The most valuable features of Sophos XG are user-friendliness and it is highly secure.
Branch Manager at a non-profit with 1,001-5,000 employees
Helpful support, secure, and user-friendly
Pros and Cons
- "The most valuable features of Sophos XG are user-friendliness and it is highly secure."
- "Sophos XG could improve by making the remote access and VPN better."
What is most valuable?
What needs improvement?
Sophos XG could improve by making the remote access and VPN better.
For how long have I used the solution?
I have used Sophos XG within the last 12 months.
What do I think about the stability of the solution?
Sophos XG is a stable solution.
Buyer's Guide
Sophos XG
December 2025
Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The scalability of the solution is good. We have approximately 4,000 concurrent users.
How are customer service and support?
The Sophos XG technical support we receive from our local vendor, they are very helpful.
What other advice do I have?
I would recommend this solution to others. I have recommended it to many organizations already. I have had a very good experience with the Sophos XG.
I rate Sophos XG an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Architect at a consultancy with 11-50 employees
Lacking security, poor search tool, but stable
Pros and Cons
- "The performance of Sophos XG is generally good and it is stable."
- "The security of Sophos XG could be improved."
What is our primary use case?
Sophos XG is a firewall and we use it to create networking rules.
What needs improvement?
The security of Sophos XG could be improved.
Sophos wants to move all things to the cloud, including access to the end-user PCs and data from the cloud. What will be easier to hack for a customer with an outdated firewall, or the Sophos cloud could get hacked which has all the access and information from customers. With my experience, it's not a question of if they will hack it, but a question of when they will do it. I'm not happy with the direction Sophos is going on.
We have problems with the use of the user interface. You have a poor search engine for objects via which you can write new rules. You have to start at the beginning of the whole object name. With the Sophos UTM, you can start with a pattern, with part of the whole word. In Sophos UTM it will list you all the hits with parts of what you type, and that does not happen on the Sophos XG.
For how long have I used the solution?
I have been using Sophos XG for approximately 10 years.
What do I think about the stability of the solution?
The performance of Sophos XG is generally good and it is stable.
What do I think about the scalability of the solution?
I have found the scalability of Sophos XG the same as Sophos XG.
We have approximately 10 clients using this solution.
How are customer service and support?
Since Sophos XG moved the support from London to somewhere in the world, such as India, it's a little bit longer to receive a fast response. They are knowledgeable but they are slow to make decisions. For example, we had a firewall and the hardware was defect. It was really clear, but we had to have a long discussion for them to be able to send us the new firewall. It took one or two weeks until the supporter was able to talk to someone who can make the decision. This is too long, this process could be streamlined.
How was the initial setup?
The initial setup is straightforward . As long as you buy the appliances from Sophos, it works very well. However, in some cases, we have to use our own servers because they have more power and more network bandwidth.
What about the implementation team?
The amount of users needed for the implementation and maintenance depends on the size of the customer's infrastructure.
What's my experience with pricing, setup cost, and licensing?
There is a license required to use this solution and my customers pay for it annually.
What other advice do I have?
I am not amazed by this solution.
I rate Sophos XG a four out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Sophos XG
December 2025
Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
Network Engineer at a tech services company with 201-500 employees
Reliable and flexible for small and large companies, but has some feature issues to resolve
Pros and Cons
- "Sophos XG Firewall is very usable, very easy to install, and very user friendly."
- "We are facing some problems on this firmware version, version 18, that require improvement. We want to improve the email security because it doesn't give proper security with the data protection. Also, our clients are facing some problems where most of the sites which they're accessing are getting blocked. I want to improve those sites, that email security, and the data protection on the Firmware version 18."
What is our primary use case?
You can use Sophos XG in small or large companies. In a small company we are using it as a router and firewall. In larger company, like in the Bangladesh government, they are using Sophos Firewall in various sites, including the Bangladesh Navy. Many of the sites are using Sophos Firewall as a router and firewall and also for security purposes.
How has it helped my organization?
