technical support is okay. It is provided by a local company, not Sophos directly.

Which solution did I use previously and why did I switch?

Previously we did not have any integrated solutions. We had an antivirus of one kind, and a firewall of another. It was a good step for us to integrate all these features into one solution.

How was the initial setup?

The initial setup was simple and straightforward. The deployment was fast. It only took about a week or so, maybe less. 

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable. Of course, the customer would always like it to be lower, however, the quality to price ratio is positive.

Which other solutions did I evaluate?

I'm also aware of Fortinet options, however, they are more expensive if you look at Fortinet vs Sophos. 

What other advice do I have?

We are customers and end-users. We came into the pandemic situation needing a VPN and the one offered by the Sophos behaves quite well. From the point of view of our users, it has been a positive experience.

I don't quite know by heart the version of the solution, however, it's quite recent. It's not the newest one. I saw that the brand new one which came out this year and we don't have that.

I'd rate the solution at an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Technical Manager at Digital World
Real User
Easy to install, scalable, and stable
Pros and Cons
  • "It's a stable solution."
  • "We need to speed up the support."

What is our primary use case?

We use this solution as a firewall, for DCP filtering, applications, and training.

What needs improvement?

We need to speed up the support.

For how long have I used the solution?

We have been using this solution for three years.

What do I think about the stability of the solution?

It's a stable solution.

What do I think about the scalability of the solution?

It is a scalable solution but the only disadvantage is that when we use a proxy, we can bypass Sophos.

We have 50 customers. The maximum number of users in one device is approximately 4,000. It's a large network.

How are customer service and technical support?

The support is okay, but it takes time to connect to the support team.

How was the initial setup?

It is easy to install.

We only require one engineer to deploy and maintain this solution.

What's my experience with pricing, setup cost, and licensing?

The appliance should be purchased and there is a fee for the license.

There is an option for a yearly licensing fee or for three years.

What other advice do I have?

We recommend this solution. We complete between 20 and 30 installations per month.

I would rate Sophos UTM a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
it_user163662 - PeerSpot reviewer
Founder at a tech services company with 51-200 employees
Consultant
Sophos UTM helps us to control incoming and outgoing network traffic. Not a highly available and scalable product.

What is most valuable?

Valuable Features include Sophos Remote Access VPN, Country Based Firewall, Web Application Firewall, Ease of access (via browser) and Reporting.

How has it helped my organization?

Sophos UTM helps us to control incoming and outgoing network traffic. It also helps employees connect to the AWS VPC environment from remote locations. Web application firewall protects applications from different hacking attempts like SQL Injection, Cross site scripting, Cookie signing, URL hardening etc. On top of that, it also helps the organization adhere to compliance rules and provides an audit trail of the environment.

What needs improvement?

Sophos UTM is not a highly available and scalable product. Till now, it is a single point of failure.

For how long have I used the solution?

2.5 years.

What was my experience with deployment of the solution?

No issues encountered. We had a very smooth deployment.

What do I think about the stability of the solution?

No issues with stability.

What do I think about the scalability of the solution?

Yes. Sophos UTM on AWS is not an scalable product. Sophos is actively working on scalability part from using a UTM manager which can control configuration deployment on multiple UTM's

How are customer service and technical support?

Customer Service:

Customer service level is top notch.

Technical Support:

Very Good. All our queries were properly answered on time.

Which solution did I use previously and why did I switch?

Yes. Earlier, we had used Checkpoint. But the deployment procedure and user interface for Checkpoint was very complicated. The amount of time to invest in checkpoint is nearly 2x than Sophos. Checkpoint requires tool to be installed on your system while Sophos is a browser based tool.

How was the initial setup?

It was a very straightforward setup. As it is a browser based tool, it helps administrator to access it from different location and system. We don't have to download desktop clients on our local system. Also, we can access this product from different operating systems (linux, windows and Mac).

What about the implementation team?

We deployed it in-house.

What was our ROI?

ROI for the product is very high. The cost of the product is based on the number of users and the licensing is not too expensive.

What's my experience with pricing, setup cost, and licensing?

On AWS, instances/servers are charged on hourly basis. The yearly licensing cost for 10 years is nearly around $200-300.

Which other solutions did I evaluate?

While we were looking for deployment of UTM product on AWS in year 2011, there were only 2 stable products available in market i.e., Sophos and Checkpoint. We choose to go ahead with Sophos.

What other advice do I have?

Easy to use, Easy to access, good for compliance. It is a very good product as compared to others available on AWS.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user297576 - PeerSpot reviewer
it_user297576IT and Data Security Manager at a tech services company
Consultant

The Sophos UTMs are highly available you just need 2 or more. You can also have them in active active or active passive mode

See all 2 comments
Osama Tobji - PeerSpot reviewer
Chief Information Technology Officer at AcenTek
Real User
It's a good value and priced better than many competing solutions, but it should integrate more advanced threat detection
Pros and Cons
  • "Sophos UTM provides security for our network here and access through a VPN connection for our remote users. It also offers the flexibility to create different tools for accessibility."
  • "I would like to see Sophos UTM add support for all the new threat-detection technologies and the ability to respond to novel security threats that come along every day."

What is most valuable?

Sophos UTM provides security for our network here and access through a VPN connection for our remote users. It also offers the flexibility to create different tools for accessibility.

What needs improvement?

I would like to see Sophos UTM add support for all the new threat-detection technologies and the ability to respond to novel security threats that come along every day.

I'm in the process of switching every UTM device in all branches to Sophos, so I need visibility into each branch to see the activity. I need alerts for any threat that enters the network. If there is unauthorized access or some specific action that can threaten my network, I want to be notified.

For how long have I used the solution?

We've been using Sophos UTM for the last three years.

What do I think about the stability of the solution?

Sophos UTM is stable so far. 

What do I think about the scalability of the solution?

I haven't had the need to scale up Sophos UTM so far, but I believe it's scalable.

How are customer service and support?

We have excellent technical support. The company that supports us is highly experienced with Sophos.

Which solution did I use previously and why did I switch?

We previously had Cyberoam. After Sophos acquired Cyberoam, we purchased new Sophos hardware devices.

What's my experience with pricing, setup cost, and licensing?

Sophos UTM is priced in the middle range. Okay. It's a good value and a far better price than many competing solutions.

What other advice do I have?

I rate Sophos UTM seven out of 10.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2024
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros sharing their opinions.