Sophos XG OverviewUNIXBusinessApplication

Sophos XG is the #7 ranked solution in best firewalls. PeerSpot users give Sophos XG an average rating of 8.2 out of 10. Sophos XG is most commonly compared to Fortinet FortiGate: Sophos XG vs Fortinet FortiGate. Sophos XG is popular among the large enterprise segment, accounting for 44% of users researching this solution on PeerSpot. The top industry researching this solution are professionals from a computer software company, accounting for 19% of all views.
Sophos XG Buyer's Guide

Download the Sophos XG Buyer's Guide including reviews and more. Updated: May 2023

What is Sophos XG?

Sophos XG Firewall is a complete firewall solution that provides all the real-time security and insights you need to protect your network from ransomware and advanced threats. Sophos XG Firewall provides visibility into suspicious users, unknown and unwanted apps, encrypted traffic, and other threats. With its advanced artificial intelligence capabilities, Sophos XG Firewall immediately identifies potential risks and intrusions on web servers and networks.

Sophos XG Firewall Features

Sophos XG Firewall offers a wide range of security features, including:

  • Application control: Prevent widespread infections with XG’s Security Heartbeat. XG Firewall automatically identifies the source of an infection on a network and automatically prevents it from accessing other network resources.

  • Synchronized user ID: Eliminate the need for client or server authentication agents by sharing user identification between the endpoint and the firewall through Security Heartbeat.

  • Centralized management: Easily manage all activities with Sophos Central. The XG cloud management platform allows users to easily set up, manage, and monitor XG firewalls along with other Sophos products. Some of Sophos Central’s features include alerting, backup management, one-click firmware updates, and rapid deployments of new firewalls.

  • Lateral movement protection: Automatically isolate compromised systems at every point in the network to stop attacks dead in their tracks.

  • Network protection: Protect networks from attacks and threats while providing secure network access.

  • Web protection: Gain clear visibility and control over all users’ web and application activity.

  • Web server protection: Solidify web servers and applications against hacking attacks while providing secure web access.

  • Email protection: Consolidate email protection with anti-spam, DLP, and encryption. XG’s Live Anti-Spam provides protection from the most recent spam campaigns, phishing attacks, and malicious attachments. Data Loss Prevention automatically triggers encryption on sensitive data in outgoing emails.

Reviews from Real Users

Sophos XG Firewall stands out among its competitors, among other reasons, for its intrusion detection capabilities, its user-friendly management platform, and in general, for being a complete and robust firewall solution.

Niranjan P., a network & system support engineer, writes, “Sophos is a comprehensive solution which allows me to configure all the attendant products, such as Sophos's firewall, endpoint, and encryption features. A nice feature of Sophos is that it offers in sync and heartbeat security. When my clients have a perimeter involving Sophos firewall and endpoints with Sophos Endpoint, they can communicate with each other.”

Antonio D., sales manager at INFOSEC, notes, “The product has a console that is based in the cloud for all their products. In this console, they have email security, firewall security, endpoint security, et cetera. All of the products on offer in the console are very useful for us. The solution is stable. The solution works well for enterprises and large-scale organizations.”

Antony M., ICT/HMIS supervisor at a healthcare company, writes, “The VPN feature is the most valuable. It has come in handy during this period when people are working from home. The filtering feature is also valuable because you can easily filter the sites that you don't want to visit. You can also set timely surfing quotas”

Sophos XG Video

Archived Sophos XG Reviews (more than two years old)

Filter by:
Filter Reviews
Industry
Loading...
Filter Unavailable
Company Size
Loading...
Filter Unavailable
Job Level
Loading...
Filter Unavailable
Rating
Loading...
Filter Unavailable
Considered
Loading...
Filter Unavailable
Order by:
Loading...
  • Date
  • Highest Rating
  • Lowest Rating
  • Review Length
Search:
Showingreviews based on the current filters. Reset all filters
Head of ICT Infrastructure and Security at City of Harare
Real User
Top 10Leaderboard
Easy to set up with great protection features and excellent documentation
Pros and Cons
  • "The initial setup is very straightforward and the solution is extremely user-friendly."
  • "I'd like the dashboard to be improved. It could be a bit more customizable."

What is our primary use case?

We use Sophos Firewall for our environment.

The Sophos Firewall, from our interaction and the way we are using it, is a very effective network security solution that basically protects our infrastructure, identifies any infections or any network security threats that actually may happen within our environment. We also are able to manage our users in terms of bandwidth usage and the allocation of bandwidth, whereby we give our users restricted access for use during working hours and they are supposed to utilize the bandwidth and make sure that we optimize and prioritize the applications able to get the necessary bandwidth. We do use it to manage our bandwidth. We do use it as well to make sure that our environment is secure against any possible threats.

What is most valuable?

In terms of the Sophos XG Firewall, what really excites us is basically the issue of intrusion detection and the intrusion prevention features. Those are both very, very good. 

The issue of sandboxing as well is something that is very useful. It's able to protect our environment quite well. 

Email protection is something that we are basically using all the time and it protects our environment which has more than 2000 users. 

All of the protection features are great in terms of securing our environment.

Sophos is way ahead of a number of other products in terms of the enhancements and upgrades they offer.

Sophos offers a great centralized dashboard that makes it easy to see what's happening on your network. 

The initial setup is very straightforward and the solution is extremely user-friendly.

The documentation is very, very good.

What needs improvement?

In terms of the product, from the way that we have been utilizing it, we have noticed that the vendor has been able to continuously upgrade and upgrade and update the product with new features. You'd find that all the time a new release has come out, and we're actually happy with that. We don't find it inconvenient that we are constantly upgrading. 

I can't think of any downsides in terms of the features on offer.

I'd like the dashboard to be improved. It could be a bit more customizable. 

For how long have I used the solution?

I have about five years of experience with the product.

Buyer's Guide
Sophos XG
May 2023
Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: May 2023.
709,643 professionals have used our research since 2012.

What do I think about the stability of the solution?

We are very satisfied with the functionality. We are very satisfied with the way that it is securing our environment. The stability has been excellent.

What do I think about the scalability of the solution?

We have 2,000 users on the solution currently.

The solution is very scalable. We basically started with about 900 users. We went up to about 1,300. As we went up, as our users increased, we also scaled it up in terms of protection. Sophos was able to scale up easily and protect all our end users as well as our environment. It's been great overall.

We do plan to increase usage. Our employee base is about 10,000. We have 2,000 networked employees and we are planning to add another 1,000 users by the end of the year.

How are customer service and support?

The technical support has been great. All of our technical staff have been certified as Sophos administrators. They were able to offer us the training to make sure that all of the support staff are familiar with the functionality of the product. Then, in terms of technical support that we may need, when we call the Sophos team, they are usually very available and they are even able to support us remotely if there is a need to do that. We are extremely satisfied overall.

Which solution did I use previously and why did I switch?

I also often work with Cisco's ASA Firewall as well as Nagios. We bought Sophos to complement the ASA firewall.

How was the initial setup?

The initial setup was very, very straightforward. You find that we did not even require a lot of external help from the vendor. It's so straightforward. The documentation is quite comprehensive and it takes the user through a step-by-step process, It's very user-friendly.

For the firewall as well as deployment of the end-user, the email protection as well as the sandbox, and the like, it took us approximately three days to finalize everything for our entire environment. We had over a hundred network sites, which are dotted through the city of Harare, therefore, we knew that we had to make sure that deployment was done fully throughout the entire environment.

What about the implementation team?

There was very minimal, minimal assistance from the vendor. The vendor, here and there, would assist if we requested their help. However, you'd find that in most of the installations we did in-house, we didn't need the vendor to do anything. We knew that the installation process was very user-friendly.

What's my experience with pricing, setup cost, and licensing?

The cost of procuring this product is very reasonable and it's very affordable for most organizations.

What other advice do I have?

We're a customer and an end-user.

We use the latest version of the product.

I'd advise those considering the solution that Sophos' security solution is highly synchronized, very secure, and provides comprehensive security. I'd like them to know that it has enhanced and very detailed and sophisticated functionality, which is really easy to use, easy to deploy, and very user-friendly. It is a product that I would highly recommend for any organization that needs to comprehensively secure its infrastructure.

I'd rate the solution at a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Jorge Costa Neves - PeerSpot reviewer
IT Advisor at Silopor SA
Real User
Top 5
Easy to use, easy to install, and easy to monitor
Pros and Cons
  • "It is very easy to use. You can configure and monitor everything from one unique dashboard."
  • "Its price should be improved. It should be cheaper."

What is our primary use case?

We use it for the protection of our network. We also have a product from Sophos for ransomware protection using which we are able to protect our network from ransomware. All of our solutions are from Sophos, and we have everything integrated. 

What is most valuable?

We can define which systems can be accessed from outside of our company. We can define the connection rules for inside and outside of the company. It is easy to implement or modify rules.

It is very easy to use. You can configure and monitor everything from one unique dashboard. It is also easy to install.

What needs improvement?

Its price should be improved. It should be cheaper. 

In terms of features, I am happy, and I don't need more features. The firewall is perfect, but the antivirus could be better. It would be useful if the antivirus was less heavy and had better performance.

For how long have I used the solution?

I have been using this solution for two years.

What do I think about the stability of the solution?

It is stable. We receive the updates online. They provide the updates at a good frequency. 

What do I think about the scalability of the solution?

It is scalable to a limit. If the size of the network grows, you will have to buy new equipment. If you need just a few more connections, you will able to work with the existing system.

Currently, we have 16 users who are using it. We don't have any plans to increase its usage because our company is in liquidation. If the government decides, we can have more projects, but, as of now, we are in liquidation. We are keeping things working for now, and we plan to keep using this solution, but there are no investments.

How are customer service and technical support?

We have support from the supplier of our firewall, and if needed, we also get support from the people who develop our software.

How was the initial setup?

It is easy to install. Our company is at three locations. It takes two days to install it at all locations. It takes one day for one location and another day for the other two locations.

What about the implementation team?

For the first installation, we took the help of the supplier. Since then, we do it ourselves. We don't have teams attached directly to the system. We have two or three IT guys who work with this system, but we can have support from the maintenance team.

What's my experience with pricing, setup cost, and licensing?

Currently, we have a contract for three years. It would be good if its price is reduced before we renew the contract. We will buy the equipment if it is cheaper.

What other advice do I have?

I'm happy with what I am getting. I haven't faced any problems. Everything is integrated, and it is easy to install and easy to control. 

I would rate Sophos XG a nine out of ten. I am very satisfied with this solution.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Sophos XG
May 2023
Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: May 2023.
709,643 professionals have used our research since 2012.
IT Manager at k sera sera
Reseller
Top 20
Easy to navigate and create rules with helpful technical support on call 24/7
Pros and Cons
  • "The solution is easy to set up and configure."
  • "The pricing can be high unless you choose a longer contract."

What is most valuable?

The solution is very easy to use. It's easy to navigate. 

I like that I can create new rules and policies quite easily.

The solution works quite well overall.

The solution is easy to set up and configure.

Technical support has been very good.

The solution is scalable.

The product so far has been quite stable.

What needs improvement?

We are in the movie industry. We're a movie distribution company. Currently, we are affected badly by corona, since March of 2020. We are working from home, however, this solution is for on-premises tasks.

The pricing can be high unless you choose a longer contract.

For how long have I used the solution?

We've been using the solution for about two years. 

What do I think about the stability of the solution?

We have no complaints in regards to the stability. It doesn't crash or freeze. There are no bugs or glitches. It's good. We find it to be reliable in terms of performance.

What do I think about the scalability of the solution?

The scalability potential is very good. If a company needs to expand it, it can do so with ease.

We have 100 users on the solution.

How are customer service and technical support?

We have 24/7 help if we need it. The technical support on offer is quite helpful. The offices are also in Mumbai, and that makes it very easy to connect with them and get help when we need it.

Which solution did I use previously and why did I switch?

Previous to Sophos, we worked with Cyberoam. We switched due to the fact that Sophos took over Cyberoam and the Cyberoam model we had was outdated. Therefore, we were upgraded in Sophos.

How was the initial setup?

The initial setup is quite easy. it's not overly complex. The configuration process is also very simple.

We have a team within our organization that can handle any maintenance that is required.

What's my experience with pricing, setup cost, and licensing?

The pricing is not an issue. We pay almost it's $40,000 per year. Longer contracts offer better pricing. I'm taking a renewal with a four-year core contract.

What other advice do I have?

I'd recommend the solution to other users and companies. Sophos has been great so far.

I'd rate the solution at an eight out of ten. It loses some marks due to the fact that I have had some technical issues with it. I also don't use it that much and wouldn't consider myself a Sophos expert. I need to spend more time with it.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Distributor
PeerSpot user
IT Manager at Thyme IT
Real User
A rock-solid and sensible product that works very well, comes at a fair price, and requires minimal handling
Pros and Cons
  • "There are many features. VPN, firewalling, and intrusion detection are the main features that are most useful for us at this time."
  • "Their support is fairly good, and they come back to me. I've had an issue once or twice where I couldn't understand what the support person was saying because those calls were probably routed to India. They were a bit difficult to understand, but it is generally not an issue."

What is our primary use case?

We use it for firewalling. Lately, we are also using it for remote access or VPN access for the users to the firewall and then onto the local network for people working from home. We've seen a huge jump in work from home. Everybody is working from home, so we need a secure connection to the office.

I am not using its latest version. I normally wait for a couple of months before upgrading the unit to make sure there are no bugs or issues. I check on the forums to see what other people are saying and whether there are any issues. 

What is most valuable?

There are many features. VPN, firewalling, and intrusion detection are the main features that are most useful for us at this time.

What needs improvement?

Their support is fairly good, and they come back to me. I've had an issue once or twice where I couldn't understand what the support person was saying because those calls were probably routed to India. They were a bit difficult to understand, but it is generally not an issue.

For how long have I used the solution?

I have been using this solution for seven years.

What do I think about the stability of the solution?

It is stable. We've been dealing with it for such a long time. We know exactly how to set it up. Sometimes, clients have got funny ideas, and I just say to them, "You tell me what you need, and I'll do the config and set it up." I've got two clients who have got technical skills. One of them is fairly proficient on Sophos, so he does the work as well, but for most of our other clients, we set it up, and there are no issues. It just works.

What do I think about the scalability of the solution?

It is scalable provided you purchase the correct product. We do a bit of homework. We don't just sell you the first device on the list because that's not always suitable. We do a scope of the client's business. They may be a startup with just five users, but they might have a plan to have 100 or 200 users. We need to just size according to what they anticipate to be. It is no good if we sell them an entry-level device now, and two months later, it is too small. We purchase according to a client's requirements.

We've got clients with four users, and the number can go up to hundreds. I'm currently busy setting one up for 150 users, and obviously, there is much more work involved in doing the remote VPN setups.

How are customer service and technical support?

I use the local support in South Africa. If they can't help me, then I log a case with their international support. They're fairly good, and they come back to me. 

I've had an issue once or twice where I couldn't understand what the support person was saying because those calls were probably routed to India. They were a bit difficult to understand. They spoke so fast, and I could not hear what they were saying, but it is generally not an issue. It is not a showstopper, and we manage to work. If I don't understand, I say to them, "Can we rather chat by email?", which makes it a lot easier.

Which solution did I use previously and why did I switch?

There some other firewalls that my company is using, but they're way below in terms of specs and what they can do. Sophos XG is a layer 7 firewall, and most of the others are only layer 2 firewalls. Sophos is far superior. 

I do not have any knowledge about Cisco, Juniper, or other firewalls. I don't really use them. I use some open-source firewalls, but they're also a lot lighter. I've got one or two very small clients or non-profits where we run an open-source firewall, but the feature set is way limited compared to Sophos.

Sophos XG comes in at a fair price as compared to some of the other products out there. Its learning curve wasn't that steep. It makes sense, and it is a sensible product. It is not like some of the other products.

How was the initial setup?

It is simple for me. I've done so many setups. I can probably do these things in my sleep. In fact, I have got one in front of me now that I need to configure and install. I'm fairly proficient in the use of these devices. I'm happy with it.

The deployment duration depends on the setup. Some simple setups can be up and running within two hours. Complex ones most probably will take four to six hours. It also depends on the client's needs. Some of them have simple requirements, and they just want firewalling and one or two remote-access VPNs. Others have got a complex setup where we need to set up cameras and VoIP telephone systems. It all depends on a client's requirements.

It doesn't require any maintenance because the definitions are auto-updated. I've got a dashboard where I can manage all of the firewall devices from one dashboard. If I want to upgrade the software on 20 of them, I'll log onto the dashboard and upgrade the software just by selecting it and saying upgrade the software, and it is done. It requires very minimal handling on a day-to-day basis. Antivirus definitions, scanning definitions, and all those things are auto-updated anyway.

What's my experience with pricing, setup cost, and licensing?

It comes at a fair price as compared to some of the other products out there. Its price is in the middle. It is not the cheapest, and it is also not as expensive as Juniper, Check Point, and definitely Cisco. Nowadays, everybody is very cost-sensitive, and people don't want to spend unnecessary money, but even before that, it was a fairly priced product.

You've got your choice of what license you want. There are basically two types of licenses, and it depends on what you need to do, and everything is included in that license. There is no cost for VPN and DMZ. You purchase the license, and you know upfront what you're getting or what you're not getting, and that's it. It is one license fee and done and dusted.

What other advice do I have?

I would definitely recommend this solution to others. I recommend it to all my clients. I'm using it at home as well, and it works great. I'm fairly proficient in it, so I'm very confident. I can recommend it to anybody and everybody. It is a great product, and I've got no issue with it.

I would rate Sophos XG a ten out of ten. It is a rock-solid product that works. We've so many deployments of this solution. I'm just happy with it. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Founder & Chief Operating Officer at a tech services company with 11-50 employees
Real User
Secure, reliable access, with good support that responds promptly
Pros and Cons
  • "It is easy to implement."
  • "It is already secure but it could be better in terms of other breaches that may occur."

What is our primary use case?

We use Sophos XG to provide access to our internal environment, to our infrastructure for our clients.

What is most valuable?

It is easy to implement.

It is very secure, which is why we have chosen it.

What needs improvement?

It is already secure but it could be better in terms of other breaches that may occur.

For how long have I used the solution?

I have been using the latest version of Sophos XG for a few months.

What do I think about the stability of the solution?

It's a stable solution.

What do I think about the scalability of the solution?

Sophos XG is scalable.

This solution is being used by approximately 800 to 1,000 people.

How are customer service and technical support?

Technical support is very good. They are very prompt.

Which solution did I use previously and why did I switch?

I have not used any other solutions before using Sophos XG.

How was the initial setup?