Sophos XG Firewall is for security purposes and we are also using it as a router. Wherever we are deploying it as a router we are mapping and also port forwarding. More clients take it as a router and also a firewall.
What is most valuable?
Sophos XG Firewall is very usable, very easy to install, and very user friendly.
The features that I have found most valuable are the infiltration prevention and data protection. We provide immune security. There are also many features on the VPN. We provide a social VPN. We deployed so many features.
What needs improvement?
We are facing some problems on this firmware version, version 18, that require improvement. We want to improve the email security because it doesn't give proper security with the data protection. Also, our clients are facing some problems where most of the sites which they're accessing are getting blocked. I want to improve those sites, that email security, and the data protection on the Firmware version 18. Also, sometimes it gets frozen and we cannot access it. After we shut it down and restart, then it's perfect. That's a point that we want to improve.
In the next release, I want them to please improve version 18 so that it has more features and is more user friendly and it should have a VRF option.
For how long have I used the solution?
We are using Sophos XG for five years.
What do I think about the stability of the solution?
Sophos XG is stable.
Maintenance, once it is established on the network, requires about two to three people dedicated to Sophos Firewall. We have to give about two to three days monthly.
What do I think about the scalability of the solution?
Scalability is good.
We have about a thousand or more users and have plans to increase usage of this product.
How are customer service and support?
The Sophos support team is good now.
How was the initial setup?
Initial setup is easy. It took about one hour to do the initial setup.
What about the implementation team?
I am an implementer so I deployed it by myself.
What's my experience with pricing, setup cost, and licensing?
Sophos XG is on a subscription basis. We can take a one year or two year subscription.
What other advice do I have?
On a scale of one to ten, I will give Sophos XG a seven.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Security Engineer at a financial services firm with 5,001-10,000 employees
Good filtering and application control features, but the bandwidth could be more effective
Pros and Cons
- "Some of the most valuable features are filtering and application control. The DDoS detection also shows traffic jamming and traffic shaping."
- "This solution could be improved with more effective bandwidth. I found that when I enable DDoS detection for our clients, bandwidth is reduced. If DDoS detection is disabled, the bandwidth will be high, but it isn't secure. We recommend that customers enable DDoS detection, but if they need high bandwidth, we recommend Palo Alto and FortiGate instead of Sophos."
What is our primary use case?
We provide Sophos XG to customers. We work at deploying this solution from scratch to the customer, from unboxing, racking, or stacking, and doing licensing and upgrades for the box. Then we establish the process and security profiles that the customer requires.
This solution is deployed on-prem.
What is most valuable?
Some of the most valuable features are filtering and application control. The DDoS detection also shows traffic jamming and traffic shaping.
What needs improvement?
This solution could be improved with more effective bandwidth. I found that when I enable DDoS detection for our clients, bandwidth is reduced. If DDoS detection is disabled, the bandwidth will be high, but it isn't secure. We recommend that customers enable DDoS detection, but if they need high bandwidth, we recommend Palo Alto and FortiGate instead of Sophos.
For how long have I used the solution?
I have been using Sophos XG for about six months.
What do I think about the stability of the solution?
This solution is not as stable as other products. In terms of stability, our number one recommendation is Palo Alto, number two is FortiGate, and number three is Sophos.
What do I think about the scalability of the solution?
Sophos is scalable, but not enough.
How are customer service and support?
Sophos technical support is effective.
How was the initial setup?
The installation takes two days. It is easy to deploy, and not as complicated as Palo Alto or FortiGate. We make it in our company labs and, for deployment and maintenance, we recommend one or two people.
What about the implementation team?
We provide and implement this solution for customers.
What's my experience with pricing, setup cost, and licensing?
The licensing for Sophos XG is based on the number of users, so I get the module from the sizing of the customer.
Which other solutions did I evaluate?
We also recommend that customers use FortiGate and Palo Alto, since these solutions are more stable and have more effective bandwidth.
What other advice do I have?
