We use Sophos XG for network security as a firewall for our company.
IT Support Engineer at odak bilisim
Easy port configuration, scalable, but policies could improve
Pros and Cons
- "I have found configuring the ports to be easier in Sophos XG compared to the other devices."
- "Sophos XG could improve the policies, they are a bit confusing when creating them. There are many options that make it confusing and it could be simplified."
What is our primary use case?
What is most valuable?
I have found configuring the ports to be easier in Sophos XG compared to the other devices.
What needs improvement?
Sophos XG could improve the policies, they are a bit confusing when creating them. There are many options that make it confusing and it could be simplified.
For how long have I used the solution?
I have been using Sophos XG for approximately two years.
Buyer's Guide
Sophos XG
September 2025

Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
871,358 professionals have used our research since 2012.
What do I think about the stability of the solution?
The Stability and performance are quite good. We haven't seen any problems.
What do I think about the scalability of the solution?
The solution is scalable.
I would rate the scalability of Sophos XG an eight out of ten.
We have approximately 10 people using this solution in my organization.
My customers are using this solution on a daily basis.
How are customer service and support?
I have contacted support once or twice to receive some clarification. I had a good experience.
Which solution did I use previously and why did I switch?
I have used other solutions preciously and FortiGate's user interface is much easier to use when compared to Palo Alto and Sophos. Additionally, in Palo Alto, assigning the ports are more user-friendly.
How was the initial setup?
The installation is straightforward.
What about the implementation team?
I did the implementation of Sophos XG myself and it took approximately 20 minutes.
There is no maintenance is required for this solution.
Our networking team is approximately 10 people that use the solution.
What's my experience with pricing, setup cost, and licensing?
The Palo Alto solution is expensive and the FortiGate is less expensive than Palo Alto. The Sophos XG would be priced in the middle of the two.
There are some fees but you can purchase a bundle package.
What other advice do I have?
My advice to those wanting to use this solution is if you don't have experience, don't use it.
I would recommend this solution to others.
I rate Sophos XG a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Pre-sales at ITCG SOlutions Pvt Ltd
A comprehensive solution which makes available heartbeat security
Pros and Cons
- "Sophos is a comrehensive solution which allows me to configure all the attendant products, such as Sophos' firewall, Endpoint and Encryption features."
- "The response time could stand improvement."
What is most valuable?
Sophos is a comprehensive solution which allows me to configure all the attendant products, such as Sophos' firewall, Endpoint and Encryption features.
A nice feature of Sophos is that it offers in sync and heartbeat security. When my clients have a perimeter involving Sophos firewall and endpoints with Sophos Endpoint, they can communicate with each other.
Heartbeat security is a great feature.
What needs improvement?
In light of all the firmware upgrades, maintenance, feature and general releases of firmware, I really appreciate the support offered by Sophos. It is really good.
However, the response time could stand improvement, as I do not benefit from immediate support. There is a delay involved. This can be problematic when I need urgent support, such as when my device is in a production environment.
How are customer service and support?
The support is really good. With all the firmware upgrades, maintenance, feature and general firmware releases which occur nowadays, I really appreciate Sophos support. It is really good.
This said, it could be faster, as it is not immediate. This can be problematic when I require urgent support, such as when my device is in a production environment.
How was the initial setup?
When it comes to the firewall, everything hinges on the configuration. Every firewall is good, but one can see the importance of the configuration in the firewalls of Sophos and SonicWall. This is the most important thing, since users occcasionally disable the app control, IPS or anti-spyware features. They do this out of a lack of familiarity with the security, something which allows attacks to occur. Therefore, the configuration is key. I configure every firewall I employ, be it Sophos, SonicWall or Fortinet.
I have not encountered any issues when it comes to the configuration.
What's my experience with pricing, setup cost, and licensing?
I was a gold partner with Sophos XG. As such, I make suggestions about the appropriate model in line with my customer's requirements. Essentially, over the last two years of the COVID-19 crises, most users required an SSL VPN license, something for which SonicWall charges but which Sophos offers for free.
SSL VPN involves two factor authentication. This is free of charge. Both email and key OTP are options. While SonicWall also offers SSL VPN capabilities, it is problematic. When I needed a license, I purchased an additional perpetual SSL VPN license.
Which other solutions did I evaluate?
SonicWall makes available all the different models, such as TZ and NSA. I am familiar with all the models. Sophos only has an entry-level model, which is actually 87, 107 and 116.
Fortinet offers the Forti ATF model.
What other advice do I have?
I recommend the solution to other clients, but make certain to first understand their individual needs. I would be doing them a disservice were it otherwise.