The initial setup is straightforward. It is easy to install and it only took a few hours to do.

You only need one person to maintain this solution.

What about the implementation team?

We have an in-house team to install and deploy the solution. We did not use an integrator.

What's my experience with pricing, setup cost, and licensing?

We pay our licensing fees yearly.

I don't think that it is expensive when you compare it with other solutions available on the market.

What other advice do I have?

We have not had any issues with this solution. I would recommend it and my advice is that people should definitely try it out.

I would rate Sophos XG a nine or a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Manager , SAP HANA Administrator at Tara Paints & Chemicals
Real User
Overall work well, reliable, but reporting needs more information
Pros and Cons
  • "Overall the solution works well."
  • "The reporting could be improved in this solution by adding more details."

What is most valuable?

Overall the solution works well.

What needs improvement?

The reporting could be improved in this solution by adding more details.

For how long have I used the solution?

I have been using this solution for approximately five years.

What do I think about the stability of the solution?

There used to be problems with the stability of the solution a few years ago but now the solution is stable and reliable.

What do I think about the scalability of the solution?

We have approximately 400 users using this solution in my company and we plan to increase usage in the future.

How are customer service and technical support?

The technical support has been good.

How was the initial setup?

The initial installation is straightforward.

What's my experience with pricing, setup cost, and licensing?

The solution is priced well.

What other advice do I have?

I am satisfied with the solution.

I rate Sophos XG a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Director at a consultancy with 1-10 employees
Reseller
Feature rich, useful QoS function, and straightforward installation
Pros and Cons
  • "The valuable features of this solution are the VPN, load balancer, and the QoS for splitting the ISP band."
  • "The reports could improve, they do not seem complete and more information could be added."

What is our primary use case?

I use this solution for a firewall and proxy server.

What is most valuable?

The valuable features of this solution are the VPN, load balancer, and the QoS for splitting the ISP band.

What needs improvement?

The reports could improve, they do not seem complete and more information could be added.

For how long have I used the solution?

I have been using the solution for approximately two years.

What do I think about the stability of the solution?

I am very happy with the stability of the solution.

What do I think about the scalability of the solution?

There are currently five people using this solution in my organization.

How are customer service and technical support?

The technical support is good and they provided me assistance through email.

How was the initial setup?

The initial setup is easy. It takes approximately three hours to install.

What's my experience with pricing, setup cost, and licensing?

There is a license required for this solution that is priced well and all the features are included.

What other advice do I have?

I would recommend this solution, it is very good.

I rate Sophos XG a ten out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Consultant at a tech services company with 51-200 employees
Consultant
Synchronized security with Sophos endpoints, easy to configure, and easy to deploy
Pros and Cons
  • "The most valuable is the synchronized security between Sophos XG and Sophos endpoint because it provides a lot of visibility about unknown applications. The endpoint shares the information of unknown applications, and you can learn about those applications and create policies to allow or block those applications."
  • "Everything is working as expected at this moment, but the anti-spam solution in Sophos XG needs to be improved. It needs more granular features and more stability. The anti-spam solution currently doesn't have many features, and we would like to have more features. At this moment, there is no expression filter for anti-spam. We need something to be able to filter subjects or attachments in emails based on the keyword. Sometimes, there is an issue with anti-spam, and Sophos XG suddenly stops processing incoming or outgoing emails. The only solution for this issue is to restart the appliance. Their support should be improved. It takes a long time to escalate a support case from level one to level two."

What is our primary use case?

Most of the clients use it for web filtering, application control, SSL inspection, and VPN. We have on-premise and cloud or virtual environment deployments. On the cloud, Sophos XG is on Azure or OVH.

What is most valuable?

The most valuable is the synchronized security between Sophos XG and Sophos endpoint because it provides a lot of visibility about unknown applications. The endpoint shares the information of unknown applications, and you can learn about those applications and create policies to allow or block those applications.

What needs improvement?

Everything is working as expected at this moment, but the anti-spam solution in Sophos XG needs to be improved. It needs more granular features and more stability. The anti-spam solution currently doesn't have many features, and we would like to have more features. At this moment, there is no expression filter for anti-spam. We need something to be able to filter subjects or attachments in emails based on the keyword. Sometimes, there is an issue with anti-spam, and Sophos XG suddenly stops processing incoming or outgoing emails. The only solution for this issue is to restart the appliance.

Their support should be improved. It takes a long time to escalate a support case from level one to level two.

For how long have I used the solution?

I have been using Sophos XG for six years.

What do I think about the stability of the solution?

It is stable, but sometimes, there is an issue with anti-spam, and Sophos XG suddenly stops processing incoming or outgoing emails. This is the only issue that I have with the anti-spam solution on Sophos XG.

What do I think about the scalability of the solution?

It is scalable. Most of our clients are small enterprises. We also have some medium enterprises.

How are customer service and technical support?

Their support should be improved. When we open a support case on their support portal, it first goes to their tier-one support. When an issue is complex, it takes a long time to escalate a support case to a level-two engineer, which is frustrating. Their response time is slow.

How was the initial setup?

Its deployment and setup are very easy. It is not at all complex to set up. The deployment duration varies. It can take around three days for a deployment with anti-spam, application control, IPS, and VPN with filtering.

What about the implementation team?

For its deployment and maintenance, usually, there are two of us, but sometimes, there is just one person.

Which other solutions did I evaluate?

Most of the customers here evaluate FortiGate against Sophos XG. Some of them also evaluate WatchGuard Firebox. In the past, FortiGate had the advantage of having an SD-WAN solution, but now Sophos also has an SD-WAN solution with a graphical user interface.

Sophos XG is very easy to follow and easy to configure, which is something very valuable for me and our customers. It is also very easy to use a site-to-site VPN with certificates, which is another pro. SD-RED devices are one more advantage that Sophos has over other vendors. These devices are very useful for those customers who don't have IT personnel in branch offices. With SD-RED devices, they can connect to the central site. The connection is automatically established with Sophos XG on the site. There is no need to have an IT person on the site.

What other advice do I have?

I would recommend this solution because it is really easy to implement. Sophos XG is very focused on cybersecurity. Its ability to synchronize information with Sophos endpoint is a very good feature when you are concerned about security. Other vendors or firewalls are more focused on establishing the connection and policies.

I would rate Sophos XG an eight out of ten. It is very good, but it could be better.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Infrastructure Administrator at CFA-INSTA
Real User
Top 20
Fully integrated, easy to use, and scalable
Pros and Cons
  • "I have found the solution easy to use and fully integrated."
  • "The solution could improve by having better security."

What is most valuable?

I have found the solution easy to use and fully integrated.

What needs improvement?

The solution could improve by having better security.

For how long have I used the solution?

I have been using this solution for one year.

What do I think about the scalability of the solution?

In my experience, I have found it to be scalable.

How was the initial setup?

The installation took approximately one day to complete.

What about the implementation team?

We did the implementation of the solution and we used a team of two.

What other advice do I have?

I would recommend this solution to others.

I rate Sophos XG a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Senior Executive IT at Mattsen Kumar LLC
Real User
After four years, we've never had a complaint from a customer
Pros and Cons
  • "We created and configured a VPN for connecting our remote sites and also to make it more secure and reliable. We also like its two-factor authentication features."
  • "The support service level agreement in regard to the amount of time needed to upgrade things is too low. It should be higher."

What is our primary use case?

We mainly use this solution for team meetings. We also implemented the LAN control for Sophos XG.

How has it helped my organization?

We have been dealing with this solution for the past four years and we haven't had any challenges or complaints from any of our clients.

What is most valuable?

We created and configured a VPN for connecting our remote sites to make them more secure and reliable. We also like its two-factor authentication features.

What needs improvement?

The support service level agreement in regard to the amount of time needed to upgrade things is too low. It should be higher.

For how long have I used the solution?

I have been using Sophos XG for roughly four years. 

What do I think about the stability of the solution?

This solution is both stable and secure.

How are customer service and technical support?

The technical support is good enough. 

What other advice do I have?

I would absolutely recommend this solution to others. It's far better than other solutions available on the market right now. This solution could benefit any organization. 

Overall, on a scale from one to ten, I would give this solution a rating of nine. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Administrator at a construction company with 51-200 employees
Real User
A stable and easy-to-deploy solution with a fair price and useful IPS and ATP features
Pros and Cons
  • "IPS and advanced threat protection (ATP) are the most valuable features. I am able to segment my network traffic and block incoming connections. It is also easy to use."
  • "I would like to have better SSL decryption and HTTP decryption. There should be filtering of SSL and HTTP traffic. Sophos XG consumes a lot of endpoint resources. It consumes a lot of RAM and CPU resources, and they should look into this."

What is our primary use case?

It is a firewall. It is used in my defense line. It provides defense and a form of security for my internal network.

What is most valuable?

IPS and advanced threat protection (ATP) are the most valuable features. I am able to segment my network traffic and block incoming connections. It is also easy to use.

What needs improvement?

I would like to have better SSL decryption and HTTPS decryption. There should be filtering of SSL and HTTPS traffic.

Sophos XG consumes a lot of endpoint resources. It consumes a lot of RAM and CPU resources, and they should look into this.

For how long have I used the solution?

I have been using this solution for two years.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

Its scalability is fine. We have about 40 users. We don't have any plan to increase its usage at the moment. However, it depends on recruitments and other things. If required, my company would change my box to a bigger one for better processing speed.

How are customer service and technical support?

Their technical support is okay. Sometimes, during the webinars, when I have some questions, they respond to them, but sometimes, I don't get any response.

Which solution did I use previously and why did I switch?

I have worked with Check Point before. Check Point is very expensive. At this time, we are not thinking of switching to another solution. If we were switching, Cisco Firepower would have been an option, but my colleagues, who have good experience with such solutions, would prefer to stay with Sophos XG. Cisco Firepower is a little bit complicated to use. It is also expensive. Cisco and Check Point have different boxes for different things, whereas Sophos brings everything into one box.

How was the initial setup?

It was straightforward.

What's my experience with pricing, setup cost, and licensing?

Its price is fair. It is cheaper and way better than others.

What other advice do I have?

I like this solution. I would rate Sophos XG an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Sr. Network Officer at a tech services company with 1,001-5,000 employees
Real User
Features a great firewall but better solutions exist regarding email security
Pros and Cons
  • "The user interface is very good."
  • "We are not very happy with the customer support they provide — it's quite slow."

What is our primary use case?

We use this solution as our main firewall. We also use it for email security purposes. Within our organization, there are roughly eight employees using this solution. 

What is most valuable?

The user interface is very good. As we've been using Sophos for four years now, we're very comfortable with the GUI interface. In addition, the IPS is quite good. 

What needs improvement?

We recently updated our previous version; now, the security licensing fee is quite high. I don't know if it's a bug in the OS, but it's not been very stable after we upgraded to the latest version.

For how long have I used the solution?

we have been using Sophos for XG for four years. 

What do I think about the stability of the solution?

Sophos is quite stable.

What do I think about the scalability of the solution?

It's not that scalable but it's good enough for us. 

How are customer service and technical support?

We are not very happy with the customer support they provide — it's quite slow.

A year ago, we contacted technical support regarding the high security licensing fees but they still haven't gotten back to us; they're still analyzing the log.

Support-wise, I would only give Sophos a rating of three to four out of ten. 

How was the initial setup?

For us, the installation was very straightforward. We deal with a local vendor and they guide us through the installation process. We haven't experienced any issues setting up this solution. 

What's my experience with pricing, setup cost, and licensing?

The price of Sophos is reasonable. It's not too expensive — I think it's worth it. Price-wise, I'd give Sophos a rating of eight out of ten.

Which other solutions did I evaluate?

Before Sophos, we were using Fortinet. Fortinet was also a good solution but Sophos was equipped with more features that we needed. 

What other advice do I have?

Feature-wise, I would give Sophos a rating of seven out of ten.

They need to improve their support, overall customer care, and lower the security licensing fees. If they improved these issues, I would give them a higher rating.

 Before upgrading any Sophos firmware, be sure to contact the Sophos team and upgrade it according to their advice. Without their advice, I wouldn't recommend performing an upgrade.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Manager at a hospitality company with 51-200 employees
Real User
User-friendly, easy to configure, and stable
Pros and Cons
  • "The interface is user-friendly and the product is easy to configure."
  • "Support for this product is something that is really important, and it needs to improve."

What is our primary use case?

We are using a basic model for its security features. We are in the hospitality industry and it has all of the features that we need.

What is most valuable?

The interface is user-friendly and the product is easy to configure.

What needs improvement?

Support for this product is something that is really important, and it needs to improve.

For how long have I used the solution?

I have been using Sophos XG for almost eight years.

What do I think about the stability of the solution?

This solution has been stable so far.

What do I think about the scalability of the solution?

This is a scalable product and we have about 45 people using it.

Only one person is required for maintenance.

How are customer service and technical support?

Before the current pandemic, technical support was good, but it is becoming worse.

Which solution did I use previously and why did I switch?

In the past, I have worked with SonicWall and Fortinet products.

I prefer Sophos because of the user-friendly configuration and stability.

How was the initial setup?

The initial setup is easy.

What's my experience with pricing, setup cost, and licensing?

This is a budget-friendly product with reasonable pricing.

What other advice do I have?

In summary, this is a good product and other than the support, I don't think that there is anything else that will improve it for us.

I would rate this solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Co-Founder at Multitechservers
Real User
A reliable product that provides remote VPN capability and multifactor authentication
Pros and Cons
  • "The multifactor authentication is helpful because whenever the user wants to connect to the firewall, they have to use the authenticator before they can access it."
  • "Technical support can be slow to respond, which is something that should be improved."

What is our primary use case?

We are using Sophos XG for remote two-factor authentication. We manage the web and application access, as well as the traffic. We also used it for remote, site-to-site VPNs.

What is most valuable?

The most valuable feature is the remote VPN.

The multifactor authentication is helpful because whenever the user wants to connect to the firewall, they have to use the authenticator before they can access it.

The LAN traffic management features such as implicit denial are very good.

What needs improvement?

Technical support can be slow to respond, which is something that should be improved.

In the future, I would like to see the addition of artificial intelligence for identifying and controlling traffic.

For how long have I used the solution?

We have been using Sophos XG for the past year.

What do I think about the stability of the solution?

This is a reliable solution.

What do I think about the scalability of the solution?

This product is scalable. We have approximately 400 users, spread across different departments. As our production increases and we onboard more users, we will extend the use of Sophos XG.

How are customer service and technical support?

The technical support team is good but sometimes, there is a large delay in answering the phones.

How was the initial setup?

The initial setup is straightforward.

What about the implementation team?

We had assistance from the vendor during the onboarding process when the system was being set up. They spotted a lot of things during the implementation, which helped.

What was our ROI?

We get a return on this investment because the inbuilt two-factor authentication means that we don't need to purchase a third-party tool for this security feature.

What's my experience with pricing, setup cost, and licensing?

The price is good and licensing fees are billed on a yearly basis.

Which other solutions did I evaluate?

We evaluated Cisco Firepower but we found that Sophos XG was more efficient in terms of cost. As such, we implemented XG.

What other advice do I have?

This is a product that I can recommend for organizations with a medium-level or large-level infrastructure.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
PeerSpot user
Vipin Garg - PeerSpot reviewer
Vipin GargCo-Founder at Multitechservers
Real User

Sophos XG Firewall is one of the best firewalls we have used till date. 2FA, Remote VPN also a number of features it has.

Network Engineer at a individual & family service with 11-50 employees
Real User
Reporting provides a lot of detail, dashboard is easy to use; technical support needs improvement
Pros and Cons
  • "Dashboard is easy to use and the reporting offers a lot of detail."
  • "Technical support is difficult to access."

What is our primary use case?

I generally use Sophos for the firewall and also for endpoint protection. 

What is most valuable?

The dashboard is easy to use and quite sensitive, I like it. The reporting offers a lot of detail and that's good. 

What needs improvement?

The technical support they offer is difficult to access. There is no direct number to call and when you do get hold of them and have confirmation, it takes a while to get a response.

For how long have I used the solution?

I've been using Sophos XG for about seven months. 

What do I think about the stability of the solution?

I haven't had any issues with stability. 

How are customer service and technical support?

Dealing with technical support is not simple. 

How was the initial setup?

The initial setup is straightforward. 

Which other solutions did I evaluate?

I know a little about Cisco which is less complicated than Sophos, but I prefer the Sophos dashboard. 

What other advice do I have?

I recommend this solution, the only issue is that it's not suitable for enterprise size companies. 

I rate this solution a seven out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
RSI at a logistics company with 201-500 employees
Real User
Easy to deploy and simple to use but the pricing could be lower
Pros and Cons
  • "The solution seems to be very easy to use."
  • "It would be helpful if the solution offered some tutorial videos to help new users learn the system quickly."

What is our primary use case?

We primarily use the solution for security and protection.

What is most valuable?

The solution seems to be very easy to use.

The administration is pretty simple.

The solution is easy to deploy.

We've found the solution to be quite stable.

My understanding is that the solution is scalable.

What needs improvement?

Cyberoam was extremely hard to develop. If this solution makes that process easier, we will be happy.

The solution should be lowered. It would help entice more clients. We'd like to pay a lower price.

We're concerned about the safety of our devices. We are worried if someone manages to hack the firewall, that they will be able to get past other protections and perhaps onto devices. We'd like Sophos to remain vigilant in its protective capabilities and to continuously update its solution to expand its security offering in order to better protect its customers.

It would be helpful if the solution offered some tutorial videos to help new users learn the system quickly.

There should be some trial on offer that allows users to try out the solution and learn it before implementing it.

For how long have I used the solution?

I've only been working with the solution for about one month or so. It hasn't been that long just yet.

What do I think about the stability of the solution?

The solution has been very stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable in terms of the performance it offers.

What do I think about the scalability of the solution?

The solution is scalable. If a company needs to expand it, it shouldn't have any issues doing so.

We have about 200 people using it in our company.

How are customer service and technical support?

I have not used technical support just yet. If some issue comes through in the future, I will reach out. However, as of now, I can't speak to their level of responsiveness or their knowledgeability.

Which solution did I use previously and why did I switch?

I used to use Cyberoam. However, this particular solution was acquired by Sophos, and therefore, now the company I work for uses Sophos. It's pretty much the same product.

How was the initial setup?

The product is pretty easy to deploy. We use a gateway from our partner, and not with Sophos.

What's my experience with pricing, setup cost, and licensing?

The solution is a bit costly. It would be ideal if it was less expensive for its user base.

We pay a yearly licensing fee. We do not pay monthly.

What other advice do I have?

I'm a customer and an end-users. I do not have a business relationship with Sophos.