I rate Sophos XG a seven out of ten. I would recommend it to others, based on their needs, but the stability could be better.
We have five to seven customers who are using Sophos XG.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Managing Director at a media company with 51-200 employees
Reliable, user-friendly, and provides good endpoint protection
Pros and Cons
- "Sophos XG is easy to use."
- "The only area that requires improvement is scalability."
What is our primary use case?
The majority of our customers use Sophos XG as a traditional firewall. Some use it for endpoint protection, which is similar to anti-virus.
We also have customers that have SD-WAN as part of their use case. For the most part, it is a firewall, it depends on what the customer environment looks like that would determine how you're going to configure the appliance to work for the customer.
Technology can deliver what you want based on your environment, what you do may differ from what others do.
We have customers from insurance, some oil, and gas, as well as some from the banking sector. Based on the technicality and the peculiarities of the environment, we must explain the technology, of how Fortinet delivers its own firewall, and also others such as Check Point, and Palo Alto deliver their own firewall.
With the explanation given the customer can choose the solution, they want in their environment.
What is most valuable?
Sophos XG is easy to use.
What needs improvement?
The only area that requires improvement is scalability.
I understand why scalability is difficult in all firewalls. I understand why it is difficult in our firewalls. If you want to scale, you can scale vertically or horizontally. That is the world of scalability. However, you cannot do so for the firewall. It's a forklift, you have to buy a new appliance.
For how long have I used the solution?
We have been deploying Sophos XG for our customers for many years.
What do I think about the stability of the solution?
The stability is based on the environment.
What do I think about the scalability of the solution?
Every firewall solution has a different level of scalability. The majority of firewalls are based on the user. Scalability, in Sophos XG, requires a forklift.
The scalability could be improved.
We have between 12 and 16 customers.
How are customer service and support?
I have never contacted technical support.
How was the initial setup?
We have deployed more Sophos this year than in any previous year.
I have six engineers dedicated to deploying and maintaining the solution.
What's my experience with pricing, setup cost, and licensing?
It is a price-based solution, not based on technology.
Licensing fees are paid on a yearly basis.
What other advice do I have?
I would recommend this solution to others who are interested in using it.
I would rate Sophos XG an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Tech Doctor at a recruiting/HR firm with 11-50 employees
Easy to manage, reasonable price, and very stable
Pros and Cons
- "Compared to other firewalls that I had looked at, I thought Sophos was the better solution. It just seems to be easier to manage versus Cisco, Fortinet, or one of the other options I was looking at."
- "I'm just a sole proprietor for IT support, and from my perspective, there could be better ways to educate a proprietor, such as myself, on how to set it up, and program it, and manage it. They do tend to have support, but a lot of times, it is for larger networks. I need something that is simpler and more rudimentary as to how to go about setting up and configuring the firewall, setting up the rules, and that type of thing. So, if there is a missing component there, that would be it."
What is our primary use case?
I implemented this firewall for my clients. They're small offices. One has got half a dozen computers, and the other one has about 30 computers on the network. Both utilize VPN to remotely access their workstations in the office.
It is sized based on the client. So, there are actually two different versions that I've utilized.
How has it helped my organization?
VPN setup is great and easy to implement for outside users to access data or workstations in the network. Easy to manage and set up. No major glitches. Runs reliably. Setting up iPhones and Macs is a bit more involved since you have to use VPN apps that are compatible with Apple for VPN and remote desktop.
What is most valuable?
Compared to other firewalls that I had looked at, I thought Sophos was the better solution. It just seems to be easier to manage versus Cisco, Fortinet, or one of the other options I was looking at.
I'm not going to say that it's easy to configure, but I can understand how to configure it. There is a certain amount of support available to do the configurations.
What needs improvement?
I'm just a sole proprietor for IT support, and from my perspective, there could be better ways to educate a proprietor, such as myself, on how to set it up, program it, and manage it. They do tend to have support, but a lot of times, it is for larger networks. I need something simpler and more rudimentary to set up and configure the firewall, set up the rules, and that type of thing. So, if there is a missing component there, that would be it.
