We changed our name from IT Central Station: Here's why
RicardoURQUIDI
CEO at a tech services company with 1-10 employees
Real User
Migration from pfSense or Astaro is easy
Pros and Cons
  • "The two most valuable feature of Sophos XG is, one the option to filter according to different applications and two, the integration with the Active Directory."
  • "Integration with Active Directory is not reliable."
  • "Over the last six months, we have noticed that the hardware is slow, especially the VPN connections."

What is our primary use case?

We are using Sophos XG, but not the latest version. The solution works as the main gateway. We are a small company of 250 employees so we also use the solution as a router.

The hardware and VPN connections are slow so we are planning on upgrading the solution. Next month we will be replacing the Sophos XG we have as it is reaching the end of life next year. We will be purchasing the XG 3000 to gain more options in the VPN tunnels.

What is most valuable?

The two most valuable feature of Sophos XG is, one the option to filter according to different applications and two, the integration with the Active Directory.

What needs improvement?

Over the last six months, we have noticed that the hardware is slow, especially the VPN connections.

Sophos would benefit if they could improve the integration with Active Directory. It does not function consistently and we have to reconfigure it to make it function again. 

Integration with IPA, which is like Active Directory for Linux servers, would be a nice feature to include.

For how long have I used the solution?

I have been using Sophos XG for three years.

What do I think about the stability of the solution?

This solution is very stable. We have not had any problems in the three years we have been using Sophos XG. We did have one infection that gained access to one server in the DMZ but it was because the rules were not well configured and not because of the product.

What do I think about the scalability of the solution?

We haven't had to scale the solution. 

How are customer service and support?

Support from Sophos XG has been fine for what we have required.

Which solution did I use previously and why did I switch?

We had been using Astaro. We selected Sophos XG because we knew it would be easy to set up and configure as the two solutions are similar.

How was the initial setup?

Previously we were working with Astaro, so the setup and configuration of Sophos XG was easy. The implementation took less than a month.

What about the implementation team?

The company that sold the firewall solution provided support hours while we were migrating the rules of our old firewall. They provided us with advice on some of the rules, especially on the routing to connect to a branch office.

What's my experience with pricing, setup cost, and licensing?

We purchase an annual standard license.

What other advice do I have?

I recommend Sophos XG if you are coming from pfSense or Astaro as the migration will be really easy. The learning path will also be easy. If you are coming from Barracuda or Cisco it will be more difficult especially the web interface of the firewall is not intuitive.

I would rate Sophos XG an 8 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Network Engineer at Spectrum Engineering Consortium Ltd.
Real User
Reliable and flexible for small and large companies, but has some feature issues to resolve
Pros and Cons
  • "Sophos XG Firewall is very usable, very easy to install, and very user friendly."
  • "We are facing some problems on this firmware version, version 18, that require improvement. We want to improve the email security because it doesn't give proper security with the data protection. Also, our clients are facing some problems where most of the sites which they're accessing are getting blocked. I want to improve those sites, that email security, and the data protection on the Firmware version 18."

What is our primary use case?

You can use Sophos XG in small or large companies. In a small company we are using it as a router and firewall. In larger company, like in the Bangladesh government, they are using Sophos Firewall in various sites, including the Bangladesh Navy. Many of the sites are using Sophos Firewall as a router and firewall and also for security purposes.

How has it helped my organization?

Sophos XG Firewall is for security purposes and we are also using it as a router. Wherever we are deploying it as a router we are mapping and also port forwarding. More clients take it as a router and also a firewall.

What is most valuable?

Sophos XG Firewall is very usable, very easy to install, and very user friendly.

The features that I have found most valuable are the infiltration prevention and data protection. We provide immune security. There are also many features on the VPN. We provide a social VPN. We deployed so many features.

What needs improvement?

We are facing some problems on this firmware version, version 18, that require improvement. We want to improve the email security because it doesn't give proper security with the data protection. Also, our clients are facing some problems where most of the sites which they're accessing are getting blocked. I want to improve those sites, that email security, and the data protection on the Firmware version 18. Also, sometimes it gets frozen and we cannot access it. After we shut it down and restart, then it's perfect. That's a point that we want to improve. 

In the next release, I want them to please improve version 18 so that it has more features and is more user friendly and it should have a VRF option.

For how long have I used the solution?

We are using Sophos XG for five years. 

What do I think about the stability of the solution?

Sophos XG is stable.

Maintenance, once it is established on the network, requires about two to three people dedicated to Sophos Firewall. We have to give about two to three days monthly.

What do I think about the scalability of the solution?

Scalability is good.

We have about a thousand or more users and have plans to increase usage of this product.

