We use it for VPN and for filtering direct traffic. We are using XG50.
ICT/HMIS Supervisor at a healthcare company with 501-1,000 employees
A stable and seamless solution with good support and useful VPN and filtering features
Pros and Cons
- "The VPN feature is the most valuable. It has come in handy during this period when people are working from home. The filtering feature is also valuable because you can easily filter the sites that you don't want to visit. You can also set timely surfing quotas."
- "They made some changes to the firmware update sometime last year, which moved some of the policies from where they were before. Some of the policies, such as NAS policies, were separated, which made it a bit hard for people to trace the policies they had configured."
What is our primary use case?
What is most valuable?
The VPN feature is the most valuable. It has come in handy during this period when people are working from home.
The filtering feature is also valuable because you can easily filter the sites that you don't want to visit. You can also set timely surfing quotas.
What needs improvement?
They made some changes to the firmware update sometime last year, which moved some of the policies from where they were before. Some of the policies, such as NAS policies, were separated, which made it a bit hard for people to trace the policies they had configured.
For how long have I used the solution?
I have been using this solution for three years.
Buyer's Guide
Sophos XG
December 2025
Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
What do I think about the stability of the solution?
It has been very stable. We haven't had any outages. It has been seamless.
What do I think about the scalability of the solution?
I am not quite sure about that. In terms of the number of nodes, we have around 200 nodes. All the internet traffic has to go through Sophos XG. In terms of the number of people who handle the support, we have two people.
How are customer service and support?
Their technical support is good. Whenever I have contacted them, they have given us support. They have been quite fast.
Which solution did I use previously and why did I switch?
We were using Cyberoam. When they were acquired, we just upgraded to Sophos because, at that time, they were providing the hardware and support to transfer your configs to Sophos.
What about the implementation team?
Its initial setup was done by a contractor. We just maintain it. We have an expert, and we also have access to an IT department.
What's my experience with pricing, setup cost, and licensing?
In terms of price, it is a mid-range product.
What other advice do I have?
I would recommend this solution. I would rate Sophos XG an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
ICT Manager at a hospitality company with 1,001-5,000 employees
Easy to use, scalable, and fairly stable, but needs simplified interface and better security
Pros and Cons
- "We find it easy to use. Its internal configuration is very easy. It is not complicated in terms of use and configuration. It has been fairly stable, and it is also scalable."
- "They can simplify its interface so that it is mostly drag-and-drop. There was an SQL injection attack on some Sophos devices. They just need to harden their devices a little bit so that they can't be hacked very easily."
What is our primary use case?
We are using it at a gateway level. We are using Sophos XG Series 135.
What is most valuable?
We find it easy to use. Its internal configuration is very easy. It is not complicated in terms of use and configuration.
It has been fairly stable, and it is also scalable.
What needs improvement?
They can simplify its interface so that it is mostly drag-and-drop. There was an SQL injection attack on some Sophos devices. They just need to harden their devices a little bit so that they can't be hacked very easily.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
It has been fairly stable.
What do I think about the scalability of the solution?
It is scalable. We had scaled it for the number of users that we have, and it has worked fine for us. We have around 40 users.
How are customer service and technical support?
We rarely contact their technical support. There was a time when our head office contacted their technical support. It was an issue in 2008, and they provided a patch.
Which solution did I use previously and why did I switch?
We used Cisco ASA five or six years ago.
How was the initial setup?
We found it easy to install. Its installation took around one to one and a half hours.
What about the implementation team?
I did it myself. I have had some training on the product. In terms of support, we have just two guys who handle the support. Two people are enough for its deployment and maintenance.
What other advice do I have?
I would recommend this solution. It is a fairly stable and good solution. We will keep on using it.
I would rate Sophos XG a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Sophos XG
December 2025
Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
Service Delivery Engineer - Network Security Lead at a tech services company with 51-200 employees
Simple to use, simple to manage, and simple to administer
Pros and Cons
- "The most valuable feature is the Intercept X. It is the advanced features that are used for malware detection, and antivirus."