I really like Sophos.
In the past, when Sophos employed XG firewall, I was forced to deal with a slow GUI. This is because its back-end kernel is Linux. Now that XGS is provided, many changes can be seen in the hardware appliance. The hardware has been upgraded. The XGS firewall is faster than the XG series, so the problem has been resolved.
While I rate Fortinet as a nine out of ten, I give Sophos XG a rating of eight.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Buyer's Guide
Sophos XG
September 2025

Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
871,358 professionals have used our research since 2012.
Senior System & Security Administrator at a retailer with 51-200 employees
It has a good interface that's very user-friendly
Pros and Cons
- "I've tried out Sophos XG a little. It has a good interface that's very user-friendly, but I haven't used all of its functions because I'm only configuring and running the system."
- "I would prefer if Sophos XG were cheaper. A lower price would benefit me as a system provider for the end customer. The cost of the license and renewal for all the software and devices is somewhat high."
What is most valuable?
I've tried out Sophos XG a little. It has a good interface that's very user-friendly, but I haven't used all of its functions because I'm only configuring and running the system.
For how long have I used the solution?
I've been working with Sophos XG for six months. I am not an end-user. I only provide the solution and implementation.
What do I think about the stability of the solution?
I think Sophos XG is very stable because the users who have installed it never mention any issues. It's very stable and scalable.
What do I think about the scalability of the solution?
Sophos XG is a scalable solution. Our clients who use Sophos are not big companies.
How are customer service and support?
I haven't dealt with Sophos support because I'm just doing the basic implementation for the Sophos. But I Sophos support is very experienced and helpful. Sophos has a team for administration and implementation—a good team to improve the application.
How was the initial setup?
It depends on the implementation and the deployment of systems. In my small company, I have four people on my technical team. Two of them specialize in firewall and security. They're working on Fortinet. They deal with antivirus and security implementation as well as Veeam Backup. The other two handle the administration implementation, including Active Directory and other administration solutions.
What's my experience with pricing, setup cost, and licensing?
I would prefer if Sophos XG were cheaper. A lower price would benefit me as a system provider for the end customer. The cost of the license and renewal for all the software and devices is somewhat high.
What other advice do I have?
I rate Sophos XG nine out of 10. I am a Fortinet partner. If a user asks me which solution to buy, I'll tell them Fortinet. But if the customer needs Sophos, I will implement it for him. However, if I had a Sophos partnership, I would recommend it every time.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Network Security Engineer | Project Manager at a consumer goods company with 10,001+ employees
Simple to use, easy installation, and performs well
Pros and Cons
- "The solution has good performance and is easy to use."
- "The solution could be more secure."
What is our primary use case?
We use Sophos XG for network threat protection in our data center.
What is most valuable?
The solution has good performance and is easy to use.
What needs improvement?
The solution could be more secure.
For how long have I used the solution?
I have been using Sophos XG for a few years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
We have approximately 100 users using this solution.
How was the initial setup?
The installation of Sophos XG is easy.
What about the implementation team?
We have four technical engineers for installation and administrators for this equipment.
Which other solutions did I evaluate?
We have evaluated Palo Alto and FortiGate.
What other advice do I have?
We have replaced some of our hardware with Palo Alto and FortiGate solutions.
I am satisfied with this solution.
I rate Sophos XG an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT support officer at a wholesaler/distributor with 51-200 employees
Performs well, the firewall and threat management are good
Pros and Cons
- "So far, I'm happy that they have recently added a firewall role, so I feel a little more comfortable with the security. The threat management is good."
- "For the moment, managing the Sophos interface is a little bit challenging."
What is our primary use case?
There are about 100 people using Sophos at our office. We have two ISPs, so we have to have access to our internet providers. We also need security to deploy our network. Also, our home and external users need to be able to log in. So we use Sophos XG to build our deployment. Sophos is more than just a firewall. It analyzes security effects, so it's a firewall for the future. It's more than just a hardware firewall. There are also some paid options, so we do not have to have the main server inside our office here. We use Office 365. And although we use five servers at our location, not everything is in the cloud yet.
What is most valuable?
We haven't used it for very long, so I have not analyzed the main features deeply. So far, I'm happy that they have recently added a firewall role, so I feel a little more comfortable with the security. The threat management is good. Also, the graphics and the throughput of our internet access are better than before, so it's the Sophos anti-threat device that we have.
What needs improvement?
For the moment, managing the Sophos interface is a little bit challenging. We have an external partner that helps me to comprehend. But it's new. It has to keep up with the market, and I understand that. But that's my personal problem at the moment. High-availability clusters have not been implemented, so we have only one firewall and one device. So should this device go down, there's no more internet access. But so far, we haven't had any problems.