Any firewall will need rules for how it protects the network against a variety of threats or various degrees of protection. My comments are not aimed at Sophos specifically. As a new person just learning about firewall protection, it would be helpful for any vendor to have an education area that runs through various scenarios and implements them in the firewall. Videos would be helpful. From my initial research on which firewall to choose, Sophos appeared to have the most straightforward interface.
I purchased the units from www.firewalls.com, and they worked with me to do the initial setup. That was very helpful to get started
For how long have I used the solution?
I have been using Sophos XG for 4 years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
It is scalable. There are different models, and you really need to choose a model that is appropriate for your current situation. You can buy something with a certain degree of scalability. Because I purchased it through firewalls.com, I was able to have that discussion, describe the application, and then choose a model that would suit that particular client with a degree of scalability. Now, for instance, if they went from 20 employees to 500 employees, then it is not scalable to that degree, but if they went from 20 employees to 50 employees, then it would be scalable. So, you've got to define the criteria in terms of what you're trying to protect, the number of users, the bandwidth that is going through it, the speed, etc. When I purchased them through firewalls.com, they explained and helped me choose the most appropriate appliance for what I'm doing.
How are customer service and support?
I did have a circumstance where the firewall had been damaged during a lightning storm or something like that, and I called them to help me diagnose what the issue was. They were good about the diagnostic. They were good about spending the time with me to figure out what was wrong. In the particular case that I was researching, it turned out that one of the ports was bad for some reason. It was either because of the lightning storm or some other reason. It was under warranty, and they replaced it with a new unit. So, I'm satisfied with Sophos' support.
Which solution did I use previously and why did I switch?
Previously used a small $100 cisco unit. Not easy to implement VPN. They may have an app, now, but at the time it was problematic and way too complicated.
How was the initial setup?
I purchased it through firewalls.com. They're an online vendor, and they did the initial setup and configuration on both firewalls. My experience with them was good.
What about the implementation team?
I used firewalls.com and they were excellent
What was our ROI?
Fewer management headaches
What's my experience with pricing, setup cost, and licensing?
The pricing was reasonable. VPN licensing is included.
Which other solutions did I evaluate?
I looked at Cisco, Fortinet, and one of the others, and compared to them, I thought Sophos was the better solution. It seemed to be easier to manage. After the implementation, I could figure out what to do with a Sophos interface. If it was something like Cisco or other vendors, it would be far more complicated to deal with. So, that's one of the reasons why I chose Sophos.
What other advice do I have?
For someone who is not acquainted with firewalls, whether it is Sophos or anything else, dealing with a third party for the implementation is kind of a must.
I am satisfied with this solution. I don't really have any hands-on experience with other firewalls that I can compare it against, but I'm satisfied with it. I like it, and I'd buy it again.
I would rate Sophos XG a 10 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PPC at a renewables & environment company with 501-1,000 employees
Offers good traffic control, has an easy setup, and is stable
Pros and Cons
- "The updates are helpful and add to the solution in a positive way."
- "The pricing has gotten much higher."
What is our primary use case?
We primarily use the solution for gateway purposes, in order to provide us with gateway security.
What is most valuable?
The product is good in terms of routing multiple ISP Internet and also it's good in internet traffic control.
The updates are helpful and add to the solution in a positive way.
The initial setup is simple.
The solution is stable.
For the most part, you can easily scale the solution.
What needs improvement?
I'm not seeing any such things that require any improvement. It's good. From time to time, some updates will come through. It's meeting our requirements right now.
The pricing has gotten much higher.
For how long have I used the solution?
We've been using the solution for three years. It's been a while now.
What do I think about the stability of the solution?
The stability and performance are excellent. There are no bugs or glitches. It doesn't crash or freeze. It's very reliable.
What do I think about the scalability of the solution?
We have 50 users spread across three devices.