- "Sophos can definitely improve with the interoperability between solutions."
What is our primary use case?
This firewall is part of the security solution that is implemented in medium-sized enterprises.
We are using it for endpoint and user security for laptops and mobile phones.
What is most valuable?
The most valuable feature is the Intercept X. It is the advanced features that are used for malware detection and antivirus. It's similar to antivirus on steroids.
It's simple to use and has a simple interface. It's generally straightforward and configuration-wise, it's not complex.
It's a very simple product to use and that's why you find it is used mostly in small to medium-sized enterprises. They don't have the manpower that a large organization can have, in terms of the skilled workforce when it comes to cybersecurity. They just need something that is simple to use, simple to manage, and simple to administer, but effective at the same time. That's the main selling point for Sophos.
What needs improvement?
I have not used their SD-WAN product or the SD-WAN feature, so I don't know how scalable the SD-WAN is. But, I hope just that the SD-WAN is up to par with FortiGate.
The integration is an area that can improve a bit. One of the other solutions that I have used that is highly interoperable is Fortinet. It's easy to integrate with other products.
Sophos can definitely improve with the interoperability between solutions.
For how long have I used the solution?
I have been using Sophos XG for a year and a half.
We are using the latest version.
What do I think about the stability of the solution?
It is very stable. I've not had any issues with it.
In terms of bugs, I've not had any bugs, or I've not encountered any bugs when deploying Sophos or administering Sophos products.
What do I think about the scalability of the solution?
In terms of scalability, it's very scalable because they have different sized firewalls for different requirements or different specifications.
It is also able to do high availability, so it's very scalable.
Currently, in our organization, we have coverage with Sophos Intercept X Endpoint Protection. We have 49 employees. We plan to continue to use this solution.
We are currently subscribed to a three-year product and will be using it for a duration of three years.
How are customer service and technical support?
I have not had any cases where I had to log technical support, but I believe it would be fast enough in case I needed to reach out to them.
Which solution did I use previously and why did I switch?
We are also using Fortinet FortiGate Firewall.
How was the initial setup?
The initial setup is very simple.
For a normal deployment with basic configuration in a medium-sized enterprise, it can take a day and a half.
If it's a complex network design then it might be three to four days.
It only requires one person to deploy and maintain this solution.
What about the implementation team?
We used an implementor and an integrator, but usually, I do it by myself.
Which other solutions did I evaluate?
The features in Sophos XG are the same features you would find in Palo Alto or Fortinet.
What other advice do I have?
I just like it the way it is. I wouldn't recommend any changes to it, because what they have is working and it's working very well. It is a product that I definitely recommend to others.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
ICT Manager at a financial services firm with 201-500 employees
A fast, agile, and stable solution that is easy to deploy and manage
Pros and Cons
- "Orchestration of the firewall is the most valuable feature. It is a fast and agile solution. It is good with protection. It is also very easy to deploy and manage, and its user interface is easy to use."
- "They can lower its price. It is very expensive. We are looking for a less expensive solution depending on our budget. They can also improve it in terms of firewall protection."
What is most valuable?
Orchestration of the firewall is the most valuable feature. It is a fast and agile solution. It is good with protection. It is also very easy to deploy and manage, and its user interface is easy to use.
What needs improvement?
They can lower its price. It is very expensive. We are looking for a less expensive solution depending on our budget. They can also improve it in terms of firewall protection.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
It is very agile.
Which solution did I use previously and why did I switch?
We didn't have any other similar solution previously.
How was the initial setup?
It is very easy to deploy.
What's my experience with pricing, setup cost, and licensing?
It is very expensive.
What other advice do I have?
I would rate Sophos XG a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Support Executive at a healthcare company with 51-200 employees
A stable and economical solution but there's room for a more customizable graphical interface
Pros and Cons
- "I recommend the solution due to its ease of use and pricing."