For how long have I used the solution?
I've only been using Sophos XG for three months.
What do I think about the stability of the solution?
Sophos is stable.
What do I think about the scalability of the solution?
Sophos XG is scalable.
How are customer service and support?
I used Sophos tech support for the previous solution because Sophos sold that as well. Now, we only work with the external partners. So for the moment, I haven't had to send questions directly to Sophos. But my past experience with Sophos support was good. It was very professional and easy. We stay with Sophos software because of the technical support.
Which solution did I use previously and why did I switch?
We had Cyberoam. That brand that doesn't exist anymore, so we had to change.
How was the initial setup?
I contacted the external partner, and the setup was easy. It took about two or three days. Some little pictures were difficult for us to find, but that's normal. We could not make a one-to-one copy of the older one, so we had to search for some little personal configurations here. Now that everything is configured right, we are happy to have it.
What's my experience with pricing, setup cost, and licensing?
Because Sophos is sold by the brand that we had before that and Cyberoam does not exist anymore, it costs less because we stayed within the older firewalls. The price was also very good. It was not expensive before because of their value at the time. I think it's not cheap but not very expensive, either. It's in the middle.
What other advice do I have?
Based on what I know from using it so far, I would recommend Sophos. I rate it eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Sr. Network Administrator at ACMC
Friendly, dependable, scalable, and simple to migrate
Pros and Cons
- "The performance is good."
- "Sophos XG does not have the ability to disconnect a user."
What is most valuable?
Sophos XG is very good.
It's very friendly.
The performance is good.
What needs improvement?
The reporting could be improved.
Many other firewalls give you the option to disconnect a user. For example, if an end-user is using too much bandwidth, you could right-click to disconnect this user, but Sophos XG does not support this feature.
Sophos XG does not have the ability to disconnect a user.
For how long have I used the solution?
I have been using Sophos XG for one and a half years.
We are using the latest version.
What do I think about the stability of the solution?
The stability of Sophos XG is great!
What do I think about the scalability of the solution?
Sophos XG is scalable.
We have approximately 120 users in our organization who are using this solution.
How are customer service and technical support?
We have never contacted the technical support for Sophos. Once or twice we called the local support but not for Sophos.
Which solution did I use previously and why did I switch?
Previously we used Cyberoam. When they announced the end of life we switched to Sophos XG.
It was upgraded because it had reached the end of its life. We only had one option for upgrading to Sophos XG. They gave us the option to upgrade and provided us with the hardware for free.
How was the initial setup?
We migrated from Cyberoam. The migration went very well.
The migration process did not require a lot of configuration.
It took a few days to complete the migration and the testing.
This solution is being managed by myself and a colleague. We are a team of two.
What about the implementation team?
We were able to complete the migration ourselves.
What's my experience with pricing, setup cost, and licensing?
They have different options for the license.
We paid for three years which included the migration and the free hardware.
In most cases, I believe that the licensing is paid yearly.
What other advice do I have?
I don't have any issues with this solution. I would recommend this solution for others who are interested in using it.
I would rate Sophos XG an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of ICT Infrastructure and Security at City of Harare
Easy to set up with great protection features and excellent documentation
Pros and Cons
- "The initial setup is very straightforward and the solution is extremely user-friendly."
- "I'd like the dashboard to be improved. It could be a bit more customizable."
What is our primary use case?
We use Sophos Firewall for our environment.
The Sophos Firewall, from our interaction and the way we are using it, is a very effective network security solution that basically protects our infrastructure, identifies any infections or any network security threats that actually may happen within our environment. We also are able to manage our users in terms of bandwidth usage and the allocation of bandwidth, whereby we give our users restricted access for use during working hours and they are supposed to utilize the bandwidth and make sure that we optimize and prioritize the applications able to get the necessary bandwidth. We do use it to manage our bandwidth. We do use it as well to make sure that our environment is secure against any possible threats.
What is most valuable?
In terms of the Sophos XG Firewall, what really excites us is basically the issue of intrusion detection and the intrusion prevention features. Those are both very, very good.
The issue of sandboxing as well is something that is very useful. It's able to protect our environment quite well.
Email protection is something that we are basically using all the time and it protects our environment which has more than 2000 users.
All of the protection features are great in terms of securing our environment.
Sophos is way ahead of a number of other products in terms of the enhancements and upgrades they offer.
Sophos offers a great centralized dashboard that makes it easy to see what's happening on your network.