How are customer service and support?

The Sophos support team is good now.

How was the initial setup?

Initial setup is easy. It took about one hour to do the initial setup.

What about the implementation team?

I am an implementer so I deployed it by myself.

What's my experience with pricing, setup cost, and licensing?

Sophos XG is on a subscription basis. We can take a one year or two year subscription.

What other advice do I have?

On a scale of one to ten, I will give Sophos XG a seven.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: January 2022.
564,599 professionals have used our research since 2012.
Head of Software department & Head of Security department at a tech services company with 11-50 employees
Reseller
Offers good integrated security but failover management is lacking
Pros and Cons
  • "The most useful aspect of the solution is the concept of integrated security."
  • "The management console could be improved and the solution lacks good technical support."

What is our primary use case?

We generally deploy this solution for our clients for its basic functionality; our clients generally don't have sophisticated requirements. The solution is used for the firewall rules and the VPN rules, as well as the WAF functionality. We are silver resellers of this product and I'm head of the software department. 

What is most valuable?

The most useful aspect of the solution is the concept of integrated security which is why I use and recommended this firewall to clients. However, given that we never use endpoint protection, there is less incentive for us to continue using it. Initially it provided a specificity which enabled one kind of endpoint protection managed through the appliance together with the WIFI integrated within the firewall, managing all basic security aspects for TPD. However, because the endpoint protection is not that good and there are problems with malware and we can't prioritize facility management over security of the finances, we can't continue to work this way.

What needs improvement?

I think the management console could be improved. I also find the partner portal difficult to work with because it never functions correctly and it's exhausting to deal with. They should also improve the failover management and the reliability of failover, and there are sometimes issues with the WAF functionality, whereby a number of applications can't be used correctly. Finally, I think the support could be improved because when you open a ticket, there's a long wait time for a response. 

For how long have I used the solution?

I've been using this solution for three years. 

What do I think about the stability of the solution?

The stability is quite good there are no major vulnerabilities. 

How are customer service and technical support?

The technical support is a real weakness but that seems to always be the case. Sophos has improved over the last couple of years. It's better than before but it's still not good.  

What's my experience with pricing, setup cost, and licensing?

I find the solution too expensive, to be honest. It's one of the reasons I'm looking for an alternative. It's overpriced for what they offer.  When you buy a commercial appliance, the only thing you really need is good support, and they don't provide that, so the cost for hardware and software is too expensive. If the support was responsive, I'd be happy to pay. Now I'd prefer to acquire my own hardware and install pfSense and spend the money helping technicians and engineers gain good skills and improve our own support. We'd have the same level of protection at a lower cost. 

What other advice do I have?

I rate this solution a seven out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
Flag as inappropriate
Head ICT at a tech services company with 11-50 employees
Real User
Top 20
Reliable, easy to install, reasonably-priced, with good management control
Pros and Cons
  • "I like the dashboard, the interface, the management console, and the remote login."
  • "I would want the level of integration to have another device on your network that is also reliable."

What is our primary use case?

We use this solution as a firewall, and for remote login during the lockdown period.

We have used Sophos client, which is connected to the firewall to help our users to log in remotely. 

How has it helped my organization?

We have always used firewalls, this is just a different one that we have deployed. It allowed our clients to log in remotely. 

It has also helped us with outbound and inbound account management.

We have used it to manage the usage of the sites and helping to control the internet usage during productive hours.

What is most valuable?

I like the dashboard, the interface, the management console, and the remote login.

What needs improvement?

I would like to explore network access control. I haven't seen that it is clearly deployed.

It might be something that is already in place, or if it is available on another device.

I would want the level of integration to have another device on your network that is also reliable.

For how long have I used the solution?

I have been using Sophos XG for three years.

What do I think about the stability of the solution?

It's very stable. It has never given us any problems.

When there are power failures, we have to reboot the network.

What do I think about the scalability of the solution?

We have not tested the scalability. Our users are below 100, and from the time that we got it, our number of users has not gone above that original 100.

From what I have read, it's scalable and we have plans to increase our usage. For example, we are not using the Intrusion section, which is an area that we want to use. 

We also plan to install the Sophos endpoint.

We are looking at integrating the two solutions and seeing how they work.

We have been using a different antivirus for our endpoints.

How are customer service and technical support?

I haven't used technical support from Sophos. I have not required it. It's been easy for me to sort out myself.

Which solution did I use previously and why did I switch?

Sophos was our first physical firewall device on our network.

Before that, we were using Linux-based open-source software firewalls.

How was the initial setup?

The initial setup is straightforward. It is easy to install.

What's my experience with pricing, setup cost, and licensing?