The solution, in terms of scalability, has its limitations, of course. Scalability in the sense of if I want to add more ISPs all depends upon my port availability. Transitions and migrations are fine and doable. I don't find any challenges there.
How are customer service and support?
Technical support from Sophos has been brilliant. We deal with them on any L3 issues and they are always helpful.
How was the initial setup?
The initial setup is very straightforward and simple. it's not overly complex or difficult.
The deployment was quick and took maybe one day.
In terms of maintenance requirements, We have an L1 technical person who will take care of all the routine maintenance of the firewall, and we also have L2 support with the vendor. We have an L3 support from the Sophos team itself.
What about the implementation team?
We did the implementation with the assistance of a vendor. We did not completely handle it ourselves.
What's my experience with pricing, setup cost, and licensing?
While, at first, the pricing was very good, it's since crept up. Now, upon renewal, it's pretty high. They've increased the costs.
Currently, we have three devices that are similar. Only the capacity varies.
What other advice do I have?
I'm a customer and an end-user. I don't have a business relationship with Sophos.
I'd recommend the solution to other users and organizations. I'd rate it at a ten out of ten. it's the best.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior System & Security Administrator at a retailer with 51-200 employees
It has a good interface that's very user-friendly
Pros and Cons
- "I've tried out Sophos XG a little. It has a good interface that's very user-friendly, but I haven't used all of its functions because I'm only configuring and running the system."
- "I would prefer if Sophos XG were cheaper. A lower price would benefit me as a system provider for the end customer. The cost of the license and renewal for all the software and devices is somewhat high."
What is most valuable?
I've tried out Sophos XG a little. It has a good interface that's very user-friendly, but I haven't used all of its functions because I'm only configuring and running the system.
For how long have I used the solution?
I've been working with Sophos XG for six months. I am not an end-user. I only provide the solution and implementation.
What do I think about the stability of the solution?
I think Sophos XG is very stable because the users who have installed it never mention any issues. It's very stable and scalable.
What do I think about the scalability of the solution?
Sophos XG is a scalable solution. Our clients who use Sophos are not big companies.
How are customer service and support?
I haven't dealt with Sophos support because I'm just doing the basic implementation for the Sophos. But I Sophos support is very experienced and helpful. Sophos has a team for administration and implementation—a good team to improve the application.
How was the initial setup?
It depends on the implementation and the deployment of systems. In my small company, I have four people on my technical team. Two of them specialize in firewall and security. They're working on Fortinet. They deal with antivirus and security implementation as well as Veeam Backup. The other two handle the administration implementation, including Active Directory and other administration solutions.
What's my experience with pricing, setup cost, and licensing?
I would prefer if Sophos XG were cheaper. A lower price would benefit me as a system provider for the end customer. The cost of the license and renewal for all the software and devices is somewhat high.
What other advice do I have?
I rate Sophos XG nine out of 10. I am a Fortinet partner. If a user asks me which solution to buy, I'll tell them Fortinet. But if the customer needs Sophos, I will implement it for him. However, if I had a Sophos partnership, I would recommend it every time.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Meraki MX
Check Point Quantum Force (NGFW)
Azure Firewall
SonicWall TZ
Sophos XGS
Fortinet FortiGate-VM
Juniper SRX Series Firewall
SonicWall NSa
KerioControl
Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos XG 210 vs Fortigate FG 100E
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What is the biggest difference between Sophos XG and FortiGate?
- Which firewall is better and why: Sophos XG 210 or Fortinet FortiGate 100E?
- Which solution do you prefer: Fortinet FortiGate or Sophos XG?
- What are the main differences in features between Sophos XG and FortiGate 80F?
- Fortinet FortiGate or Sophos XG?
- How does Meraki MX compare with Sophos XG?
- Which firewall to choose for an SMB to prevent malware damage: Cisco Firepower or Sophos XG?
- Looking for a technical comparison between Sophos XG550 and Fortinet FortiGate 600E