The initial setup is very straightforward and the solution is extremely user-friendly.
The documentation is very, very good.
What needs improvement?
In terms of the product, from the way that we have been utilizing it, we have noticed that the vendor has been able to continuously upgrade and upgrade and update the product with new features. You'd find that all the time a new release has come out, and we're actually happy with that. We don't find it inconvenient that we are constantly upgrading.
I can't think of any downsides in terms of the features on offer.
I'd like the dashboard to be improved. It could be a bit more customizable.
For how long have I used the solution?
I have about five years of experience with the product.
What do I think about the stability of the solution?
We are very satisfied with the functionality. We are very satisfied with the way that it is securing our environment. The stability has been excellent.
What do I think about the scalability of the solution?
We have 2,000 users on the solution currently.
The solution is very scalable. We basically started with about 900 users. We went up to about 1,300. As we went up, as our users increased, we also scaled it up in terms of protection. Sophos was able to scale up easily and protect all our end users as well as our environment. It's been great overall.
We do plan to increase usage. Our employee base is about 10,000. We have 2,000 networked employees and we are planning to add another 1,000 users by the end of the year.
How are customer service and technical support?
The technical support has been great. All of our technical staff have been certified as Sophos administrators. They were able to offer us the training to make sure that all of the support staff are familiar with the functionality of the product. Then, in terms of technical support that we may need, when we call the Sophos team, they are usually very available and they are even able to support us remotely if there is a need to do that. We are extremely satisfied overall.
Which solution did I use previously and why did I switch?
I also often work with Cisco's ASA Firewall as well as Nagios. We bought Sophos to complement the ASA firewall.
How was the initial setup?
The initial setup was very, very straightforward. You find that we did not even require a lot of external help from the vendor. It's so straightforward. The documentation is quite comprehensive and it takes the user through a step-by-step process, It's very user-friendly.
For the firewall as well as deployment of the end-user, the email protection as well as the sandbox, and the like, it took us approximately three days to finalize everything for our entire environment. We had over a hundred network sites, which are dotted through the city of Harare, therefore, we knew that we had to make sure that deployment was done fully throughout the entire environment.
What about the implementation team?
There was very minimal, minimal assistance from the vendor. The vendor, here and there, would assist if we requested their help. However, you'd find that in most of the installations we did in-house, we didn't need the vendor to do anything. We knew that the installation process was very user-friendly.
What's my experience with pricing, setup cost, and licensing?
The cost of procuring this product is very reasonable and it's very affordable for most organizations.
What other advice do I have?
We're a customer and an end-user.
We use the latest version of the product.
I'd advise those considering the solution that Sophos' security solution is highly synchronized, very secure, and provides comprehensive security. I'd like them to know that it has enhanced and very detailed and sophisticated functionality, which is really easy to use, easy to deploy, and very user-friendly. It is a product that I would highly recommend for any organization that needs to comprehensively secure its infrastructure.
I'd rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at Thyme IT
A rock-solid and sensible product that works very well, comes at a fair price, and requires minimal handling
Pros and Cons
- "There are many features. VPN, firewalling, and intrusion detection are the main features that are most useful for us at this time."
- "Their support is fairly good, and they come back to me. I've had an issue once or twice where I couldn't understand what the support person was saying because those calls were probably routed to India. They were a bit difficult to understand, but it is generally not an issue."
What is our primary use case?
We use it for firewalling. Lately, we are also using it for remote access or VPN access for the users to the firewall and then onto the local network for people working from home. We've seen a huge jump in work from home. Everybody is working from home, so we need a secure connection to the office.
I am not using its latest version. I normally wait for a couple of months before upgrading the unit to make sure there are no bugs or issues. I check on the forums to see what other people are saying and whether there are any issues.
What is most valuable?
There are many features. VPN, firewalling, and intrusion detection are the main features that are most useful for us at this time.
What needs improvement?
Their support is fairly good, and they come back to me. I've had an issue once or twice where I couldn't understand what the support person was saying because those calls were probably routed to India. They were a bit difficult to understand, but it is generally not an issue.
For how long have I used the solution?
I have been using this solution for seven years.
What do I think about the stability of the solution?
It is stable. We've been dealing with it for such a long time. We know exactly how to set it up. Sometimes, clients have got funny ideas, and I just say to them, "You tell me what you need, and I'll do the config and set it up." I've got two clients who have got technical skills. One of them is fairly proficient on Sophos, so he does the work as well, but for most of our other clients, we set it up, and there are no issues. It just works.
What do I think about the scalability of the solution?