The price for the firewall is reasonable.

The endpoint, however, is expensive. The price is not very standard, considering where we are coming from.

What other advice do I have?

We are considering Sophos endpoint and should have it next month.

I would recommend Sophos XGto others.

I would rate Sophos XG an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Engineer at a engineering company with 11-50 employees
Real User
Top 20
Easy to deploy and configure, good documentation, and works as advertised
Pros and Cons
  • "It is very easy to configure and straightforward. The firewall rules are straightforward. It works great out of the box. It has been working as advertised, and I haven't had any issues with it."
  • "Its user interface is a little bit slow."

What is our primary use case?

We are using it for our VPN and firewall. It acts as our firewall for the external portal into our network.

What is most valuable?

It is very easy to configure and straightforward. The firewall rules are straightforward.

It works great out of the box. It has been working as advertised, and I haven't had any issues with it.

What needs improvement?

Its user interface is a little bit slow.

For how long have I used the solution?

I have been using this solution for a couple of weeks.

What do I think about the stability of the solution?

It has been up and running for probably three weeks and hasn't had any issues. I didn't have a lot of time on it yet to make a good call about that, but so far, so good.

What do I think about the scalability of the solution?

It scales for our purposes. We're a very small office. We have 25 users on the system. We're an engineering consulting company, so all remote users are accessing our network

It is being used quite heavily, and I don't see any need to increase its usage at all at this point.

How are customer service and technical support?

I didn't have any direct interaction with Sophos. Their online documentation is very good. It is much better than Cisco.

Which solution did I use previously and why did I switch?

It was a replacement for Cisco ASA Firewall. Our Cisco licensing had expired, and it was very expensive. Sophos XG is a lower-cost solution for the same thing. It was also easier to configure.

How was the initial setup?

It was very simple. It took a couple of hours.

What about the implementation team?

We had a partner, and they did the initial setup and walked us through it. Our experience was very good.

Its maintenance is very simple. You need less than one administrator for its maintenance.

What was our ROI?

I expect to see ROI in a year or two.

What's my experience with pricing, setup cost, and licensing?

Its licensing cost is around 700 bucks a year or something like that. It is 100 bucks a month at the most. It seems to be standard licensing with no additional costs.

What other advice do I have?

I would advise others to go through the Sophos demos. They are very good, and they walk you through configuration and use cases. Their online documentation is very helpful in not only configuring it but also selecting a proper model to deploy.

I would rate Sophos XG an eight out of ten for ease of use and cost.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Nadeem Syed
CEO at Haniya Technologies
Reseller
Top 5Leaderboard
Strong in security, scalable, and good performance
Pros and Cons
  • "Sophos firewalls are scalable. They are pretty strong in security. So, when they provide any kind of firewall, they provide all the features such as anti-spam, antivirus, etc."
  • "Its price should be improved. Its features are pretty okay, but the price is the area where we have to fight more. They should do something about the price structure."

What is our primary use case?

Firewall is not our expertise, but we do sell it as per the requirement of the customer or if they ask for it. 

Most of the firewalls are on-prem. What we deliver is the hardware. It is appliance-based.

What is most valuable?

Sophos firewalls are scalable. They are pretty strong in security. So, when they provide any kind of firewall, they provide all the features such as anti-spam, antivirus, etc.

What needs improvement?

Its price should be improved. Its features are pretty okay, but the price is the area where we have to fight more. They should do something about the price structure.

For how long have I used the solution?

It has been a couple of years.

What do I think about the stability of the solution?

It is stable. Its performance is very good. They have now stopped calling it a firewall. They're calling it a Unified Threat Management (UTM) solution.

What do I think about the scalability of the solution?

It is scalable in the sense that if they are using a small model or a small box of firewall and there is an increase in their network and the number of users, they can move that small box to a bigger model. So, if they are using a firewall and they want to scale it up, they can go to the next model.

Sophos has more than 1,000 customers.

How are customer service and technical support?

Our clients have a good system of support over here. They have full support. They get support from the distributors, from the partners, and then directly from Sophos.

Which solution did I use previously and why did I switch?

We are a partner of Sophos and Fortinet. We work with Sophos much more than we work with Fortinet.

How was the initial setup?

If it is a small model and a small network, it takes about two days. You need at least two people for its deployment and maintenance.

What's my experience with pricing, setup cost, and licensing?

Its price should be better. Initially, the clients have to pay for the appliance. Then, they have to pay for the software that is installed on the appliance. Depending on whether they have a one-year, two-year, or three-year license, they just have to renew the license of the software after it expires. They don't have to renew the appliance license. So, they have to pay for the appliance only once, and after that, they just renew the software license. That's all.