- "An area of improvement would be the reporting as diagnostic graphs take a long time to load and refresh. If there could be an option to show only select graphs, it may speed up the graphics."
What is our primary use case?
Our main use case of this solution is to support internal clients with virus scanning on laptops and on critical processors.
What needs improvement?
An area of improvement would be the reporting as diagnostic graphs take a long time to load and refresh. If there could be an option to show only select graphs, it may speed up the graphics.
Most of the time we don't use the disk usage, memory or CPU graphs. The main graph we watch is the bandwidth usage.
Additionally, their previous update contained many bugs. They need to ensure that, before releasing a new version, there are not so many bugs.
For how long have I used the solution?
I have been using this solution for two years.
What do I think about the stability of the solution?
The solution is stable.
Which solution did I use previously and why did I switch?
We previously used Caveo Systems, but that was about 10 years ago.
How was the initial setup?
The initial setup is very easy. The licensing and setting up of firewall rules takes some time, but the full deployment took about an hour.
What's my experience with pricing, setup cost, and licensing?
The pricing is economical.
What other advice do I have?
I recommend the solution due to its ease of use and pricing.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Manager at a agriculture with 11-50 employees
A stable, flexible, and easy-to-use solution that works well and comes with a web management portal that can be accessed from anywhere
Pros and Cons
- "It is stable, flexible, and easy to use. It has got a web management portal that can be accessed from anywhere."
- "I would like to have more artificial intelligence in the web monitoring service that comes with it. It should alert us when particular events happen. It has already got some of that. I know that it is more of a service, and Sophos is already looking at it. It is called SIEM."
What is our primary use case?
It can be used as a firewall, SD-WAN enabler, and secure web gateway. You can also use it for unified threat management, email detection, mobile device management, and wireless management. I use it in the cloud and on-premises, and I have its latest version.
What is most valuable?
It is stable, flexible, and easy to use. It has got a web management portal that can be accessed from anywhere.
What needs improvement?
I would like to have more artificial intelligence in the web monitoring service that comes with it. It should alert us when particular events happen. It has already got some of that. I know that it is more of a service, and Sophos is already looking at it. It is called SIEM.
For how long have I used the solution?
I have been using this solution for a few years.
What do I think about the scalability of the solution?
We have roughly 700 users who use this firewall.
How are customer service and technical support?
I have interacted with them a few times. I am very satisfied with their technical support.
Which solution did I use previously and why did I switch?
We were using FortiGate.
How was the initial setup?
It is easy to install. I have done the installation in less than a day.
What about the implementation team?
We did it ourselves. We have two people for its deployment. We have one engineer and one admin.
What's my experience with pricing, setup cost, and licensing?
It is not that expensive compared to the other solutions. It is about the same price range as Fortigate, which we used previously. Licensing is on a yearly basis.
What other advice do I have?
I would recommend this solution. We're very happy with the product. It works very well, and we don't have too many issues.
I would rate Sophos XG a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Security Administrator at a comms service provider with 501-1,000 employees
Reasonably-priced and straightforward to set up, but instability has caused problems and customer support should be improved
Pros and Cons
- "The initial setup was straightforward."
- "The first area that needs to be improved is customer support."
What is our primary use case?
We use the Sophos XG firewall as part of our security solution.
What needs improvement?
The first area that needs to be improved is customer support.
If I'm implementing a connection on the DMZ or WAN, I should be able to dive deep into the implementation, specifying what needs to be implemented or not. For example, I should be able to configure specific details for the DMZ, and not have to follow the templates that they provide.
We have had problems with the stability that affected business operations.
For how long have I used the solution?
We have been using Sophos XG for three years.
What do I think about the stability of the solution?