I'm not sure which version of the solution we're using. It might be version 65 or something like that.

We do not use the cloud version. It's for device management, and therefore it's on-premises.

Currently, I would rate the solution at a seven out of ten. I haven't used it for very long, and can't fully evaluate it; I must learn more about the offering and what it can do first.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Entrepreneur at Carmel Infotech Solutions
Reseller
Good reporting, stable, with local support available
Pros and Cons
  • "It is feature-rich, I like the server authentication, and the reports are good."
  • "In the next release, I would like to see improvements made to the policy and simplify the policy-making, as the complexity of it makes it really tough."

What is our primary use case?

I am a reseller.

What is most valuable?

It is feature-rich, I like the server authentication, and the reports are good.

What needs improvement?

The recent changes of the policy compared to Cyberoam are a little bit less user-friendly and complicated. Cyberoam is much easier to use.

Security could be better.

In the next release, I would like to see improvements made to the policy and simplify the policy-making, as the complexity of it makes it really tough.

For how long have I used the solution?

I have been working with Sophos XG for more than six years.

What do I think about the stability of the solution?

It's a stable product.

What do I think about the scalability of the solution?

It's more scalable than most, but like other products, a Sandbox cannot be scalable.

Our clients are small and medium-sized companies.

How are customer service and technical support?

We get a local-level team for support. There is less support with Cyberoam.

Which solution did I use previously and why did I switch?

Cyberoam is the first product I started selling. We sell Fortinet also. Customers prefer Fortinet.

There is not a lot of difference between Sophos and Fortinet, they are very similar but in a large environment, Fortinet is better.

How was the initial setup?

The initial setup is really not a problem, but the policy-making is a bit complex.

What's my experience with pricing, setup cost, and licensing?

The price is not reasonable. The price is a bit higher.

Cyberoam is better in terms of cost.

What other advice do I have?

I always recommend Sophos but there is a Enterprise security concern so I prefer Palo Alto.

I would rate Sophos XG an eight out of ten.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
PeerSpot user
Senior Manager, Information Technology at a university with 201-500 employees
Real User
Top 5Leaderboard
Reliable and easy to install, but the policies should be upgraded
Pros and Cons
  • "It is simple to use."
  • "In the next release, I would like to see improvements to simplify the interface and more policy deployments."

What is our primary use case?

We use this solution as a firewall for everyone to connect to the internet.

We protect ourself and we use it as a VPN to connect to the internal network. 

How has it helped my organization?

It is improved significantly. 

What is most valuable?

It is simple to use.

What needs improvement?

The interface should be changed. It should be more user-friendly.

They should also update the policies and statistics because Fortinet is better, but Sophos could grow.

In the next release, I would like to see improvements to simplify the interface and more policy deployments.

For how long have I used the solution?

It was Cyberoam and we upgraded to Sophos XG. We have been using Cyberoam for more than 10 years and more than one year with Sophos XG.

We were on version 17 and have just upgraded to version 18.

What do I think about the stability of the solution?

It's stable. We have no problem at all with stability or with Sophos XG.

What do I think about the scalability of the solution?

Its high availability is fine, it's good. It's scalable as well.

 We have approximately 500  employees using this solution.

We will continue and increase our usage of this product.

How are customer service and technical support?

We had one issue with Cyberoam, but it was upgraded with Sophos. They helped us, but it takes a bit of time to resolve it but it's fine. 

Which solution did I use previously and why did I switch?

We also use Fortinet FortiGate for large locations. The Fortinet usage is completely different than Sophos. Sophos is simple, but I prefer Fortinet.

How was the initial setup?

It's easy to install. 

It takes the team one hour to launch it.

We have a team of 15 people to deploy and maintain this solution.

What about the implementation team?

We completed the installation ourselves.

What's my experience with pricing, setup cost, and licensing?

We purchased the technical appliances for on-premises.

We have our license for three years.

Which other solutions did I evaluate?

Yes. Fortinet. However the price is much better to Fortinet.

What other advice do I have?

I would recommend Sophos XG to others, but it would depend on their capacity.

I would rate Sophos XG a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Consultant at Wavednet Group
Consultant
Enhanced security features, easy to use for all users, and has informative reports
Pros and Cons
  • "The solution has very good security features, is easy to use for administrators and users, and has informative reports."
  • "I would like to see in future releases a tool to scan for malicious packets and give the location of where they are coming from."

What is our primary use case?

We are an IT solution company and we provide network security. This solution is used for securing your network.

What is most valuable?

The solution has very good security features, is easy to use for administrators and users, and has informative reports.

What needs improvement?

I would like to see in future releases a tool to scan for malicious packets and give the location of where they are coming from. Nowadays all over the world is suffering from ransomware threats. If they could map where those packets are coming from and make the packet monitoring more efficient it will be helpful to prevent more of these kinds of threats.

For how long have I used the solution?

I have been using the solution for approximately five years.

What do I think about the stability of the solution?

The solution has been highly stable.

Which solution did I use previously and why did I switch?

We have used SonicWall and Fortinet in the past.

How was the initial setup?

The installation is very easy for anyone. The configuration is straightforward, all the information is available through a quick Google search.

What's my experience with pricing, setup cost, and licensing?

The price can be a bit steep but for the number of features, it is worth it. Additionally, the enterprise version of this solution is priced well for all the features that you receive.

If you are thinking about implementing Fortinet, SonicWall, or any other product you will pay extra for additional security features and might need to purchase additional licenses. If they just spend a little more on this solution they will get the extra features for the same amount.

Which other solutions did I evaluate?

This solution has security features that in other solution you have to purchase them as add-ons, such as malware and email filters. Comparing this solution overall to competitors it is by far the best.

What other advice do I have?

I rate Sophos XG an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Sales Manager at INFOSEC
Real User
Top 20
Stable with a good cloud-based console and great for enterprise-level organizations
Pros and Cons
  • "The product has a console that is based in the cloud for all their products. In this console, they have email security, firewall security, endpoint security, et cetera. All of the products on offer in the console are very useful for us."
  • "The manuals or guides we are given are too simple. When we are implementing the product, it is difficult for us as we don't have more detailed information."

What is most valuable?

The product has a console that is based in the cloud for all their products. In this console, they have email security, firewall security, endpoint security, et cetera. All of the products on offer in the console are very useful for us.

The solution is stable.

The solution works well for enterprises and large-scale organizations.

What needs improvement?

The manuals or guides we are given are too simple. When we are implementing the product, it is difficult for us as we don't have more detailed information. 

The technical support on offer is slow. When I have questions, they answer me very slowly. Sometimes within 24 hours, I have a response. However, it can be longer. In Mexico, Sophos doesn't have technical support locally. It's in Argentina or in other countries. It would be nice if support was available in the country.

What do I think about the stability of the solution?

The stability is okay. That said, as an enterprise solution, it can be a bit unstable during the initial implementation.

What do I think about the scalability of the solution?

The solution works well for enterprise-level organizations.

How are customer service and technical support?

We're not overly satisfied with technical support. We'd like to see local support, from within our country. Due to the fact that it is coming from outside, the response is very slow. We'd like it to be faster. We aren't completely satisfied with the level of service we get. 

How was the initial setup?

The initial setup is difficult in that there isn't enough documentation available to walk a user through the process. It can cause some issues. It's not exactly straightforward.

What about the implementation team?

Sometimes we need to work with other resellers. We don't always implement the solution by ourselves. 

What other advice do I have?

We are partners with Sophos.

We are using the 130-type of solution.

We take a hybrid approach to deployment. Some servers are on-premise and some servers are in-cloud.

I'd rate the solution at an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior solution architect at a comms service provider with 51-200 employees
Real User
Suitable for any environment, plenty of features, and strong protection capabilities
Pros and Cons
  • "The solution has all the security features you would need for any type of environment."
  • "In feature releases of the solution, I would like there to be an increase in the detection capability."

What is our primary use case?

We use the solution for typical perimeters a firewall is used for. Recently they have added some more additional security such as web application firewalls and email security as part of their offering.

What is most valuable?

The solution has all the security features you would need for any type of environment. I have found the protection capabilities and email security protection most valuable.

What needs improvement?

In feature releases of the solution, I would like there to be an increase in the detection capability. The detection is low compared to the other solution available in the market.

For how long have I used the solution?

I have been using the solution for approximately three years.

What do I think about the stability of the solution?

The solution has been stable. However, two years ago there were some issues causing stability concerns.

What do I think about the scalability of the solution?

I have found the solution to be scalable.

How are customer service and technical support?

I have found the technical support could be more knowledgeable and faster in the future.

How was the initial setup?

The installation was very easy. When comparing the installation to other firewalls it takes approximately the same amount of time. We were able to complete the migration from our old firewall in one day. In terms of migration downtime, it is in the average range compared to other solutions. The rolling out of the policies time depends on the existing environment.

What about the implementation team?

The deployment and maintenance of the solution can be done by one technician, it is very simple.

What's my experience with pricing, setup cost, and licensing?

There is no license required to use this solution.

What other advice do I have?

I would recommend this solution to others.

I rate Sophos XG an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
Senior Technical Consultant at Hash 1 IP services llp
Consultant
Good content filtering and intrusion prevention, but needs better quality checks for firmware upgrades and better support
Pros and Cons
  • "Content filtering and intrusion prevention are most valuable. Our customers are fully satisfied with the performance of Sophos. It has all the features that they require in a firewall."
  • "They need to do more quality checks before they release firmware upgrades. Currently, a few Cyberoam firewall customers are facing some issues while upgrading the Cyberoam firmware to Sophos. After the new firmware is installed, they are seeing some performance issues, which require some bug fixes. The performance is fine after getting the required support. Customers who are already using Sophos hardware are quite satisfied with this solution. Their support should also be improved. We are facing difficulties getting support on time through email or phone."

What is our primary use case?

I'm providing services to my customers. They are using Sophos firewalls, and a few of them are also using antivirus.

What is most valuable?

Content filtering and intrusion prevention are most valuable. Our customers are fully satisfied with the performance of Sophos. It has all the features that they require in a firewall. 

What needs improvement?

They need to do more quality checks before they release firmware upgrades. Currently, a few Cyberoam firewall customers are facing some issues while upgrading the Cyberoam firmware to Sophos. After the new firmware is installed, they are seeing some performance issues, which require some bug fixes. The performance is fine after getting the required support. Customers who are already using Sophos hardware are quite satisfied with this solution. 

Their support should also be improved. We are facing difficulties getting support on time through email or phone.

For how long have I used the solution?

I have been using this solution for three to four years.

How are customer service and technical support?

I regularly contact them. Connecting Sophos support is quite a difficult task during the pandemic. We are facing difficulties getting support on time through email or phone. Sometimes when a problem comes, it has to be sorted for the customer quickly, but it is taking time. One of the customers has just upgraded a firewall from Cyberoam firmware to Sophos, and it took them around ten days to get that firewall upgraded from Sophos.

Which other solutions did I evaluate?

Most of the customers compare Sophos with Fortinet. In comparison to Fortinet, people are more satisfied with Sophos. Sophos has a big customer base in India. Therefore, they are good in terms of performance and customer satisfaction.

What other advice do I have?

I would rate Sophos XG a seven out of ten. We are satisfied with its performance.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
IT Manager for Network and Security at a religious institution with 51-200 employees
Real User
Good reporting and scalability with great anti-spam capabilities
Pros and Cons
  • "They really work scalability into the solution at the outset."
  • "The SD-WAN could be improved."

What is our primary use case?

We are primarily using Sophos XG for the identity base, policies, load balancing, and SD-WAN. Right now we have separate, different branches, therefore, we need to integrate it with SD-WAN. Of course, with SD-WAN, we need to do the load balancing, the VPN failovers, and also watch the connectivity. We are more particular on the link, and also the implementation of user policies.

What is most valuable?

The Multi-Link, or the Multi-Wan, SD-WAN, is extremely valuable to our organization.

The Anti-Spam and the Gateway Anti-Virus capabilities have been very useful.

The solution offers a very good Network Ring, QRS, and landing management. 

We've found that the reporting is very good overall.

They really work scalability into the solution at the outset.

What needs improvement?

The SD-WAN could be improved. It is not yet full-blown; it's only basic, really. They need to move on with the algorithm on how the SD-WAN works, and how it works in comparison to other brands of SD-WAN. Sophos should study those algorithms on how they do the SD-WAN to learn a few things that may help them build out their own solution.

For how long have I used the solution?

I've been using the solution and various other Sophos solutions for a while.

What do I think about the scalability of the solution?

If you do the right planning, most of the time Sophos is good for five years. It depends on the recommendations as well. Sometimes the Sophos team or supplier will show you the number of users or number of networks and they'll illustrate to you a plan most suited to what you have and what you might have. They assess everything and give you a five-year plan. That way, if you need to expand, they've already taken that into consideration at the outset and there's room to scale.

We have about 100 users.

Due to the pandemic, we don't really have any plans to expand. We may be downsizing a bit. We'll see.

How are customer service and technical support?

We've been satisfied with Sophos' technical support. They are very helpful and responsive. Their staff is quite knowledgeable.

How was the initial setup?

I've worked with Sophos previously and we had a different setup. In terms of implementation, sometimes there are complex setups and sometimes the setup s are more basic. Right now, we have a complex setup. We need to ensure interconnectivity between our branches. We'll have different networks, different sites, and a lot of complexity. 

It doesn't really take too long to deploy, however. The support from the supplier is good. They're always available to assist. They are well-trained and they are already familiar with the setups and configuration so they're doing a pretty good job in terms of helping us.

What about the implementation team?

The supplier, the reseller, the partner of Sophos, is doing the change for the end-users. Most of the basic configuration has already been already done by us, however, for more complex areas, we could ask them, and they could come to us to configure it for us.

What's my experience with pricing, setup cost, and licensing?

The pricing is based on the acquisition cost.

Which other solutions did I evaluate?

We have evaluated a few different solutions. We've looked at Palo Alto and FortiGate products. In terms of our end-point security, we've also looked at Trend Micro and a few others.

What other advice do I have?

We are just a customer and an end-user.

We are using the latest version of the solution.

ON a scale from one to ten, I would rate this solution at an eight.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Manager at a outsourcing company with 5,001-10,000 employees
Real User
Protects our network but has a limited range of IP addresses
Pros and Cons
  • "Sophos XG protects our network from advanced threats."
  • "There's an IP address delivery for our VPN client and a limited range of IP addresses. So this is a problem in the latest firmware release, but rather than using homework scenarios, we need a lot of VPN clients."

What is our primary use case?

Sophos XG protects our network from advanced threats.

What is most valuable?

VPN client list has a secondary client, so we need to use it without specific software for Sophos Connect client. I am using the VPN client list and it works fine.

What needs improvement?

There's an IP address delivery for our VPN client and a limited range of IP addresses. So this is a problem in the latest firmware release, but rather than using homework scenarios, we need a lot of VPN clients.

For how long have I used the solution?

I have been using Sophos XG for a couple of years.

What do I think about the scalability of the solution?

It's important to put together the VPN client features and others because we need to use this to improve the scenario and implement the IP address delivered to the VPN client. With another point of sale there, I believe that incorporating the two solutions is important to make the VPN client work.

How are customer service and technical support?

We offer contact center services and have a channel to reach the product support team, and they are ready to help when needed.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Head of Network Department at a financial services firm with 1,001-5,000 employees
Real User
A stable firewall solution, but the GUI and support could be better
Pros and Cons
  • "Sophos is a stable solution, and we haven't had any bugs or limitations."
  • "The GUI and support could be better. I think there are other products that we are going to deploy instead of Sophos. We have already upgraded a month ago because the interfaces and support for Sophos are really weak. But other products like Juniper, Cisco, or FortiGate are better than Sophos. It's also complicated, and the end-user or client does not understand it."

What is our primary use case?

We use the SRX from Juniper as the second firewall, and Sophos is useful as a first firewall facing the internet edge. We also use it as an SD-WAN, and we're going to use it as a load balancer instead of a BIG F5 load balancer. All of the things like web filtering and internal email filtering will be inside Sophos XG.

What is most valuable?

Sophos is a stable solution, and we haven't had any bugs or limitations.

What needs improvement?

The GUI and support could be better. I think there are other products that we are going to deploy instead of Sophos. We have already upgraded a month ago because the interfaces and support for Sophos are really weak. But other products like Juniper, Cisco, or FortiGate are better than Sophos. It's also complicated, and the end-user or client does not understand it.

The interfaces and the GUI design are not easy, and when you do something, unrelated things are in the same configuration site. There are different sites to visit to configure Sophos. This is even more than other products. Many features can be improved, especially the VPN and web filtering features.

For how long have I used the solution?

We have been using Sophos XG for about five years.

What do I think about the stability of the solution?

Sophos XG is stable. 

How are customer service and technical support?

Technical support could be better. I already opened a ticket three days ago, but they are not interested or have not cooperated with the end customer. But Juniper and Cisco are fast to respond compared to Sophos. Sophos is really complicated, and it's not fair to buy the annual support when they don't provide any support quickly when you request it.

What's my experience with pricing, setup cost, and licensing?

The price is fair.

What other advice do I have?

I would advise potential users not to use Sophos if they are not buying the appliance. They should use another product like FortiGate, Check Point, or Palo Alto.

On a scale from one to ten, I would give Sophos XG a six.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Information Technology Project Manager at a tech vendor with 201-500 employees
Real User
Makes it easy to manage multiple endpoints in a centralized platform, but data traffic analysis could be better
Pros and Cons
  • "I like how you can integrate with other endpoints and Intercept X in one central management platform. I think it's a perfect solution. Sophos will manage everything in one container. You can manage many firewalls or endpoints within one panel."
  • "Data traffic analysis could be better. I think Fortinet products like FortiAnalyzer are very effective in analyzing data traffic. I think it's better than Sophos. It could also be more stable."

What is most valuable?

I like how you can integrate with other endpoints and Intercept X in one central management platform. I think it's a perfect solution. Sophos will manage everything in one container. You can manage many firewalls or endpoints within one panel.

What needs improvement?

Data traffic analysis could be better. I think Fortinet products like FortiAnalyzer are very effective in analyzing data traffic. I think it's better than Sophos. It could also be more stable.

For how long have I used the solution?

I have been using Sophos XG for more than two years.

What do I think about the stability of the solution?

I think Sophos has to concentrate on the latest firmware's stability because we have version 18, and we have many problems with our customers who have this version. I think Sophos has to thoroughly test the firmware before launching it. When you get any update on any hardware device, you get many problems. It's not good.

What other advice do I have?