What other advice do I have?

I would definitely recommend Sophos to others. I would rate it a nine out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
Sandesh Khade
IT Manager at k sera sera
Reseller
Top 20
Easy to navigate and create rules with helpful technical support on call 24/7
Pros and Cons
  • "The solution is easy to set up and configure."
  • "The pricing can be high unless you choose a longer contract."

What is most valuable?

The solution is very easy to use. It's easy to navigate. 

I like that I can create new rules and policies quite easily.

The solution works quite well overall.

The solution is easy to set up and configure.

Technical support has been very good.

The solution is scalable.

The product so far has been quite stable.

What needs improvement?

We are in the movie industry. We're a movie distribution company. Currently, we are affected badly by corona, since March of 2020. We are working from home, however, this solution is for on-premises tasks.

The pricing can be high unless you choose a longer contract.

For how long have I used the solution?

We've been using the solution for about two years. 

What do I think about the stability of the solution?

We have no complaints in regards to the stability. It doesn't crash or freeze. There are no bugs or glitches. It's good. We find it to be reliable in terms of performance.

What do I think about the scalability of the solution?

The scalability potential is very good. If a company needs to expand it, it can do so with ease.

We have 100 users on the solution.

How are customer service and technical support?

We have 24/7 help if we need it. The technical support on offer is quite helpful. The offices are also in Mumbai, and that makes it very easy to connect with them and get help when we need it.

Which solution did I use previously and why did I switch?

Previous to Sophos, we worked with Cyberoam. We switched due to the fact that Sophos took over Cyberoam and the Cyberoam model we had was outdated. Therefore, we were upgraded in Sophos.

How was the initial setup?

The initial setup is quite easy. it's not overly complex. The configuration process is also very simple.

We have a team within our organization that can handle any maintenance that is required.

What's my experience with pricing, setup cost, and licensing?

The pricing is not an issue. We pay almost it's $40,000 per year. Longer contracts offer better pricing. I'm taking a renewal with a four-year core contract.

What other advice do I have?

I'd recommend the solution to other users and companies. Sophos has been great so far.

I'd rate the solution at an eight out of ten. It loses some marks due to the fact that I have had some technical issues with it. I also don't use it that much and wouldn't consider myself a Sophos expert. I need to spend more time with it.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor
Flag as inappropriate
PPC at EMMVEE Photovoltaic Power Private Limited
Real User
Offers good traffic control, has an easy setup, and is stable
Pros and Cons
  • "The updates are helpful and add to the solution in a positive way."
  • "The pricing has gotten much higher."

What is our primary use case?

We primarily use the solution for gateway purposes, in order to provide us with gateway security.

What is most valuable?

The product is good in terms of routing multiple ISP Internet and also it's good in internet traffic control.

The updates are helpful and add to the solution in a positive way.

The initial setup is simple.

The solution is stable.

For the most part, you can easily scale the solution.

What needs improvement?

I'm not seeing any such things that require any improvement. It's good. From time to time, some updates will come through. It's meeting our requirements right now.

The pricing has gotten much higher. 

For how long have I used the solution?

We've been using the solution for three years. It's been a while now. 

What do I think about the stability of the solution?

The stability and performance are excellent. There are no bugs or glitches. It doesn't crash or freeze. It's very reliable. 

What do I think about the scalability of the solution?

We have 50 users spread across three devices. 

The solution, in terms of scalability, has its limitations, of course. Scalability in the sense of if I want to add more ISPs all depends upon my port availability. Transitions and migrations are fine and doable. I don't find any challenges there.  

How are customer service and support?

Technical support from Sophos has been brilliant. We deal with them on any L3 issues and they are always helpful. 

How was the initial setup?

The initial setup is very straightforward and simple. it's not overly complex or difficult. 

The deployment was quick and took maybe one day.

In terms of maintenance requirements, We have an L1 technical person who will take care of all the routine maintenance of the firewall, and we also have L2 support with the vendor. We have an L3 support from the Sophos team itself. 

What about the implementation team?

We did the implementation with the assistance of a vendor. We did not completely handle it ourselves. 

What's my experience with pricing, setup cost, and licensing?

While, at first, the pricing was very good, it's since crept up. Now, upon renewal, it's pretty high. They've increased the costs. 

Currently, we have three devices that are similar. Only the capacity varies.

What other advice do I have?

I'm a customer and an end-user. I don't have a business relationship with Sophos. 

I'd recommend the solution to other users and organizations. I'd rate it at a ten out of ten. it's the best. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
Product Categories
Firewalls
Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros sharing their opinions.