The issue of stability is the reason that I'm trying to move away from using Sophos as our firewall. There were times where Sophos randomly cut some users off of the internet, which adversely affected business operations. It is important because our business relies on throughput and service, like the uptime of e-commerce servers.
What do I think about the scalability of the solution?
Scalability depends on the specifications during the time of order, prior to first implementing the firewall. With respect to my organization, scalability has been okay. It comes down to the amount of money that is spent.
We have 1,200 users in the company.
How are customer service and technical support?
Customer support needs to be improved. The time they take to resolve issues is too long.
How was the initial setup?
The initial setup was straightforward. It took us less than 30 minutes. Normally, it depends on the size of your organization, so for mine, the installation was less than 15 minutes. By 30 minutes I was finished even with the setup and configuration.
What's my experience with pricing, setup cost, and licensing?
For our company, the price was reasonable.
What other advice do I have?
We are now thinking about incorporating the Fortinet next-generation firewall.
My advice for anybody who is considering Sophos is that a business with a lot of throughput and data traffic should look for another firewall.
I would rate this solution a six out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Engineer with 51-200 employees
User-friendly and helpful interface with good support that responds quickly
Pros and Cons
- "The VPN access for users is also a great thing, especially nowadays when working from home."
- "Having a web portal where you could make requests for the categorization of non-categorized items, would be beneficial."
What is our primary use case?
For the primary use cases, we use SSL VPN access for rolling remote access. We use web filtering and we use the intrusion prevention that comes with network protection.
What is most valuable?
The user interface is very user-friendly and very helpful.
The VPN access for users is also a great thing, especially nowadays when working from home.
What needs improvement?
Categorization or uncategorized websites is an area that needs improvement.
Having a web portal where you could make requests for the categorization of non-categorized items, would be beneficial.
The DLP rules don't cover countries such as Serbia. You cannot make custom rules. That could be added so that we could detect content that is not supposed to leave the company via email, and so that the rules could be customized by the clients.
We only have predefined rules and most of them are not for Serbia or countries from the Region.
For how long have I used the solution?
We have been using Sophos from the time they acquired Astaro, before that it was UTM, then they released the XG firewall.
We are using the latest version.
What do I think about the stability of the solution?
It's a stable solution. We have not experienced any issues.
What do I think about the scalability of the solution?
It's a scalable product. In the office, we have four users in our organization.
How are customer service and technical support?
Our experience with technical support has been positive.
We have support from the local distributor. We have rarely had the need to contact technical support but when we have, we have had quick responses from them.
How was the initial setup?
The initial setup is very straightforward and the implementation takes a relatively short amount of time. The fine-tuning takes a little bit more time but in general, it can be deployed and implemented quickly.
Also, the upgrades, backups, and recovery are very easy.
What about the implementation team?
We are Sophos partners, we sell them and implement them ourselves.
We only need one engineer to deploy and maintain this solution. If you have a bigger deployment then you need two engineers.
What's my experience with pricing, setup cost, and licensing?
Licensing fees are on a yearly basis.
What other advice do I have?
I can recommend this solution to others who are interested in using it.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Meraki MX
Check Point Quantum Force (NGFW)
Azure Firewall
SonicWall TZ
Sophos XGS
Fortinet FortiGate-VM
Juniper SRX Series Firewall
SonicWall NSa
KerioControl
Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos XG 210 vs Fortigate FG 100E
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What is the biggest difference between Sophos XG and FortiGate?
- Which firewall is better and why: Sophos XG 210 or Fortinet FortiGate 100E?
- Which solution do you prefer: Fortinet FortiGate or Sophos XG?
- What are the main differences in features between Sophos XG and FortiGate 80F?
- Fortinet FortiGate or Sophos XG?
- How does Meraki MX compare with Sophos XG?
- Which firewall to choose for an SMB to prevent malware damage: Cisco Firepower or Sophos XG?
- Looking for a technical comparison between Sophos XG550 and Fortinet FortiGate 600E