On a scale from one to ten, I would give Sophos XG a seven.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Senior Engineer at a engineering company with 11-50 employees
Real User
Easy to deploy and configure, good documentation, and works as advertised
Pros and Cons
  • "It is very easy to configure and straightforward. The firewall rules are straightforward. It works great out of the box. It has been working as advertised, and I haven't had any issues with it."
  • "Its user interface is a little bit slow."

What is our primary use case?

We are using it for our VPN and firewall. It acts as our firewall for the external portal into our network.

What is most valuable?

It is very easy to configure and straightforward. The firewall rules are straightforward.

It works great out of the box. It has been working as advertised, and I haven't had any issues with it.

What needs improvement?

Its user interface is a little bit slow.

For how long have I used the solution?

I have been using this solution for a couple of weeks.

What do I think about the stability of the solution?

It has been up and running for probably three weeks and hasn't had any issues. I didn't have a lot of time on it yet to make a good call about that, but so far, so good.

What do I think about the scalability of the solution?

It scales for our purposes. We're a very small office. We have 25 users on the system. We're an engineering consulting company, so all remote users are accessing our network

It is being used quite heavily, and I don't see any need to increase its usage at all at this point.

How are customer service and technical support?

I didn't have any direct interaction with Sophos. Their online documentation is very good. It is much better than Cisco.

Which solution did I use previously and why did I switch?

It was a replacement for Cisco ASA Firewall. Our Cisco licensing had expired, and it was very expensive. Sophos XG is a lower-cost solution for the same thing. It was also easier to configure.

How was the initial setup?

It was very simple. It took a couple of hours.

What about the implementation team?

We had a partner, and they did the initial setup and walked us through it. Our experience was very good.

Its maintenance is very simple. You need less than one administrator for its maintenance.

What was our ROI?

I expect to see ROI in a year or two.

What's my experience with pricing, setup cost, and licensing?

Its licensing cost is around 700 bucks a year or something like that. It is 100 bucks a month at the most. It seems to be standard licensing with no additional costs.

What other advice do I have?

I would advise others to go through the Sophos demos. They are very good, and they walk you through configuration and use cases. Their online documentation is very helpful in not only configuring it but also selecting a proper model to deploy.

I would rate Sophos XG an eight out of ten for ease of use and cost.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Head ICT at a tech services company with 11-50 employees
Real User
Reliable, easy to install, reasonably-priced, with good management control
Pros and Cons
  • "I like the dashboard, the interface, the management console, and the remote login."
  • "I would want the level of integration to have another device on your network that is also reliable."

What is our primary use case?

We use this solution as a firewall, and for remote login during the lockdown period.

We have used Sophos client, which is connected to the firewall to help our users to log in remotely. 

How has it helped my organization?

We have always used firewalls, this is just a different one that we have deployed. It allowed our clients to log in remotely. 

It has also helped us with outbound and inbound account management.

We have used it to manage the usage of the sites and helping to control the internet usage during productive hours.

What is most valuable?

I like the dashboard, the interface, the management console, and the remote login.

What needs improvement?

I would like to explore network access control. I haven't seen that it is clearly deployed.

It might be something that is already in place, or if it is available on another device.

I would want the level of integration to have another device on your network that is also reliable.

For how long have I used the solution?

I have been using Sophos XG for three years.

What do I think about the stability of the solution?

It's very stable. It has never given us any problems.

When there are power failures, we have to reboot the network.

What do I think about the scalability of the solution?

We have not tested the scalability. Our users are below 100, and from the time that we got it, our number of users has not gone above that original 100.

From what I have read, it's scalable and we have plans to increase our usage. For example, we are not using the Intrusion section, which is an area that we want to use. 

We also plan to install the Sophos endpoint.

We are looking at integrating the two solutions and seeing how they work.

We have been using a different antivirus for our endpoints.

How are customer service and technical support?

I haven't used technical support from Sophos. I have not required it. It's been easy for me to sort out myself.

Which solution did I use previously and why did I switch?

Sophos was our first physical firewall device on our network.

Before that, we were using Linux-based open-source software firewalls.

How was the initial setup?

The initial setup is straightforward. It is easy to install.

What's my experience with pricing, setup cost, and licensing?

The price for the firewall is reasonable.

The endpoint, however, is expensive. The price is not very standard, considering where we are coming from.

What other advice do I have?

We are considering Sophos endpoint and should have it next month.

I would recommend Sophos XGto others.

I would rate Sophos XG an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Project manager at a tech services company with 51-200 employees
Reseller
Top 20
Provides quality threat protection
Pros and Cons
  • "Sophos XG deployment is easy and rapid."
  • "Sophos XG's web server protection and log viewer could improve. They should also introduce sandboxing."

What is our primary use case?

Our clients from the governmental and enterprise sectors have multiple use cases for this product. 

What is most valuable?

The most valuable feature of this product is threat protection. Filtering and web protection are important as well. 

What needs improvement?

Sophos XG's web server protection and log viewer could improve. They should also introduce sandboxing. 

For how long have I used the solution?

I have about five years of experience with this solution. 

What do I think about the stability of the solution?

The solution's stability is fine. 

What do I think about the scalability of the solution?

There is not much flexibility or scalability with this solution. 

How are customer service and technical support?

The Sophos XG technical support is good. 

How was the initial setup?

Sophos XG deployment is easy and rapid. 

Which other solutions did I evaluate?

Most of our clients that end up choosing Sophos XG also consider Fortinet. However, Sophos XG has a better user interface. It is also better with managing users, updates, and integrating with Active Directory. 

What other advice do I have?

Before deciding on this product, it's important to evaluate the price of the network. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
Head of Cybersecurity at mundo credito
Real User
Management centralized, highly scalable, and technical support helpful
Pros and Cons
  • "I have found the feature allowing you to manage everything from a centralized location beneficial."
  • "I am using the Azure Active Directory in my company and it was complicated to integrate this solution with Azure."

What is our primary use case?

We are using the solution as a firewall to protect all the computers in our financial organization, we did not have one before.

What is most valuable?

I have found the feature allowing you to manage everything from a centralized location beneficial.

What needs improvement?

I am using the Azure Active Directory in my company and it was complicated to integrate this solution with Azure. I had to use an internal VPN and had to do many configurations to get it operating. This process should be easier to implement.

For how long have I used the solution?

I have been using the solution for the past six months.

What do I think about the stability of the solution?

The solution has been stable in my experience.

What do I think about the scalability of the solution?

One of the main reason I chose this solution was great scalability. I have approximately 150 people using this solution in my company.

How are customer service and technical support?

The technical support is very good. Two months ago we needed help with implementation and they helped us with the configuration of Azure and this solution. You are able to find everything in the documents for the solution, it comes with easy to follow information with photos.

Which solution did I use previously and why did I switch?

I was using Cisco products before and we decided to switch to this solution because of Sophos Central and it is easier to manage. 

How was the initial setup?

The setup was easy to manage for this solution.

What about the implementation team?

It has taken us six months to implement the solution and I am still deploying my system. We used another company to help us do the deployment and maintenance is done by a team of three.

What's my experience with pricing, setup cost, and licensing?

I paid for a license for the solution for three years costing approximately $11,000. Additionally, I received the Web Appliance fee for paying for the full license. 

What other advice do I have?

All my experience with this solution has been good. I would recommend this to others and already have.

I rate Sophos XG a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
CEO at MARVIV SRLS
Real User
Top 20
Light and stable with excellent real-time control
Pros and Cons
  • "It's a product that is in continuous improvement and is following what the customer is asking for. They are taking inputs and designing new releases specifically according to the client and their needs."
  • "The solution could offer a bit more integration with other systems, with other platforms - just to be able to extend the capability and to interface with other kinds of platforms or systems that I can find on the market as it gives the possibility to improve the level of integration."

What is our primary use case?

I'm using the solution mainly for its firewall application and to prevent intrusion in the system. The XG platform is very powerful from the perspective of identification and to prevent potential attacks on the system due to its the capacity to predict and to anticipate the potential damage on the system.

It's integrated inside the system, meaning that it can control all the endpoints in the system and talk with them and identify any potential situation. It can also isolate one area inside the system without compromising the entire system. This allows you to isolate the initial problem without involving the entire infrastructure. 

You have real-time control of all your infrastructure. It is integrated with the hardware and offers good performance alongside the hardware and by the firmware, and these work together to control the entire infrastructure.

What is most valuable?

The real-time control on offer is excellent.

We really appreciate that you can segment and quarantine certain sections of your system without having to shut down the entire operation.

The product has artificial intelligence that has the capability to quickly identify which could be the potential risk mainly for intrusions like ransomware or a new kind of typology of attacks that are in place right now. 

The idea is to mainly prevent the condition and not to manage the situation, as, if that happens, in many ways, it's already too late. It's to identify the condition that can help the company to prevent or mainly to reduce the risk of an intrusion. In that sense, its performance is excellent. 

The product is doing it job without affecting the system with a heavy load. The activity on offer is very light in terms of resources that are required by the system. It does not require a lot of resources in terms of memory, et cetera. There is no performance impact on the system. The customer doesn't detect its presence on the system when it's working, and yet they still get all of the great benefits of protection.

The solution has been quite stable. 

It's a product that is in continuous improvement and is following what the customer is asking. They are taking inputs and designing new releases specifically according to the client and their needs.

It's one of the best products on the market as it really understands where the market is moving and iterates based on the future. It's constantly improving. It does a great job at keeping confidentiality while guaranteeing security.

The solution doesn't just offer theoretical security, it really does offer very good, real-time security and delivers on its promise to the client.

What needs improvement?

There is no specific features request right now really. I see that all the features that Sophos is implementing and is proposing on the market follow exactly what the market is asking. It's difficult to identify something that is missing compared with what the market can ask as one of the most important things that Sophos does is have the capability to anticipate in a certain way what the market expects. As a leader on the market, they tend to have the solution just before the market is asking them for it. 

The solution could offer a bit more integration with other systems, with other platforms - just to be able to extend the capability and to interface with other kinds of platforms or systems that I can find on the market as it gives the possibility to improve the level of integration.

What do I think about the stability of the solution?

The solution is very stable. There are no bugs or glitches. It doesn't crash or freeze. It's very reliable.

What do I think about the scalability of the solution?

The solution is quite scalable. You have to consider that all Sophos products are scalable. This is one of the main characteristics of the system. It means that you can start with a base solution that is very simple and improve this step by step without losing what you have done in the past. It's scalable in the sense that you have a different layout that you can cover, however, you don't have to dismiss what you have done in the past. You have just to integrate. In this way, if you consider the cost of implementation for the company, it has the possibility to optimize the cost because the company has the possibility to appreciate the system initially, and then improve the system step by step without losing what has been done in the past.

This means the company has the possibility to distribute the cost if you're in a certain period of growth. Normally some companies start to say, "I want to guarantee to control to the outside with a certificate and give the possibility to access my data in a controlled way. After that, I want to extend the security on the email that is managed by the company. I want to encrypt the data on the server and so on." All these features can be approached in a step-by-step manner instead of all at once, and you can implement them on the system in different ways and at different times.

We normally have about 50 users and around five technicians.

Which solution did I use previously and why did I switch?

I also currently use Cisco products alongside Sophos.

However, we did not previously use a solution that was different from Sophos.

How was the initial setup?

The initial setup is not so complicated. The system is not complicated to understand and also in can be installed without a very high level of expertise. Of course, if you have this kind of expertise, you can obtain from the system the maximum performance that the system can do, however, it means that you are not obliged to be a guru to be able to use these kinds of products. You can use these kinds of products just as an IT manager inside the company without having or needing special knowledge. 

Otherwise, you can leave to Sophos with the capability of doing something like a close box. You are sure that Sophos is able to guarantee the level of security that you are expecting. You can have it be automatic, or you can choose to go more manual in its operations. For example, if you were a professional photographer, you'd probably like a manual experience, as it would allow you more leeway with your craft, and if you were an amateur, you 'ld likely prefer an automatic camera that handles the heavy lifting for you. Sophos, in that sense, is the same. If you want, you can configure single parameters, or you can leave it to Sophos to give you something out-of-the-box.

In any case, if you stay on the automatic configuration, you are guaranteed that the system can provide the correct level of service that you want. It means that it's not required to have an expert. That said, you need of course to have a minimum level of knowledge, as it's clear that you need to know what you are managing. Starting from that, you can obtain what you need without moving into an advanced configuration.

Typically, a configuration takes about half a day or so, if you go that route. It doesn't take long, as those who would handle it would know what they are doing.

What about the implementation team?

We handled the implementation ourselves, in-house. We did not need the assistance of an implementor or consultant. I have enough knowledge on the solution to manage it myself.

What other advice do I have?

I'm mainly a user. Sometimes I handle installations.

I'm using the latest version of the solution. I don't have the version number on-hand.

We do plan on continuing to use the solution. I've been quite please with it overall.

I would recommend the solution to others. It's worked quite well so far and really leads the market.

I would rate the solution at a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Software Engineer at a tech services company with 201-500 employees
Real User
Dual antivirus sets solution apart from other vendors
Pros and Cons
  • "Sophos CG is cost-effective, which makes it really suitable for SMB. If you want basic security and more embedded features, go with Sophos XG."
  • "We are facing some technical issues with Sophos XG right now. We have already escalated this issue with the Sophos technical support. They seem to be working on it. We are satisfied with the technical support. They reply quickly to our queries, but sometimes take time upgrading their systems."

What is our primary use case?

We do not have a primary use case for this solution. We are using Sophos XG to configure wireless networks. Some of our clients have Sophos XG integrations and we are using the MAC filtering on it. 

We also use the Sophos XG antivirus, content filtering, and as a secure email gateway. 

We have a bundled license with an email security subscription. We also use the free Sophos XG VPN. 

What sets Sophos XG apart from other vendors is the solution's dual antivirus. We enabled the Security Heartbeat feature, which synchs endpoints with the network layer antivirus; they work as a single unit. If there is a virus attack from outside world, the firewall handles it. If a virus comes when the network layer is idle, the endpoint protection takes care of it, which is why we are using this solution in our office scenario.

What is most valuable?

The solution is not vulnerable and that is the most important aspect of it for me. We deployed the Sophos XG firewall on the Edge browser and everything that comes in from the outside world as a potential threat is handled by the firewall.

I'm satisfied with the user interface and the solution's security level. They have a sandboxing solution for zero-day threats and a real-time cloud solution with millions of tags. I think the number at this point is four million tags. This is a good features in Sophos XG; it provides more security against new attacks, which are generated every day.

What needs improvement?

I don't see any drawbacks to this solution at the moment. I know of other products that have more features and are more advanced stages, but ultimately, an organization's choice of software depends on its budget. If you have a small amount of money and you want to secure your network, Sophos XG can provide you with network security. Sophos ZG is a mid-range solution. There are solutions that are above it in terms of features on the market, but they cost more money. 

They could work on their technical support to make it more productive for the end customer. Some of my friends and colleagues have had unfavorable experiences with the tech support taking too long to close their ticket. However, I opened two cases this week and both have been resolved. 

For how long have I used the solution?

I have been using Sophos XG for five years. 

What do I think about the scalability of the solution?

My impressions of the solution's scalability is that it varies depending on the model or capability of the box. When we have clients that want to deploy a small box on 200 or 150 users, we suggest that they get a box that's better able to cater to problems and their traffic. If a customer has 35 or 50 users, we will propose just a small box.

How are customer service and technical support?

We are facing some technical issues with Sophos XG right now. We have already escalated this issue with the Sophos technical support. They seem to be working on it.

We are satisfied with the technical support. They reply quickly to our queries, but sometimes take time upgrading their systems.

How was the initial setup?

The initial setup was not complex. I was new to the solution when I deployed it and I didn't face any problems; it wasn't a hassle or challenging for me.

Which other solutions did I evaluate?

I did not evaluate any other options. 

What other advice do I have?

This is a mature product. It has a good Gartner rating. It is best for the enterprise level, for the SMBs. Anyone can deploy according to the needs of their customers.

Sophos CG is cost-effective, which makes it really suitable for SMB. If you want basic security and more embedded features, go with Sophos XG. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
Dipl. Ing. at a tech services company with 11-50 employees
Reseller
Easy to manage and lots of functionality
Pros and Cons
  • "The user interface is very good. It's already quite simple and easy to use."
  • "Recently, I've had a problem with updating things."

What is our primary use case?

The solution is primarily used as a firewall with all the "next Generation" functionality. We sell this solution to our clients.

What is most valuable?

I prefer the solution to other Firewalls as it is very intuitive to manage.  

The product offers a more complete set of security functionality at one price . It differentiates more in objects to protect like web server protection or email protection.

Troubleshooting is easy with XG Firewall because of clear arrangement of troubleshooting features in GUI.  I like the ease of use.

The Base License includes already VPN, network protection and web protection functionality and you have a wireless controller on top. The data stream analysis and security features are built-in; these are the main features we need these days.

The user interface is very good. It's already quite simple and easy to use.

What needs improvement?

Recently, I've had a problem with updating firmware. Updates should be more stable . The last update I did was not successful and ended in a unusable device. Also the support case i opened for it could have been more effective.

I don't use all of the features and therefore it would be difficult to evaluate if anything is missing.

For how long have I used the solution?

I've been dealing with the solution for around 12 months or so. It's been about a year at this point.

What do I think about the stability of the solution?

From the update side, the last update didn't run successfully and this is not good for us as the customer needs this device to access the internet. If this device is failing and it has no connection to the internet  it is a great problem for the customer.

It may be possible to implement a second device in a fail-over cluster and this would avoid such a problem as then if one device fails in the updating process, the other device could be take over, and so it would be not such a great problem. That said, in this scenario, you have to sell two devices. That would be the best way to ensure stability, however.

What do I think about the scalability of the solution?

The scalability of the solution is limited according to sizing. You buy one device with specific performance parameters, which should be equivalent to the customer's needs, and this device is not able to customize to a higher level. If you need to grow, you must buy another device with higher parameters.

In our case, the customers we work with have small setups. They aren't large organizations. Sophos told us about a sizing guide in the future.

How are customer service and technical support?

We are a reseller and  our first and only support case was not very effective. It should not be used as a guideline.

Which solution did I use previously and why did I switch?

We also resell Cisco products.

How was the initial setup?

The initial setup is not overly complex.  The process is straightforward. A company shouldn't run into problems but need a understanding of the device and the functions.

The deployment process depends on the requirements. A good planning is beneficial.

What's my experience with pricing, setup cost, and licensing?

The pricing is good due to the fact that you get so much functionality from one overall solution. The base license covers all features you need to protect against threats from internet. Setting up the device basically is intuitive and there are a lot of help from internet community.

What other advice do I have?