It is scalable provided you purchase the correct product. We do a bit of homework. We don't just sell you the first device on the list because that's not always suitable. We do a scope of the client's business. They may be a startup with just five users, but they might have a plan to have 100 or 200 users. We need to just size according to what they anticipate to be. It is no good if we sell them an entry-level device now, and two months later, it is too small. We purchase according to a client's requirements.
We've got clients with four users, and the number can go up to hundreds. I'm currently busy setting one up for 150 users, and obviously, there is much more work involved in doing the remote VPN setups.
How are customer service and technical support?
I use the local support in South Africa. If they can't help me, then I log a case with their international support. They're fairly good, and they come back to me.
I've had an issue once or twice where I couldn't understand what the support person was saying because those calls were probably routed to India. They were a bit difficult to understand. They spoke so fast, and I could not hear what they were saying, but it is generally not an issue. It is not a showstopper, and we manage to work. If I don't understand, I say to them, "Can we rather chat by email?", which makes it a lot easier.
Which solution did I use previously and why did I switch?
There some other firewalls that my company is using, but they're way below in terms of specs and what they can do. Sophos XG is a layer 7 firewall, and most of the others are only layer 2 firewalls. Sophos is far superior.
I do not have any knowledge about Cisco, Juniper, or other firewalls. I don't really use them. I use some open-source firewalls, but they're also a lot lighter. I've got one or two very small clients or non-profits where we run an open-source firewall, but the feature set is way limited compared to Sophos.
Sophos XG comes in at a fair price as compared to some of the other products out there. Its learning curve wasn't that steep. It makes sense, and it is a sensible product. It is not like some of the other products.
How was the initial setup?
It is simple for me. I've done so many setups. I can probably do these things in my sleep. In fact, I have got one in front of me now that I need to configure and install. I'm fairly proficient in the use of these devices. I'm happy with it.
The deployment duration depends on the setup. Some simple setups can be up and running within two hours. Complex ones most probably will take four to six hours. It also depends on the client's needs. Some of them have simple requirements, and they just want firewalling and one or two remote-access VPNs. Others have got a complex setup where we need to set up cameras and VoIP telephone systems. It all depends on a client's requirements.
It doesn't require any maintenance because the definitions are auto-updated. I've got a dashboard where I can manage all of the firewall devices from one dashboard. If I want to upgrade the software on 20 of them, I'll log onto the dashboard and upgrade the software just by selecting it and saying upgrade the software, and it is done. It requires very minimal handling on a day-to-day basis. Antivirus definitions, scanning definitions, and all those things are auto-updated anyway.
What's my experience with pricing, setup cost, and licensing?
It comes at a fair price as compared to some of the other products out there. Its price is in the middle. It is not the cheapest, and it is also not as expensive as Juniper, Check Point, and definitely Cisco. Nowadays, everybody is very cost-sensitive, and people don't want to spend unnecessary money, but even before that, it was a fairly priced product.
You've got your choice of what license you want. There are basically two types of licenses, and it depends on what you need to do, and everything is included in that license. There is no cost for VPN and DMZ. You purchase the license, and you know upfront what you're getting or what you're not getting, and that's it. It is one license fee and done and dusted.
What other advice do I have?
I would definitely recommend this solution to others. I recommend it to all my clients. I'm using it at home as well, and it works great. I'm fairly proficient in it, so I'm very confident. I can recommend it to anybody and everybody. It is a great product, and I've got no issue with it.
I would rate Sophos XG a ten out of ten. It is a rock-solid product that works. We've so many deployments of this solution. I'm just happy with it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
FirewallsPopular Comparisons
Fortinet FortiGate
Netgate pfSense
OPNsense
Cisco Secure Firewall
Palo Alto Networks NG Firewalls
WatchGuard Firebox
Cisco Meraki MX
Check Point Quantum Force (NGFW)
Azure Firewall
SonicWall TZ
Sophos XGS
Fortinet FortiGate-VM
Juniper SRX Series Firewall
SonicWall NSa
KerioControl
Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos XG 210 vs Fortigate FG 100E
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What is the biggest difference between Sophos XG and FortiGate?
- Which firewall is better and why: Sophos XG 210 or Fortinet FortiGate 100E?
- Which solution do you prefer: Fortinet FortiGate or Sophos XG?
- What are the main differences in features between Sophos XG and FortiGate 80F?
- Fortinet FortiGate or Sophos XG?
- How does Meraki MX compare with Sophos XG?
- Which firewall to choose for an SMB to prevent malware damage: Cisco Firepower or Sophos XG?
- Looking for a technical comparison between Sophos XG550 and Fortinet FortiGate 600E