We are a reseller of both Cisco and Sophos.

We're using the latest version of the solution for our clients.

I'd rate the solution at an nine out of ten. We've  been satisfied with the product, however, there is still more they could do in testing updates.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Owner at Dinamica en Microsistemas de Informatica, S.A. de C.V.
Reseller
Easy to use and deploy with an improved pricing structure in place
Pros and Cons
  • "The initial setup is pretty easy."
  • "They need to allow their solution to integrate with other products and not just other Sophos solutions."

What is our primary use case?

My clients are mostly based in the government. They are my core clients. I install the solution for my clients.

What is most valuable?

The solution is very easy to use. 

Of course, we have the skills, however, it's very easy for us to deploy the solution. That's one of the valuable features. 

They have a communication between the endpoint and the firewall which is very, very useful for security purposes.

Pricing is now pretty good. They changed the pricing structure a few months ago.

The initial setup is pretty easy.

What needs improvement?

The integration could be a bit better. They need to allow their solution to integrate with other products and not just other Sophos solutions.

Sophos has a feature that in my opinion is very limited. They don't have enough VPNs on their models. They have the XG 750, which is a sizeable appliance. On those models, they used to have not enough VPNs. They always were short on that area. 

Pricing used to be very bad, however, they've adjusted their strategy recently. 

The product needs to improve its marketing in Mexico. It's not a well-recognized product in our country.

The solution's technical support is very bad.

There is an overall lack of documentation in relation to features and capabilities. We need these to help explain aspects of the solution to our clients. 

For how long have I used the solution?

I've used the solution since around 2014. I have about six years of experience at this point. It's been a while. I've definitely worked with the product in the last 12 months.

What do I think about the stability of the solution?

The solution is quite stable. There are no bugs and glitches. It doesn't crash and freeze. It's quite reliable. We don't have problems with it.

What do I think about the scalability of the solution?

The solution is very scalable. It is not a problem. Sometimes we have issues when we are trying to do something with a different traditional version of hardware as sometimes the new hardware has more ports. However, if we are talking about scalability in a huge customer, we can do it very easily. 

Mexico is very different than other countries and continents as here, when we say it's a big customer, we are talking about 2,000 to maybe 3,000 users. There aren't too many large-scale operations in the country. However, in general, for our area, we tend to deal with large-scale companies.

For a company that has maybe 1,000 users, Sophos seems to work very well. We have one operation with 10,000 endpoints and it is working quite well.

How are customer service and technical support?

Technical support from Sophos is very bad.

Sometimes we lose a project due to the fact that we need to solve some issues or answer questions. Things that may be technical but also involve the administrative side. I'm talking about licensing and the capabilities of the feature. We need some documentation, something we can show clients. They can better in those cases. They can either help us or supply us with what we need. 

In response time, they are terrible. In the area of technical knowledge, they are getting better, however, they aren't where they need to be. Right now, we are not satisfied with the level of support provided.

How was the initial setup?

The initial setup is not complex. However, here in Mexico, it's very complex to sell the product. The brand is not as well known.

That said, the process is pretty straightforward. 

The deployment times vary. It depends on the end-user and what they need. Sometimes, it's easy as they don't have too many policies. The more policies they have, the longer it takes.

In other cases, clients may have a lot of VPNs. We have to work on those VPNs, and we have to do a lot of routing. However, that depends on the customer. Not all are like that.

For one appliance, you just need one person for deployment and maintenance. If we are working a lot of VPNs, we would have to use more people. We need to involve maybe two or three individuals and re-apply the configuration in that case. 

What about the implementation team?

We handle the installation process ourselves. We do not need the assistance of consultants.

What's my experience with pricing, setup cost, and licensing?

The pricing has recently changed on Sophos. Their licensing and cost structures are much more clear now. It's much better than it was.

Which other solutions did I evaluate?

Clients, in many cases, evaluate for Check Point, Forcepoint, and sometimes Fortinet. Occasionally, they may look at SonicWall, or Palo Alto however, the others are the main big competitors. 

Palo Alto is very expensive as are Check Point and Forcepoint. That's why we sometimes win the projects. We find Fortinet, is very, very hard to beat as they have a lot of market share, have a lot of marketing. Sophos doesn't have that presence, that marketing. Also, when you have to think about prices, Fortinet gives customers everything and it's hard to beat.

The biggest issue I've found with Sophos is the small number of VPNs that we can do compared to a similar appliance with Fortinet or in the same level center. In fact, many other brands offer more VPNs than Sophos.

What other advice do I have?

I'm a Sophos reseller.

We use multiple versions. We have worked with XG 460 and XG 135 and some others -such as XG 230. In those cases, sometimes it has been Rev 1 and in other cases Rev 2 in terms of the hardware versions.

I mostly work with on-premise deployments. The only item I have installed in the cloud is an email solution by Sophos.

I'd recommend the solution to other organizations. Overall, I would rate it at a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
System Integrator at Tecnimex S.r.l.
Real User
Very good at web and application filtering with a great GUI
Pros and Cons
  • "The stability has been excellent."
  • "Technical support could be improved. They aren't as responsive as they could be."

What is our primary use case?

We primarily use the solution as a comprehensive security device.

What is most valuable?

The VPN capabilities are quite good.

The solution is very good at web and application filtering.

It's quite a comprehensive security solution.

The performance the solution offers is excellent. Compared to the older solution, and especially on the cloud, it can reach very good performance. It depends on the licenses, of course. 

The graphical user interface is excellent. 

The intrusion protection module is very useful.

You can easily connect the solution to cloud management.

The stability has been excellent.

What needs improvement?

Technical support could be improved. They aren't as responsive as they could be.

It would be ideal if we could have a more populated and detailed knowledge base. Generally, the new features must be tested before applying them to the production side. I would like to see more case studies, more application notes, and so on.

We would like to see an improvement in mail management. When passing from FG Series to XG Series, some mail features have been lost. We would like to regain them.

For how long have I used the solution?

We've used the solution for many years - before it was even Sophos. Sophos, some years ago, was Astaro AG. Sophos acquired Astaro AG. We have at least ten years of experience with the solution.

What do I think about the stability of the solution?

We've found the stability to be very good. It doesn't crash or freeze. There are no glitches. The performance and reliability are excellent. 

Occasionally, we do have to do a debug, however, that's typical of all firewall solutions.

What do I think about the scalability of the solution?

The scalability of the solution is very good overall. If a company needs to expand it, it can do so.

We have about 200 people using the solution.

How are customer service and technical support?

The reaction times of technical support are slow. They should be more responsive. We're not completely satisfied with the way they handle it.

Which solution did I use previously and why did I switch?

In the past, I've had some experience with SonicWall, Fortinet, and with a Linux solution. However, compared to other solutions, we prefer Sophos.

How was the initial setup?

It's better to be certified to install in a good manner. You need to understand what you are doing. Sophos offers the chance to certify at different levels. There are commercial levels and technical levels.

The time it takes to deploy depends on the complexity of the setup and environment. It can take a few hours or a few days. It can even take a week if the architecture is very advanced.

Generally, you need to be an engineer to handle maintenance. We have three people at our office that can handle implementation and setup as well as maintenance.

What's my experience with pricing, setup cost, and licensing?

You need a license to use the solution. We offer the license as a box license, or we can offer a license like an MSP, as a service provider. We often acquire the licenses and we give them to our customers as an MSP.

What other advice do I have?

We are an authorized partner for Sophos.

We're using the latest version of the solution.

I'd recommend the solution, especially over, for example, Cisco. 

I'd rate the solution ten out often. It's really worked well for us.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
CIO LATAM at i-Track Systems Development, S.A. de C.V.
Reseller
Great cost benefits, reliable, easy to set up, and scalable
Pros and Cons
  • "The most valuable feature of this solution is that the license offers everything."
  • "It is complicated to get the reports if you are not experienced with Sophos."

What is our primary use case?

We implement different security solutions. We also integrate the different environments and secure them, based on the customer's needs.

Our customers are from banking or financial institutions, insurance institutions, telecommunication companies, advocacy companies, construction companies, and retail companies.

What is most valuable?

The most valuable feature of this solution is that the license offers everything. You don't have to purchase a license for the VPN, or the mobile VPN, or for any other features that the firewall works with. That is the best thing about Sophos. 

They include everything on the firewall as a base and if you want other exclusive services or to add more security to your service, you would have to purchase the full license.

To me, the cost benefits are the best.

What needs improvement?

They can improve all indicators, all KPIs, all the scores, the consoles, and the monitors. These are all areas that need improvement.

These areas need to be more clear for the customers. You have to have good experience working with Sophos to know how to get to the forums and to get to the information that you want from the beginning.

It is complicated to get the reports if you are not experienced with Sophos. For example, if you want to get a report on what the firewall is doing, you have to be a very experienced engineer.

For how long have I used the solution?

We have been using Sophos XG for three years.

The version we use is up to the customer and their environment's needs. For example, if the customer has a small infrastructure, we implement a small firewall, which could be an XG 115 or an XG 125.

For larger companies, we implement an XG 450 or XG 500.

What do I think about the stability of the solution?

The stability is very good. Stability is the main reason we use Sophos.

We have no complaints about the reliability, performance, or stability. It's a very strong product.

We are currently building the security architecture and we are trying to build according to the customer's requirements. The plan is for 35% growth in the next three years.

Our clients are usually medium to large-sized businesses. 

We currently have 23 engineers to maintain this solution.

What do I think about the scalability of the solution?

Depending on the firewall that you are using, or that you purchase with the biggest supply end, you can add other cards that can grow with some other services.

How are customer service and technical support?

We provide technical support to the customers. We provide our own SOC to support the security solution and we complement the Sophos support plan.

Their technical support is fair, as well as the forums. Today there are only webinars, but we are trying to keep up with the latest technologies and trends.

We are also trying to keep up on how the hackers work because we are working with different associations of security worldwide that way we know the best way to protect our customers and what we need to sell to our customers.

Which solution did I use previously and why did I switch?

We work with several brands. Sophos is in the top sales.

Previous to Sophos XG, we were working with Sophos and Cyberoam.

How was the initial setup?

The initial setup is straightforward. It's easy, using the wizard.

If you go outside the wizard and you are not an experienced engineer, it could get a little tricky.

Our implementation strategy is to have clear communication with the customer. Implementation is based on 99% of the information that the customer is providing to your other anything else.

It can take five days to deploy.

What's my experience with pricing, setup cost, and licensing?

The license includes most of the features that are necessary, but the basis of the firewall does not include everything, which helps us to continue to sell.

When comparing with Palo Alto and Cisco, Sophos is cheaper.

Which other solutions did I evaluate?

The top three solutions that we sell and that the customers consider are Sophos, Palo Alto, and Cisco.

The main difference is the pricing.

What other advice do I have?

We try to sell some cloud services but in Mexico, customers are not familiar with the cloud services yet. We are starting to grow, but it is very common that customers prefer services on-premises.

We do not only plan for the sales, but we also plan with the customers and their growth, and how we are going to increase their services. We also consider what will be selling to the customers in the next three years. We plan with the customer, as well.

When we sell a firewall, it is not for sale for right now, it's for sale for long-term use. We build long-term relationships with our clients.

My suggestion to others who are interested in using this solution is to try it. The only way to know how well it works is to try it.

Sophos XG is an excellent solution and I would rate it an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Programmer / Analyst at Maridive & Oil Services
Real User
A firewall solution with many good features
Pros and Cons
  • "I like the web filter, application filter, and VBA."
  • "Their updates can be faster and more regular."

What is most valuable?

I like the web filter, application filter, and VBA. There are so many good features. The most powerful thing is clearly the software. I can easily do whatever I want.

What needs improvement?

Their updates can be faster and more regular. Right now, it's updated monthly. When I need to update the firmware, I want it done within weeks, not months. There are also some changes in version 18, like rules, that aren't needed.

What do I think about the stability of the solution?

Sophos XG is a very powerful and stable solution. It's more stable than Cyberoam.

What do I think about the scalability of the solution?

Sophos XG is scalable.

How are customer service and technical support?

Technical support is good and easy to deal with. If I have a problem, I open the ticket, and I call, and the problem's solved automatically by them.

Which solution did I use previously and why did I switch?

We used Cyberoam ten years ago and then transferred to Sophos. We switched because it was the latest technology.

How was the initial setup?

The initial setup was very easy because you can follow the manuals, follow your past experiences, and so on. We also need about three to six people a day to maintain this solution.

What's my experience with pricing, setup cost, and licensing?

At first, I thought the price was very high. But when I read about the machine's features, we decided to go with it. Now I think the price is reasonable.

What other advice do I have?

On a scale from one to ten, I would give Sophos XG a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
ICT/HMIS Supervisor at a healthcare company with 501-1,000 employees
Real User
A stable and seamless solution with good support and useful VPN and filtering features
Pros and Cons
  • "The VPN feature is the most valuable. It has come in handy during this period when people are working from home. The filtering feature is also valuable because you can easily filter the sites that you don't want to visit. You can also set timely surfing quotas."
  • "They made some changes to the firmware update sometime last year, which moved some of the policies from where they were before. Some of the policies, such as NAS policies, were separated, which made it a bit hard for people to trace the policies they had configured."

What is our primary use case?

We use it for VPN and for filtering direct traffic. We are using XG50.

What is most valuable?

The VPN feature is the most valuable. It has come in handy during this period when people are working from home.

The filtering feature is also valuable because you can easily filter the sites that you don't want to visit. You can also set timely surfing quotas.

What needs improvement?

They made some changes to the firmware update sometime last year, which moved some of the policies from where they were before. Some of the policies, such as NAS policies, were separated, which made it a bit hard for people to trace the policies they had configured.

For how long have I used the solution?

I have been using this solution for three years.

What do I think about the stability of the solution?

It has been very stable. We haven't had any outages. It has been seamless.

What do I think about the scalability of the solution?

I am not quite sure about that. In terms of the number of nodes, we have around 200 nodes. All the internet traffic has to go through Sophos XG. In terms of the number of people who handle the support, we have two people.

How are customer service and technical support?

Their technical support is good. Whenever I have contacted them, they have given us support. They have been quite fast.

Which solution did I use previously and why did I switch?

We were using Cyberoam. When they were acquired, we just upgraded to Sophos because, at that time, they were providing the hardware and support to transfer your configs to Sophos.

What about the implementation team?

Its initial setup was done by a contractor. We just maintain it. We have an expert, and we also have access to an IT department.

What's my experience with pricing, setup cost, and licensing?

In terms of price, it is a mid-range product.

What other advice do I have?

I would recommend this solution. I would rate Sophos XG an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Ryan Dominic Momblan - PeerSpot reviewer
System Engineer at Microgenesis Business Systems
Real User
Stable with good web-filtering and the application control
Pros and Cons
  • "We've had good experiences with technical support."
  • "The solution could be improved if it offered more documentation or at least provided more information about the products themselves."

What is our primary use case?

Most of our clients are primarily using the solution for the network protection it offers them.

What is most valuable?

The most valuable aspects of the solution are the web-filtering and the application control.

The solution is stable.

We've had good experiences with technical support.

The product is scalable.

What needs improvement?

The solution could be improved if it offered more documentation or at least provided more information about the products themselves. If there was a virtual assistant of some kind that would help clients familiarize themselves with everything, that would be very helpful.

It would be helpful to get some insights into new features so that we are able to relay information to clients effectively.

For how long have I used the solution?

I've been using the solution technically since 2019, however, I haven't really been able to focus on it too much. Right now, I am refreshing my knowledge on Sophos XG.

What do I think about the stability of the solution?

The solution is very stable. There aren't bugs or glitches. It doesn't crash or freeze. It's very reliable overall.

What do I think about the scalability of the solution?

We have clients from various sized companies, and the solution works well with all of them.

There seems to be pretty good scalability potential, at least up to a point.

How are customer service and technical support?

We've been in touch with technical support and found them to be very accommodating. We are very satisfied with eh level of support they provide to us.

Which solution did I use previously and why did I switch?

While I may have other colleagues on different solutions, my main focus is Sophos at the moment.

How was the initial setup?

When we're talking about the initial setup for the Sophos XG it can either be simple or complex. It will depend mostly on the infrastructure of the client.

Deployment times also vary, according to the complexity.

Typically, the client handles the maintenance process themselves.

What about the implementation team?

We handle the implementation process for our clients.

What's my experience with pricing, setup cost, and licensing?

We have a platinum partnership with Sophos at this time.

I'm more on the technical side. I don't really have any insights into licensing and pricing as it's not an aspect of the solution I directly deal with on a regular basis.

I'd advise those considering any solution to really take the time to study the product and understand different aspects of it. Every solution is different, and therefore it's important to be able to navigate them. Doing some extra research at the outset will ensure you don't purchase the wrong firewall, which can be a waste of time and money.

I would rate the solution at a nine out of ten. We're quite happy with the product so far.

What other advice do I have?

We're using the latest version of the solution at this time.

We're integrators and resellers.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
ICT Manager at a hospitality company with 1,001-5,000 employees
Real User
Easy to use, scalable, and fairly stable, but needs simplified interface and better security
Pros and Cons
  • "We find it easy to use. Its internal configuration is very easy. It is not complicated in terms of use and configuration. It has been fairly stable, and it is also scalable."
  • "They can simplify its interface so that it is mostly drag-and-drop. There was an SQL injection attack on some Sophos devices. They just need to harden their devices a little bit so that they can't be hacked very easily."

What is our primary use case?

We are using it at a gateway level. We are using Sophos XG Series 135. 

What is most valuable?

We find it easy to use. Its internal configuration is very easy. It is not complicated in terms of use and configuration.

It has been fairly stable, and it is also scalable.

What needs improvement?

They can simplify its interface so that it is mostly drag-and-drop. There was an SQL injection attack on some Sophos devices. They just need to harden their devices a little bit so that they can't be hacked very easily.

For how long have I used the solution?

I have been using this solution for three years. 

What do I think about the stability of the solution?

It has been fairly stable.

What do I think about the scalability of the solution?

It is scalable. We had scaled it for the number of users that we have, and it has worked fine for us. We have around 40 users.

How are customer service and technical support?

We rarely contact their technical support. There was a time when our head office contacted their technical support. It was an issue in 2008, and they provided a patch.

Which solution did I use previously and why did I switch?

We used Cisco ASA five or six years ago.

How was the initial setup?

We found it easy to install. Its installation took around one to one and a half hours.

What about the implementation team?

I did it myself. I have had some training on the product. In terms of support, we have just two guys who handle the support. Two people are enough for its deployment and maintenance.

What other advice do I have?

I would recommend this solution. It is a fairly stable and good solution. We will keep on using it.

I would rate Sophos XG a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Owner at supernovatel
Real User
Top 5
A firewall solution with a valuable VPN feature
Pros and Cons
  • "Because of the pandemic, the VPN is the most valuable feature."
  • "I used to work with Fortinet, and sometimes I see that the SD-WAN feature could be better because it's much easier in Fortinet."

What is our primary use case?

We use Sophos XG for a central firewall, with some branches making a VPN, but that's the normal deployment. Some clients use it as a proxy, but most of my clients use it as a gateway. We use Sophos to configure policies, work filters, application filters, and the SSL VPN and IPSec VPNs.

What is most valuable?

Because of the pandemic, the VPN is the most valuable feature. In Bolivia, the clients normally asked for an appliance with a web protection license or network protection and web protection license. These are the most common features demanded by our customers.

Some clients are also using the wireless solution and using XG firewall as a wireless controller. For those clients, this feature is a very important.

What needs improvement?

I used to work with Fortinet, and sometimes I see that the SD-WAN feature could be better because it's much easier in Fortinet. That area could be improved in Sophos XG as it's too complicated right now.

For example, I remember a case where the routers had to be configured by commands. It's not hard, but you have to read and investigate how to do that. The XG firewall works fine, but you have to read, and it takes some time to do it.

Sophos XG could also improve the floating area. I have more features in Fortinet, more visibility of the networking table, and the networking area. But in Sophos, you have to enter the CLA and display it. It'll also help if they offered more toll booths for VPN like Fortinet.

For how long have I used the solution?

I've been working with Sophos XG for around five years.

What do I think about the stability of the solution?

I have no issues with the stability. No reboots are needed, and there hasn't been a problem with that.

What do I think about the scalability of the solution?

The new enterprise models are scalable, and we don't have problems. I think it's fine.

How are customer service and technical support?

I like their technical support. With Cyberoam, I remember the technical support used to work closely with us. They used to configure some features for us and help us resolve problems, but not just by email. They used to work with us and show us how to do it. I think that was nice, but in Sophos, they give us instructions and help us, but by email.

How was the initial setup?

The initial setup and configuration was very easy for us. I think it's easier than the other options in the marketplace. The deployment time is relative. For example, if you're deploying for a client who has another firewall and have to integrate it, it'll take around two or three days. But if it's a new environment, you can deploy the firewall within two hours.

Which other solutions did I evaluate?

Normally, my clients look at Fortinet. Both have similar features, and sometimes Sophos is more expensive, or FortiGate is more expensive. It depends. But normally, I have clients that migrate from Fortinet to Sophos. They are used to working with FortiGate without a problem, but the main difference in our case is the support. Because as a company, SUPERNOVATEL, has more experience with Sophos to help our clients immediately. That makes the difference.

What other advice do I have?

On a scale from one to ten, I would give Sophos XG a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Head Of Network & Technical Support at a financial services firm with 501-1,000 employees
Real User
Top 5
Plenty of features, easy to use and simple install
Pros and Cons
  • "In my experience, the solution was easy to use, has lots of features, and is easy to configure."
  • "There are issues with electricity with this solution."

What is our primary use case?

We use the solution as our HQ main firewall.

What is most valuable?

In my experience, the solution was easy to use, has lots of features, and is easy to configure.

What needs improvement?

There are issues with electricity with this solution.

For how long have I used the solution?

I have been using the solution for approximately five years.

What do I think about the stability of the solution?

I have found the solution to be stable.

What do I think about the scalability of the solution?

The scalability could be better. We have 500 to 1000 users using the solution at my company.

How was the initial setup?

The installation is easy.

What about the implementation team?

The deployment only took an hour for one person to do it.

What's my experience with pricing, setup cost, and licensing?

The hardware is inexpensive but the license is expensive.

What other advice do I have?

I am going to continue using this product and I recommend this product to others.

I rate Sophos XG a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Engineer at Vibs
Real User
Stable, scalable, with a good central dashboard, and good technical support
Pros and Cons
  • "The most valuable feature is the central dashboard"
  • "I would like to see the performance improved."

What is our primary use case?

We are integrators. We integrate solutions for other our client's companies.

What is most valuable?

The most valuable feature is the central dashboard. It provides us with good performance.

What needs improvement?

When you utilize the processors, the device hangs. Many firewalls hang because of the high volume of loads.

If we are using the HP policy and the user policy at the same time, the firewall gets hung and it means that we cannot get clear reports.

We have mitigated the firewall with Palo Alto because Palo Alto is working on multiple environments. 

I would like to see the performance improved.

For how long have I used the solution?

I have been working with Sophos XG for three years.

Currently, we are using the MR4 v18.

What do I think about the stability of the solution?

It's a stable solution.

What do I think about the scalability of the solution?

This product is scalable. I would rate the scalability an eight out of ten.

So far we use this solution for SMB and enterprise companies.

How are customer service and technical support?

Technical support is very good.

Which solution did I use previously and why did I switch?

We are also working with Fortinet FortiGate and Palo Alto Networks NG Firewalls.

Palo Alto is the best product from a compliance point of view, and security. Fortinet is the second and the last is Sophos XG.

How was the initial setup?

I have installed Sophos XG in multiple organizations.

The initial setup is very easy.

It took less than 10 minutes to deploy.

What's my experience with pricing, setup cost, and licensing?

Sophos is very good for small companies because of the cost of the product compared to other solutions.

The price is reasonable.

What other advice do I have?

I prefer Palo Alto Networks NG Firewalls to Sophos. Palo Alto is very good and the customers are happy. The hardware is customizable with multiple firewalls. I think that it is the best.

I would rate Sophos XG an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Systems Administrator Team Leader at a retailer with 1,001-5,000 employees
Real User
Very solid and stable, although there are some ADL bugs that require enhancing
Pros and Cons
  • "This is a very stable solution."
  • "The MTR feature needs enhancing."

What is our primary use case?

This solution is generally used for environment protection, using the ADR and MTL features. I'm a system administrator and team leader and we are customers of Sophos. 

What is most valuable?

It is a stable product because it's on the central cloud so there's no management required. 

What needs improvement?

The MTR feature has to be enhanced. There are some bugs on the ADL which need enhancing. 

For how long have I used the solution?

I've been using this solution for two years. 

What do I think about the stability of the solution?

This is a stable solution.

What do I think about the scalability of the solution?

Because this is a cloud portal, scalability isn't an issue. It's fully managed by the vendor, we just login to the portal and check the logs and check the updates.

Which solution did I use previously and why did I switch?

We have Sophos firewalls and were planning to do a full integration with XG, but unfortunately this did not happen.

How was the initial setup?

The initial setup is carried out on the portal so you need to work on the configuration with the respective partner and have the portal accessing all of the environment. It's a simple setup. We have deployed this solution on around 200 machines.

What's my experience with pricing, setup cost, and licensing?

We pay an annual license.

What other advice do I have?

I would rate this solution a seven out of 10. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Service Delivery Engineer - Network Security Lead at a tech services company with 51-200 employees
Reseller
Simple to use, simple to manage, and simple to administer
Pros and Cons
  • "The most valuable feature is the Intercept X. It is the advanced features that are used for malware detection, and antivirus."
  • "Sophos can definitely improve with the interoperability between solutions."

What is our primary use case?

This firewall is part of the security solution that is implemented in medium-sized enterprises.

We are using it for endpoint and user security for laptops and mobile phones.

What is most valuable?

The most valuable feature is the Intercept X. It is the advanced features that are used for malware detection and antivirus. It's similar to antivirus on steroids.

It's simple to use and has a simple interface. It's generally straightforward and configuration-wise, it's not complex. 

It's a very simple product to use and that's why you find it is used mostly in small to medium-sized enterprises. They don't have the manpower that a large organization can have, in terms of the skilled workforce when it comes to cybersecurity. They just need something that is simple to use, simple to manage, and simple to administer, but effective at the same time. That's the main selling point for Sophos.

What needs improvement?

I have not used their SD-WAN product or the SD-WAN feature, so I don't know how scalable the SD-WAN is. But, I hope just that the SD-WAN is up to par with FortiGate.

The integration is an area that can improve a bit. One of the other solutions that I have used that is highly interoperable is Fortinet. It's easy to integrate with other products. 

Sophos can definitely improve with the interoperability between solutions.

For how long have I used the solution?

I have been using Sophos XG for a year and a half.

We are using the latest version.

What do I think about the stability of the solution?

It is very stable. I've not had any issues with it.

In terms of bugs, I've not had any bugs, or I've not encountered any bugs when deploying Sophos or administering Sophos products. 

What do I think about the scalability of the solution?

In terms of scalability, it's very scalable because they have different sized firewalls for different requirements or different specifications. 

It is also able to do high availability, so it's very scalable.

Currently, in our organization, we have coverage with Sophos Intercept X Endpoint Protection. We have 49 employees. We plan to continue to use this solution.

We are currently subscribed to a three-year product and will be using it for a duration of three years.

How are customer service and technical support?

I have not had any cases where I had to log technical support, but I believe it would be fast enough in case I needed to reach out to them.

Which solution did I use previously and why did I switch?

We are also using Fortinet FortiGate Firewall. 

How was the initial setup?

The initial setup is very simple.

For a normal deployment with basic configuration in a  medium-sized enterprise, it can take a day and a half.

If it's a complex network design then it might be three to four days.

It only requires one person to deploy and maintain this solution.

What about the implementation team?

We used an implementor and an integrator, but usually, I do it by myself.

Which other solutions did I evaluate?

The features in Sophos XG are the same features you would find in Palo Alto or Fortinet.

What other advice do I have?

I just like it the way it is. I wouldn't recommend any changes to it, because what they have is working and it's working very well. It is a product that I definitely recommend to others.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
ICT Manager at toril community cooperative
Real User
A fast, agile, and stable solution that is easy to deploy and manage
Pros and Cons
  • "Orchestration of the firewall is the most valuable feature. It is a fast and agile solution. It is good with protection. It is also very easy to deploy and manage, and its user interface is easy to use."
  • "They can lower its price. It is very expensive. We are looking for a less expensive solution depending on our budget. They can also improve it in terms of firewall protection."

What is most valuable?

Orchestration of the firewall is the most valuable feature. It is a fast and agile solution. It is good with protection. It is also very easy to deploy and manage, and its user interface is easy to use.

What needs improvement?

They can lower its price. It is very expensive. We are looking for a less expensive solution depending on our budget. They can also improve it in terms of firewall protection.

For how long have I used the solution?

I have been using this solution for three years.

What do I think about the stability of the solution?

It is very stable.

What do I think about the scalability of the solution?

It is very agile.

Which solution did I use previously and why did I switch?

We didn't have any other similar solution previously.

How was the initial setup?

It is very easy to deploy.

What's my experience with pricing, setup cost, and licensing?

It is very expensive.

What other advice do I have?

I would rate Sophos XG a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Support Executive at a healthcare company with 51-200 employees
Real User
A stable and economical solution but there's room for a more customizable graphical interface
Pros and Cons
  • "I recommend the solution due to its ease of use and pricing."
  • "An area of improvement would be the reporting as diagnostic graphs take a long time to load and refresh. If there could be an option to show only select graphs, it may speed up the graphics."

What is our primary use case?

Our main use case of this solution is to support internal clients with virus scanning on laptops and on critical processors.


What needs improvement?

An area of improvement would be the reporting as diagnostic graphs take a long time to load and refresh. If there could be an option to show only select graphs, it may speed up the graphics.

Most of the time we don't use the disk usage, memory or CPU graphs. The main graph we watch is the bandwidth usage.

Additionally, their previous update contained many bugs. They need to ensure that, before releasing a new version, there are not so many bugs.

For how long have I used the solution?

I have been using this solution for two years.

What do I think about the stability of the solution?

The solution is stable.

Which solution did I use previously and why did I switch?

We previously used Caveo Systems, but that was about 10 years ago.

How was the initial setup?

The initial setup is very easy. The licensing and setting up of firewall rules takes some time, but the full deployment took about an hour.


What's my experience with pricing, setup cost, and licensing?

The pricing is economical.

What other advice do I have?

I recommend the solution due to its ease of use and pricing.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Network Architect at Virtua Technologies
Real User
Easy to set up, offers central management, the support is good, and it handles endpoint security
Pros and Cons
  • "If you want to install antivirus and firewalling on endpoints, then Sophos is the best option."
  • "The SD-WAN capability is not as good as it is in FortiGate, and is something that should be improved."

What is our primary use case?

We are a solution provider and this is one of the security solutions that we implement for our clients. The primary use for Sophos XG is to secure the internet for an organization. It does a bit of antivirus scanning, application filtering, web filtering, and normal firewalling. Security, obviously.

Some of our clients also have Sophos UAP and access points are also included in Sophos, which is the same with FortiGate.

What is most valuable?

Sophos XG is easy to manage. You've got the cloud logging and you can manage all of your Sophos firewalls from one cloud, the Sophos Central Portal.

The most valuable feature is endpoint security. If you want to install antivirus and firewalling on endpoints, then Sophos is the best option.

What needs improvement?

What I don't like about Sophos is that applying policies can sometimes take longer, and there can even be a bit of a network interruption. With FortiGate, it's just one click and then you go, but with Sophos, sometimes the wheel keeps spinning for several seconds.

The SD-WAN capability is not as good as it is in FortiGate, and is something that should be improved.

For how long have I used the solution?

I have been working with Sophos XG for approximately two and a half years.

What do I think about the stability of the solution?

Stability-wise, it's almost as good as FortiGate.

I've been selling FortiGate for 10 years and Sophos for two and a half years. I think that Sophos is just about on par with FortiGate. We just had a small thing with a client, but I don't know if that's really going to be reason enough. In terms of stability, I think they are quite good. The issue we had was the locks, and it was causing slowness or interruptions, but that was really not an issue. It's a small thing.

What do I think about the scalability of the solution?

Sophos XG is very scalable. You can go from small to large-sized use cases.

How are customer service and technical support?

I think that the technical support is very good, and similar to FortiGate,

I actually dealt directly with a Sophos engineer and I must admit, they've been very fortunate that the guy can help even on the weekends and so forth. I'm very impressed with that.

Which solution did I use previously and why did I switch?

I primarily work with FortiGate, but I am currently dabbling in OPNSense to see if I can learn it. I've also installed Cisco in the past, as well as Sophos.

Although about 80% of our clients ask for FortiGate, some of our clients ask for Sophos instead. For example, there are some banks and commercial institutions that ask for Sophos.

Sophos is better than FortiGate with respect to endpoint protection.

How was the initial setup?

The initial setup is as easy as it is with FortiGate. These products are definitely easier to install than a solution like OPNsense because it is just a hardware appliance.

What's my experience with pricing, setup cost, and licensing?

The price of this solution is mid-range. Obviously, it will never beat OPNsense because that product is available free of charge. Sophos XG is not expensive for a firewall, especially when you compare it with Check Point. Check Point is a really expensive product.

Sophos XG is a bit more expensive than companies like BitDefender and Kaspersky, but their endpoint software is very good.

What other advice do I have?

The suitability of this product depends on the use case. If somebody wants to have full endpoint protection then Sophos is the best choice. If they just want a normal UTM without endpoint software, then FortiGate is slightly better, but only slightly because of the SD-WAN capabilities. 

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Miyoba Sichimwi - PeerSpot reviewer
Information Technology Security Officer at a government with 201-500 employees
Real User
Top 20
Quick to install and configure with proactive support, but updates often cause problems
Pros and Cons
  • "Definitely, its usability is very good, and it's a very robust firewall."
  • "I think that the main area for improvement is the quality assurance of the updates."

What is our primary use case?

This product serves as our current firewall solution, which is a network protection gateway.

What is most valuable?

This is a very simple solution.

It integrates well with Sophos Endpoint Protection, and we use the two of them to form a holistic security perimeter control. 

What needs improvement?

Software updates always come with issues. For example, I just upgraded to the next version, 80.5, and it came with VPN issues. It started dropping my VPN users. So, I had to roll back to before the software update. I think that the main area for improvement is the quality assurance of the updates.

The management console is a little bit rigid.

Scalability can be improved.

I think that it performs a little bit slow when it comes to connectivity, and having the speed increased would be better.

For how long have I used the solution?

We have been using Sophos XG for the past four years.

What do I think about the stability of the solution?

This is a very stable platform. In the four years that we have had it, it's never gone down.

What do I think about the scalability of the solution?

It is not a very scalable product. I would rate the scalability a seven out of ten because where you order it, it comes with prefixed ports. You will only have perhaps two for the WAN, and then maybe four LAN ports, and one console. In this regard, it's not scalable. 

When you buy it, you can't change the port configuration. In order to get more ports, you may have to upgrade to a bigger firewall.

We have about 130 accounts for approximately 80 employees.

How are customer service and technical support?

Technical support for Sophos is very good and they have a big presence in South Africa. It uses something called Sophos Central, where support can fix the problem before you, as the user, actually finds it.

How was the initial setup?

It is a very simple and very quick initial setup and configuration. Because it is a next-generation firewall, it does most of the rule development in the background. You just need to set up the basics and start it up.

What was our ROI?

For what you are buying, it's good value for the money.

What's my experience with pricing, setup cost, and licensing?

Sophos is very good when it comes to pricing. A firewall has a lot of things to look for when you're buying it, including throughput and its features. When we purchased this product, Sophos was the best on the market.

Which other solutions did I evaluate?

In addition to Sophos, we looked at FortiGate, SonicWall, and Cisco. We were looking for a next-generation firewall, and Cisco was out of range because it was too expensive. We settled on Sophos because we already had the endpoint solution in our environment, and the price was very good as well.

What other advice do I have?

Sophos XG is a firewall that I recommend because it's a very simple firewall. It's not complicated, and a LAN expert can just start using it and learn very quickly. Definitely, its usability is very good, and it's a very robust firewall.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior IT Manager at a agriculture with 11-50 employees
Real User
A stable, flexible, and easy-to-use solution that works well and comes with a web management portal that can be accessed from anywhere
Pros and Cons
  • "It is stable, flexible, and easy to use. It has got a web management portal that can be accessed from anywhere."
  • "I would like to have more artificial intelligence in the web monitoring service that comes with it. It should alert us when particular events happen. It has already got some of that. I know that it is more of a service, and Sophos is already looking at it. It is called SIEM."

What is our primary use case?

It can be used as a firewall, SD-WAN enabler, and secure web gateway. You can also use it for unified threat management, email detection, mobile device management, and wireless management. I use it in the cloud and on-premises, and I have its latest version.

What is most valuable?

It is stable, flexible, and easy to use. It has got a web management portal that can be accessed from anywhere.

What needs improvement?

I would like to have more artificial intelligence in the web monitoring service that comes with it. It should alert us when particular events happen. It has already got some of that. I know that it is more of a service, and Sophos is already looking at it. It is called SIEM.

For how long have I used the solution?

I have been using this solution for a few years.

What do I think about the scalability of the solution?

We have roughly 700 users who use this firewall.

How are customer service and technical support?

I have interacted with them a few times. I am very satisfied with their technical support.

Which solution did I use previously and why did I switch?

We were using FortiGate.

How was the initial setup?

It is easy to install. I have done the installation in less than a day.

What about the implementation team?

We did it ourselves. We have two people for its deployment. We have one engineer and one admin.

What's my experience with pricing, setup cost, and licensing?

It is not that expensive compared to the other solutions. It is about the same price range as Fortigate, which we used previously. Licensing is on a yearly basis.

What other advice do I have?

I would recommend this solution. We're very happy with the product. It works very well, and we don't have too many issues.

I would rate Sophos XG a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Security Manager at a financial services firm with 201-500 employees
MSP
Ability to be managed by all users; unfortunately there is no tracking
Pros and Cons
  • "Each user has the ability to manage the solution."
  • "Inability to investigate incidents, there is no tracking."

What is our primary use case?

We are customers of Sophos and I'm the company IT security manager. 

What is most valuable?

I like that each user has the ability to manage the solution. 

What needs improvement?

It's a problem that we are not able to investigate incidents, there is no tracking. Security is also lacking in this product. 

For how long have I used the solution?

I've been using this solution for three years. 

What do I think about the stability of the solution?

Stability is good, no problems. 

What do I think about the scalability of the solution?

Scalability is fine. 

How are customer service and technical support?

Technical support could be improved, it's not great. 

What's my experience with pricing, setup cost, and licensing?

The price is good, it's not an expensive product.

What other advice do I have?

I would not recommend this firewall to others. 

I would rate this product a seven out of 10.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user1429977 - PeerSpot reviewer
Network Security Administrator at a comms service provider with 501-1,000 employees
Real User
Reasonably-priced and straightforward to set up, but instability has caused problems and customer support should be improved
Pros and Cons
  • "The initial setup was straightforward."
  • "The first area that needs to be improved is customer support."

What is our primary use case?

We use the Sophos XG firewall as part of our security solution.

What needs improvement?

The first area that needs to be improved is customer support.

If I'm implementing a connection on the DMZ or WAN, I should be able to dive deep into the implementation, specifying what needs to be implemented or not. For example, I should be able to configure specific details for the DMZ, and not have to follow the templates that they provide.

We have had problems with the stability that affected business operations.

For how long have I used the solution?

We have been using Sophos XG for three years.

What do I think about the stability of the solution?

The issue of stability is the reason that I'm trying to move away from using Sophos as our firewall. There were times where Sophos randomly cut some users off of the internet, which adversely affected business operations. It is important because our business relies on throughput and service, like the uptime of e-commerce servers.

What do I think about the scalability of the solution?

Scalability depends on the specifications during the time of order, prior to first implementing the firewall. With respect to my organization, scalability has been okay. It comes down to the amount of money that is spent.

We have 1,200 users in the company.

How are customer service and technical support?

Customer support needs to be improved. The time they take to resolve issues is too long.

How was the initial setup?

The initial setup was straightforward. It took us less than 30 minutes. Normally, it depends on the size of your organization, so for mine, the installation was less than 15 minutes. By 30 minutes I was finished even with the setup and configuration.

What's my experience with pricing, setup cost, and licensing?

For our company, the price was reasonable.

What other advice do I have?

We are now thinking about incorporating the Fortinet next-generation firewall.

My advice for anybody who is considering Sophos is that a business with a lot of throughput and data traffic should look for another firewall.

I would rate this solution a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Engineer at FormatPC
Reseller
User-friendly and helpful interface with good support that responds quickly
Pros and Cons
  • "The VPN access for users is also a great thing, especially nowadays when working from home."
  • "Having a web portal where you could make requests for the categorization of non-categorized items, would be beneficial."

What is our primary use case?

For the primary use cases, we use SSL VPN access for rolling remote access. We use web filtering and we use the intrusion prevention that comes with network protection.

What is most valuable?

The user interface is very user-friendly and very helpful. 

The VPN access for users is also a great thing, especially nowadays when working from home. 

What needs improvement?

Categorization or uncategorized websites is an area that needs improvement.  

Having a web portal where you could make requests for the categorization of non-categorized items, would be beneficial.

The DLP rules don't cover countries such as Serbia. You cannot make custom rules. That could be added so that we could detect content that is not supposed to leave the company via email, and so that the rules could be customized by the clients.

We only have predefined rules and most of them are not for Serbia or countries from the Region.

For how long have I used the solution?

We have been using Sophos from the time they acquired Astaro, before that it was UTM, then they released the XG firewall.

We are using the latest version.

What do I think about the stability of the solution?

It's a stable solution. We have not experienced any issues.

What do I think about the scalability of the solution?

It's a scalable product. In the office, we have four users in our organization.

How are customer service and technical support?

Our experience with technical support has been positive.

We have support from the local distributor. We have rarely had the need to contact technical support but when we have, we have had quick responses from them.

How was the initial setup?

The initial setup is very straightforward and the implementation takes a relatively short amount of time. The fine-tuning takes a little bit more time but in general, it can be deployed and implemented quickly. 

Also, the upgrades, backups, and recovery are very easy.

What about the implementation team?

We are Sophos partners, we sell them and implement them ourselves.

We only need one engineer to deploy and maintain this solution. If you have a bigger deployment then you need two engineers.

What's my experience with pricing, setup cost, and licensing?

Licensing fees are on a yearly basis.

What other advice do I have?

I can recommend this solution to others who are interested in using it.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
IT Analyst at a financial services firm with 11-50 employees
Real User
Seamless VPN connection that is easy to manage and reasonably priced
Pros and Cons
  • "The most valuable feature is the VPN aspect."
  • "In the Firewall, the Intrusion Prevention System can be improved."

What is most valuable?

The most valuable feature is the VPN aspect. It has been beneficial for my users who work from home. Connectivity and from a security aspect.  The security aspect of this is quite good. It measures up to the standard that I expect.

From a Firewall perspective and then user management, easy to manage and the user experience, profile, are giving me what I am expecting.

During this COVID era, the VPN has really been helpful. We can seamlessly connect to the applications remotely and work from home.

What needs improvement?

In the Firewall, the Intrusion Prevention System can be improved. Now because COVID has come to stay, people tend to work from home, and cybersecurity has been on the high side. 

It can improve more on the security aspect of this so that it can combat any major threat or common bug. I am not saying that the security has become compromised, as it is usually active, but they can improve on it.

Local and technical support can be improved.

When firmware updates are complete, there were issues with connectivity and VPN users. Recently, I stopped updating the firmware because I didn't want to obstruct the connectivity of the staff working remotely at different locations. 

I have stopped doing any updates until the issue can be addressed.

For how long have I used the solution?

I have been using Sophos XG for approximately 12 months.

What's my experience with pricing, setup cost, and licensing?

When you compare with Barracuda, Sophos is quite a bit cheaper. 

With Sophos, you can upgrade on what you need and upgrade as time goes on. I think that it's relatively open, compared to other products.

What other advice do I have?

I would rate this solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Mohamed Abdel Hassanein - PeerSpot reviewer
Managing Director at FORESEC
Reseller
Top 5
Straightforward to set up, stable, and is well-suited to SMB
Pros and Cons
  • "Overall, this is a good product and I would recommend it for small to mid-sized customers."
  • "The number of ports, especially on the entry-level appliances, should be increased."

What is our primary use case?

We are a solution provider and Sophos XG is one of the security products that we implement for our customers. We always provide them with the latest version.

What needs improvement?

The number of ports, especially on the entry-level appliances, should be increased.

The price of adding ports should be reduced to make it more competitive.

The vendor needs to create materials to show the differences between Sophos products and those from other vendors.

Network management needs to be included in the package.

As it is now, it only supports ten multiple users, which is something that should be increased.

For how long have I used the solution?

I have been working with Sophos XG for approximately two years.

What do I think about the stability of the solution?

This solution is stable.

What do I think about the scalability of the solution?

This is a scalable product and we have approximately 150 users.

How are customer service and technical support?

We get our support from the local distributor.

Which solution did I use previously and why did I switch?

Prior to Sophos XG, we used products from Fortinet and Forcepoint. 

The Forcepoint product is doing well. We have a different perimeter firewall for our data center that uses it because we use different vendors for different sites.

How was the initial setup?

This is an on-premises appliance and the installation is straightforward. It can be deployed in less than an hour. However, according to the number of users and the number of ports that will be connected, the design may vary. This makes it difficult to estimate the time required to do a full implementation of the product.

What about the implementation team?

We have four people in charge of maintenance, although they do not work exclusively with Sophos. We have another appliance from another vendor. The entire team, including their manager, is about 10 people.

What's my experience with pricing, setup cost, and licensing?

The price is in the mid-range and it is very good for small to medium-sized businesses. One license opens everything.

What other advice do I have?

Overall, this is a good product and I would recommend it for small to mid-sized customers.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
IT Executive at Hotel Maluri Kuala Lumpur
Real User
User-friendly and easy to explore with many good features
Pros and Cons
  • "The product is very easy to explore. It has a very good layout."
  • "The solution is tied to the US dollar. You need to pay whatever the equivalent is in your own currency, and, if the exchange is bad, it can really add to the cost."

What is most valuable?

Overall, everything about the solution works well. We haven't had any issues at all.

The features on offer are great. It has pretty much everything we need.

The solution is very user-friendly.

The product is very easy to explore. It has a very good layout.

What needs improvement?

I need to do a bit more research on the product. I can't think of any features that are missing.

The solution is tied to the US dollar. You need to pay whatever the equivalent is in your own currency, and, if the exchange is bad, it can really add to the cost.

For how long have I used the solution?

We've been using the solution for three years. It hasn't been an extremely long amount of time.

What do I think about the stability of the solution?

The stability is great. We don't have any issues. I haven't come across bugs or glitches. There isn't crashing or freezing. It's reliable.

How are customer service and technical support?

Technical support is quite good. That said, we really haven't had any issues with the product itself.

Which solution did I use previously and why did I switch?

I used to use Fortinet. That was at a different company, however.

How was the initial setup?

The solution is very straightforward to set up. It's not too complex. Sophos Endpoint is similar in that respect. It's easy to implement.

What's my experience with pricing, setup cost, and licensing?

The pricing is a bit expensive. That is mostly due to the US exchange. If the exchange is bad, it's quite an expensive option for us.

What other advice do I have?

We are Sophos customers. We're just end-users.

We also use Sophos Intercept X and Sophos Endpoint as well.

It's a good option. It's easy to explore and to use. Everything is pretty straightforward, especially if you compare it to other firewalls.

Overall, I would rate it at a nine out of ten. We've been very happy with it in general.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
CTO at Kingsway Hospitals
Real User
The great interface and security are key features
Pros and Cons
  • "Good security and a good interface."
  • "Content filtering could be more effective and efficient."

What is our primary use case?

I'm the CTO of our company and we are customers of Sophos. 

What is most valuable?

I've found that the valuable features are the interface and the security, both are really great. 

What needs improvement?

The security of the solution could be improved by making it more intuitive and it should have a background reputation service for classification of websites for content filtering. It's a service which defines the type of websites enabling me to do my content filtering in a much more effective and efficient way.

They really need to include some kind of a client app for mobiles so that firewalls and all the metrics can be accessed directly on the phone; some kind of administrative application on the phone, maybe on an iOS or Android.

For how long have I used the solution?

I've been using this solution for over four years. 

What do I think about the stability of the solution?

This is a stable solution, it's a nice robust firewall. We love using it. 

What do I think about the scalability of the solution?

The solution is scalable, we have around 700 end users and 10 technical people on staff. 

How are customer service and technical support?

We are satisfied with the technical support but having said that, we didn't need much support because the menus and all the online documentation is self-explanatory. There was no failure so we didn't have to actually log a call with Sophos. 

Which solution did I use previously and why did I switch?

We didn't previously use another solution before implementing Sophos. We chose it by specification and the reputation it has in the market.

How was the initial setup?

The initial setup was a little complex because of the kind of configuration that we were looking at, the way the firewall had to be configured was slightly complex. We carried out the implementation ourselves and it took a maximum two days. 

What other advice do I have?

I would recommend this solution but would suggest that before buying any firewall, it's important to assess your expectations and then match it with the specification. You will not be disappointed if you do this.

I would rate this solution a nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Senior IT Consultant - Sophos Architect at ARENTIA S.A.
Real User
Top 10
A powerful and cost-effective web application firewall solution
Pros and Cons
  • "The web application firewall reverse proxy is very good."
  • "Sophos can improve the debugging of the WAPS function."

What is our primary use case?

We essentially use Sophos XG to protect our customers. Most of our customers use remote VPN connections. They also use the WAF protection for exposed internet WEB servers.

What is most valuable?

The web application firewall or WAF is very useful. Web application firewalls help keep your servers safe from hackers by scanning activity and identifying probes and attacks.
Using the Web Application Firewall (WAF), also known as reverse proxy, Sophos
UTM lets you protect your webservers from attacks and malicious
behavior like cross-site scripting (XSS), SQL injection, directory
traversal, and other potent attacks against your servers.
You can define external addresses (virtual webservers) which should be
translated into the "real" machines in place of using the DNAT rule(s).
From there, servers can be protected using a variety of patterns and
detection methods.

This function has been completely re-developed in XG, relatively of the UTM-9 version, and it works fine. I protect many internet web servers (IIS) for my customers with this function, due to of a lot of attempted attacks. It's a very useful and relatively simple to implement in Sophos XG.

Obviously, like all security systems, it is not a "fire and forget" configuration. It is necessary to properly analyze the system to be protected, create an appropriate policy and monitor its behavior once activated.

https://support.sophos.com/sup...

What needs improvement?

I think Sophos XG can improve some annex features. Like in DHCP, we can't make IP reservations in the range. We must reserve out of the range, which is not good. It will not be the same as the DHCP function in a Windows Server. We can't make an IP reservation in the range of the DHCP in the Sophos.

Better in the next release? I hope...

Sophos can also improve the debugging of the WAF function and provide a better resolution in the log, in the attached WEB log. The initial error doesn't appear. You must tail the console log to find the source pattern, cause of the error.

For how long have I used the solution?

I have been using Sophos XG for about tree years.

What do I think about the stability of the solution?

Sophos XG is stable. I don't encounter problems that are typical with broken systems. But bugs in the system exists. Last example, I discovered a bug is in the asymmetric routing implementation. In a specific network configuration, asymmetric routing, with sub-net 25 doesn't work, but mask 24 and mask 26 works!!

But this is just a bug, and Sophos' support is very good to correct quickly, ASAP.

I only had a break function once because of the appliance BIOS. The Sophos support send me a new BIOS very quickly, and the problem was resolved.

How are customer service and technical support?

I have a lot of issues with Sophos technical support. I still have some pending issues that need to be resolved. It's very odd in the beginning because your first contact is with the sub-part of another sub-part of Sophos based in India or Pakistan. It's very odd to have a quick connection with the second level or third level engineer at Sophos in UK.

I have personal contact with some security managers and the sub-part manager of Sophos support. When they don't resolve a problem quickly, I send an email, or I call my contacts Sophos UK, and it happens! They have good reactivity.

Which solution did I use previously and why did I switch?

We start with Sophos UTM-9, the old version of Sophos firewalls, and then we switched to the XG.

How was the initial setup?

The initial setup of the last version of Sophos XG is good. The initialization is very simple, but you must prepare it. You need an Sophos customer account , on the web cell, to declare easy a firewall.

It'll ask for an account, and you can create it in the interface, but it's better to prepare it before in the Sophos site, to have the account ready, for the first initialization of the firewall.

The deployment time depends on the system's complexity, the number of ISPs, the number of sub-nets, WAF functions and VPNs. 

It's normally very easy for a little company. A retail company with 20-30 computer-users, and a simple connection to the internet, it'll take about four to six-hours to deploy. If you need to fine-tune it, maybe two hours more. So like eight hours or a day to deploy.

What's my experience with pricing, setup cost, and licensing?

Sophos XG isn't expensive compared to Check Point. Sure, Check Point is the Rolls-Royce of firewalls: It's great, it's fun, technically good tunned, but it's very expensive. 

But the specs and technical side of Sophos XG are close to Check Point, and the price is lower. It's better for our customers. I can do the same complex configurations with Sophos XG that I used to do on Check Point firewalls.

Which other solutions did I evaluate?

The main difference between Sophos XG and Check Point is keylogging and working with clouds. Both FortiGate and Watchguard doesn't have  in log packet analyzer to do so deeply. 

For me personally, Check Point firewall is the best firewall, because the log console is the power key of the firewalls. But Sophos XG is the main challenger of Check Point, I think. You can open the debugging packet analyzer, like a Wireshark, directly in the WEB log console. This function is a powerful tool and must be discovered, because it's very useful for quick debugging.

If I had to rank them, it's Check Point first, second, Sophos XG, and in third with FortiGate and Watchguard. We chose Sophos XG because it's much cheaper than Check Point.

What other advice do I have?

I think it's very important to choose the right appliance first. Implementing a lot of things like VPN, IPS strong protection and WAF functions will stress more the appliance CPU. It depend also with the number of connections and number of users too.

Sophos XG is a lot of fun because you can change the appliance model without changing the configuration. You can back-up the configuration of the old appliance and import into the new appliance without spending hour for migration. It's powerful, and the new system is quickly operational.

Another key is VPN LAN to LAN in SSL, allowing connections to be set up much faster. Is this the end of the old IPSEC protocol? No, but it is a function which increases the versatility of the Sophos XG firewall.

Last, but not least, the virtual appliance works perfectly, in private or public clouds. Very simple to implement, work perfectly.

On a scale from one to ten, I would give Sophos XG a nine. 

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer: ARENTIA S.A. - Sophos Gold Partner Av. Francisco Sá Carneiro 380 2415-376 Leiria - Portugal
PeerSpot user
VP of Operations at a manufacturing company with 51-200 employees
Real User
Stable, easy to setup the rules, versatile, and good support
Pros and Cons
  • "The most valuable feature of this solution is the flexibility of it, it's pretty versatile."
  • "The UI needs improvement because it can be a little weird at times."

What is our primary use case?

The primary use case of this solution is as the main company firewall.

What is most valuable?

The most valuable feature of this solution is the flexibility of it, it's pretty versatile.

Also, the firewall aspect in terms of setting up rules. They worked pretty well.

What needs improvement?

The UI needs improvement because it can be a little weird at times.

For how long have I used the solution?

I have used Sophos XG in the last twelve months.

What do I think about the stability of the solution?

This solution is stable. We haven't had any real issues.

What do I think about the scalability of the solution?

I don't know if this solution is scalable. We haven't explored this area yet.

As we grow, we plan to increase usage.

How are customer service and technical support?

Technical support is good.

How was the initial setup?

Initially, the setup was a bit complex.

It was complex because we were coming off of a different setup. It was just getting used to the software, but it's not too bad.

We require one and a half staff members for the deployment and the maintenance. They seem to do a pretty good job of updating it and keeping it current.

What about the implementation team?

We implemented ourselves. We did not use a vendor or integrator.

What was our ROI?

We're military contractors, and the cybersecurity compliance aspect of it has been the most helpful.

We know how the networks operate from our end, even though we are relatively green. We don't what we are comparing it to.

What's my experience with pricing, setup cost, and licensing?

We prepaid in advance to get the max discount.

What other advice do I have?

I would rate Sophos XG an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Samir Shah - PeerSpot reviewer
CEO at Infinity Access Technologies Pvt Ltd
Real User
Top 5
Stable product with easy setup well recommended, customer support and fiber options on smaller models could be improved
Pros and Cons
  • "The solution was able to be integrated well with exciting hardware and software and in multiple business sectors."
  • "They should include fiber ports on smaller product models and the tools should be improved for scalability."

What is our primary use case?

We were able to integrate the solution using existing infrastructure installed, such as different firewalls and security software. We have integrated the solution in multiple sectors, for example, the education and banking sectors. 

How has it helped my organization?

UTM appliances have generally improved organization networks and given away to multiple link management, identity management, and easy firewall options. SOPHOS has a better GUI and dashboard which can be easily understood and managed in an organization.

What is most valuable?

The solution was able to be integrated well with exciting hardware and software and in multiple business sectors.

What needs improvement?

With the proliferation of fiber connectivity becoming available at our homes, consumers should not have to go and buy another module for fiber to ethernet converters or another device to get the fiber options. I understand all UTM models should have direct SFP ports available so that FFTH is directly terminated to UTM for better management and uptime. 

For how long have I used the solution?

I have been using the solution for the past five years.

What do I think about the stability of the solution?

I have found it to be a stable product.

What do I think about the scalability of the solution?

I can say it is more stable rather than scalable. I do not think they have the ability for scalability with the options currently included esp in SMB segment. However, if they did have better options then I believe the product would have better scalability.

Some of our clients have been enterprise and SMB customers. Overall the range of our clients has been between medium and enterprise clients.

How are customer service and technical support?

The customer support is not that good. We found the support to be extremely slow in response.

I rate Sophos XG support a three out of ten.

Which solution did I use previously and why did I switch?

We have used other products as well and we understand those products work well which has better and local support. In addition, it depends on the company's focus. SOPHOS has focused on small to enterprise customers but support needs improvement to be in the market. SOPHOS channel partnership program needs also improvement and commitment so that System Integrators and partners are able to pitch the products well in the market. 

How was the initial setup?

Setup is good and the integration is very easy. The technology creates several good products.

What about the implementation team?

We do the deployment and implementation of the solutions.

What was our ROI?

They should include fiber SFP ports on smaller product models as well and the tools should be improved for scalability.

What other advice do I have?

I can definitely recommend the product because it is good. There is no doubt.

I rate Sophos XG a 6 out of 10.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer: Channel Partner and Consultant to various Customers.
PeerSpot user
Technical Department Manager at Direcbusiness Technologies, Inc.
Real User
Has good VPN features and capabilities
Pros and Cons
  • "We get good usage out of the features. It has enabled us to gain popularity. It has great features."
  • "The VPN features and its capabilities are great."
  • "We had a difficult time assigning IP addresses to specific MAC addresses."

What is our primary use case?

We use it for monitoring our web access, providing authentication and for security purposes.

What is most valuable?

We get good usage out of the VPN features and its capability; it is a great feature.

What needs improvement?

In terms of improvement, one of the features we are having a hard time getting a hang of is MAC addressing, like when we assign IP addresses to a specific MAC address. That is something that can be improved. For the next release, I think, it should have better feature integration.

For how long have I used the solution?

I have been using Sophos XG for seven years. 

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

The solution is scalable. We use the product for around 70 to 100 users.

How are customer service and technical support?

The support that we used was great.

How was the initial setup?

The initial setup was pretty straightforward. The setup took around one to two weeks. 

What about the implementation team?

We did all of the deployment by ourselves and we use one person for maintenance.

What was our ROI?

I think, for the XG, I think the MAC addressing. We were having a very hard time assigning MAC addresses with specific IP.

Which other solutions did I evaluate?

We haven't chosen any other product, besides Sophos.

What other advice do I have?

I would rate Sophos XG an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Firewall Engineer at a marketing services firm with 1-10 employees
MSP
Top 5
Offers good security for SMBs
Pros and Cons
  • "As a security solution, it's a very good security solution."
  • "They should improve the hardware. If they can do that, it will be a very good product."

What is our primary use case?

I use it for one of our universities in Palestine. It's an Arabic university and there were about more than 10,000 students. So, our user base ranges from 1 to 10,000. I use it as the main firewall. I use it for High Availability (HA). That's the main use case why we use Sophos XG. We do intend to keep using it.

What is most valuable?

As a security solution, it's a very good security solution.

What needs improvement?

Some features are not available on the graphical interface. So you need to return to the command line to solve some issues that are faced by the customer. I used it for enterprise networks, I decided that it is not very good for enterprise networks. There is some issue with its hardware. I have faced two problems and that were resolved by Sophos earlier. They changed the appliance. In other products, I have not seen such problems in the hardware. So I think that the hardware is not heavy duty. You can say it's not heavy duty like other vendors. The performance is not as it says on the datasheet. They should improve the hardware. If they can do that, it would be a very good product.

For how long have I used the solution?

I am using the appliance from XG 110. We use versions 105 TO 370. I use more than one product for small to medium size businesses. We also use Intercept X firewalls. We deploy Sophos XG on-premise. 

What do I think about the scalability of the solution?

It is scalable for some things. It can have an extendable host. The appliance can be customized for more than one connection point. You can put it in the same fibre and DSL connection.

How are customer service and technical support?

They have proper support in the technical point of view, and their English language is not clear. You know that they are not native English speakers. That's one of the things that I faced. But they have very good knowledge.

How was the initial setup?

The installation of Sophos is very easy and straightforward. 

What's my experience with pricing, setup cost, and licensing?

It's not very expensive. 

What other advice do I have?

I recommend it for small to medium businesses, not for enterprise businesses. I'll rate it 8 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
IT Support Executive at a healthcare company with 51-200 employees
Real User
Simple, stable and secure with regular timely updates
Pros and Cons
  • "The simplicity and timely updates."
  • "The interface could be simplified and diagnostic system graphs improved."

What is our primary use case?

Our primary use case is as a firewall, failover management of the internet lines. We have over 50 people using the product on 200 devices and we use it on a daily basis. I'm an IT support executive and we're a customer of Sophos. 

How has it helped my organization?

We are using sophos XG as the firewall for our offices, so any connections going outside of the office go through it. We are also using VPN clients and especially during the lockdown, it was very helpful.

What is most valuable?

I like the simplicity of the solution and the timely updates. It works well. 

What needs improvement?

The interface could be improved by simplifying it and making it much smarter. I would also like to see an improvement in the diagnostic system graphs. They could be modified to provide individual graphs. The present page has all graphs in a single page and it slows things down and takes more time to refresh and load. 

Additional features they could consider including in any update would be symbols and tools. They could also include URL groups and all Office updates, the regular things that people do on a daily basis. 

For how long have I used the solution?

I've been using this solution for the past year and a half. 

What do I think about the stability of the solution?

This is a stable solution. 

What do I think about the scalability of the solution?

We haven't yet tried scaling, that will take another six months. I'll be in a better position to answer then. 

How are customer service and technical support?

The technical support is fine overall.

How was the initial setup?

I've now configured three times and although it gets easier, deployment is a little complex. We had some issues with the company, unrelated to the product, more to do with the licensing procedures in India which could be simplified. Deployment only took about half an hour and the solution doesn't require any maintenance. 

What's my experience with pricing, setup cost, and licensing?

Licensing costs are generally set for three years. 

Which other solutions did I evaluate?

PaloAlto, FirtiGate

What other advice do I have?

Before installing this product it's worth taking some lessons from the website which also provides some support. It's almost better than the technical support which is offline. If you have a good vendor with hands-on experience that's also helpful for first time deployment. After you've implemented once, it's easier the second time. 

I would rate this solution an eight out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Team Lead at a manufacturing company with 5,001-10,000 employees
Real User
It is user friendly and reliable, but it needs granular control over the traffic
Pros and Cons
  • "It is very user friendly and easy to manage from the administrative point of view. It is good, reliable, and easy to implement."
  • "It is a very basic and entry-level firewall. It doesn't give very granular control over the traffic. It should have more granular control over the traffic. This feature should be there similar to Palo Alto and Cisco. It should have such advanced features."

What is most valuable?

It is very user friendly and easy to manage from the administrative point of view. It is good, reliable, and easy to implement.

What needs improvement?

It is a very basic and entry-level firewall. It doesn't give very granular control over the traffic. It should have more granular control over the traffic. This feature should be there similar to Palo Alto and Cisco. It should have such advanced features.

For how long have I used the solution?

I have been using Sophos XG for the last two years. We are using the latest version.

What do I think about the stability of the solution?

Its stability and reliability are fine.

What do I think about the scalability of the solution?

If you want to have multiple firewall rules, it has this type of scalability. When I compare it with some other products, such as Palo Alto, I can't find similar scalability in Sophos XG. In Palo Alto, we can have rules based on applications or app IDs, and we can create multiple rules for a single ID. We can create a single user or single IP, but such options are not there in Sophos XG. Granular level scalability should be there in Sophos, and they should do better.

How are customer service and technical support?

I appreciate their support. Their support is good.

Which solution did I use previously and why did I switch?

I also use Palo Alto. Palo Alto provides application IDs, which is a very powerful feature. Sophos XG is a very normal next-generation firewall with URL filtering, application filtering, and all such features. It is not something extraordinary. It is a very normal next-generation firewall. 

How was the initial setup?

The initial setup is straightforward. It is a single day task to do the initial configuration and move the traffic over there. The firewall hardening, of course, will take some time depending upon the traffic, but the initial setup is a single day task.

What other advice do I have?

It is a normal firewall. All the basic features are there. However, it is not as advanced as some of the other solutions, such as Palo Alto. As we have more security threats, we need more granular control, but these features are not available in Sophos XG.

I would rate Sophos XG a five out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Manager at a manufacturing company with 201-500 employees
Real User
User authentication rules are helpful, but the URL filtering is not good, and it suffers from instability
Pros and Cons
  • "The user authentication rules are very useful."
  • "Sophos needs improvements made to the console, such as host entry or defining rules directly from it."

What is our primary use case?

We use the Sophos XG firewall as part of our network security solution.

What is most valuable?

The user authentication rules are very useful.

What needs improvement?

Sophos needs improvements made to the console, such as host entry or defining rules directly from it.

For how long have I used the solution?

We have been using Sophos XG for the past five years.

What do I think about the stability of the solution?

I do not feel that this is a stable product. URL filtering is not good.

How are customer service and technical support?

I have not had any experience with technical support.

How was the initial setup?

The initial setup is straightforward. It took a week to deploy.

What other advice do I have?

This is not a product that I can recommend to anybody who wants to implement a firewall.

I would rate this solution a four out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Networking Engineer at a comms service provider with 1,001-5,000 employees
Real User
Easy to set up, good support, and the display of bandwidth usage statistics is interesting. There is a drill down menu showing bandwidth usage for each application. Easy to configure e-mail rules.
Pros and Cons
  • "What we found valuable is the way they deal with emails, as well as the way the bandwidth usage is shown."
  • "We are having challenges when using Zoom with Sophos XG deployed."

What is our primary use case?

Right now, we are using this product as a perimeter firewall just to deal with emails and to protect servers, as well as other equipment that is on the network.

What is most valuable?

What we found valuable is the way they deal with emails, as well as the way the bandwidth usage is shown. I find this information to be very interesting.

What needs improvement?

We are having challenges with social media because ever since this issue of COVID-19 came into existence, the idea of using online discussions has become relevant. Before this, they were not made the priority because they were not considered to be important. Now, we've discovered that we need to use a lot of these online applications.

We are having challenges when using Zoom with Sophos XG deployed. Our wireless network is not stable through the connection. More work needs to be done there, since the FW is doubling up as a wireless controller.

I would like to see improvements made to the display and visibility. I'm also using Sophos XG firewall as our wireless controller, but as it is now, I can't see my access points on the firewall. My wish is to see the Wireless network and reports also on this firewall cum- controller. 

For how long have I used the solution?

We have been using Sophos XG for almost three years.

What do I think about the stability of the solution?

Sophos XG is stable and we have no problems with it.

What do I think about the scalability of the solution?

I think there is a limitation on the issue of scalability, and it is related to the interfaces that we bought. Right now, all of the employees are using it. The traffic that passes through it covers close to 2,000 users.

For us, our bandwidth is growing so we may have to scale further, in terms of the hardware networking components.

How are customer service and technical support?

We are constantly in touch with the distributor in Zimbabwe and they are excellent.

Which solution did I use previously and why did I switch?

Prior to Sophos XG, we were using Cyberoam for our firewall. We switched because Cyberoam was acquired by Sophos.

How was the initial setup?

The initial setup is very simple. It takes perhaps an hour to complete, which included importing rules from Cyberoam.

What about the implementation team?

We completed some certifications for using this product, but for the implementation, we were assisted by IDSS. In some instances, we are doing the maintenance on our own. When we have a challenge, on a case-by-case basis, we might contact the vendor and may require them to come in and assist.

What's my experience with pricing, setup cost, and licensing?

The issue of a recurring license is a hassle because every year, we have to subscribe. It causes us problems in our organization.

What other advice do I have?

We are expanding and setting up a new data center, and I want to put a new firewall in. We have an interest in diversifying, in terms of vendors, so that we do not create a single point of failure in case one product fails. Ideally, we want to have different products.

This is a product that I can recommend for anybody who is looking for a firewall.

I would rate this solution a eight point six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Director, Middle East, East India & SAARC at DMX Technologies
Real User
Top 5Leaderboard
Good support, easy to set up, and the VPN helps ensure secure connections for people working remotely
Pros and Cons
  • "The feature that we find most valuable is the VPN, which ensures that people working remotely have a secure connection."
  • "We feel that the GUI can be improved a bit because it has a lot of information and looks a bit outdated."

What is our primary use case?

We are using this product as the firewall for our head office, so any connections going outside of the office go through it. We are also using VPN clients and especially during the lockdown, it was very helpful.

What is most valuable?

The feature that we find most valuable is the VPN, which ensures that people working remotely have a secure connection.

The email security and other security-related features are useful.

What needs improvement?

We feel that the GUI can be improved a bit because it has a lot of information and looks a bit outdated.

Nowadays, you hear a lot about next-generation firewalls, so some additional features can be added from an EI perspective. Products like FortiGate, for example, have a lot of features apart from the basic firewall. 

We would like to see integration with existing IPAM and IDAM products.

In the future, I would like to see new kinds of automations, as well as the inclusion of artificial intelligence-related features. A lot of other firewalls already have these now.

For how long have I used the solution?

I have been using Sophos XG for approximately three years.

What do I think about the stability of the solution?

We have not had many issues, perhaps two or three of them, when using Sophos XG.

What do I think about the scalability of the solution?

Scalability-wise, they have different models. With the requirements that we have, this firewall did a good job. It's still doing a good job in terms of performance. For a larger enterprise with a higher number of users, they can recommend other models.

Currently, we have approximately 100 users.

How are customer service and technical support?

We have received good support. For the small number of issues that we have had, we received help from IT. This included assistance with configuring some additional policies. Whenever we reached out to them, they were very prompt in terms of responding to us.

Which solution did I use previously and why did I switch?

Prior to Sophos XG, we were using a firewall by Palo Alto. The major reason we began looking for a different one was that the support was not very good. The firewall was pretty decent but whenever we wanted some help, it was a bit difficult to reach out to them. To summarize, it was not very prompt.

How was the initial setup?

The initial setup was simple. Within one to two hours, we were done. This was not just the installation, but the complete configuration.

What about the implementation team?

We performed the deployment with the Sophos team guiding us over the phone. It was not complex. There was one person from Sophos who was coordinating it, and it was done by our internal IT manager.

What other advice do I have?

For the most part, I can say that we plan to continue using this product. However, we would like to see if they have come up with new models and what additional features have they been incorporating. With cybersecurity, I know there have been a lot of threats of late, so we would like to see some new technologies or new features being incorporated.

This is a product that I can recommend. My advice for anybody who is implementing it is to first try to understand what the major use cases are. People need to know that there are quite a few options, such as Fortinet, and all of them have different advantages. Sophos fits perfectly for a smaller group of users, with perhaps between a hundred and two hundred people. For larger enterprises, I recommend that they implement Fortinet or Check Point.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network & System Administrator at a tech services company with 201-500 employees
Real User
Easy to set up, monitor, and block traffic, but the stability could be better
Pros and Cons
  • "The most valuable features are the central management, the user VPN, and communications."
  • "I need to open the email to see what it contains and the value of it before I know whether to access it or not."

What is our primary use case?

We are using this product to monitor traffic, payments, and VPN access to our branches. Some are using VPN with hooks, Sophos XG 210, and the main one they are using in the data center is Sophos XG 310.

What is most valuable?

The most valuable features are the central management, the user VPN, and communications.

You can monitor and block traffic.

What needs improvement?

In regards to email as an example, if you experience any malware, it is contained in the container but doesn't give you any information about the email, or what is contained in the email. You only have the option to reject it or to release it.

I need to open the email to see what it contains and the value of it before I know whether to access it or not.

Stability needs improvements.

For how long have I used the solution?

We started with Sophos SG UTM 9, then we upgraded to XG. We have been using the latest version of XG for two years.

What do I think about the stability of the solution?

The stability could be better.

What do I think about the scalability of the solution?

It's scalable and good for small businesses.

We have approximately 120 users.

How are customer service and technical support?

I have contacted technical support three to five times per year.

It's good, but I don't have many questions to ask.

Which solution did I use previously and why did I switch?

Previously, I was using Sophos SG. We were not using any other software from any other vendor. We have only dealt with Sophos.

How was the initial setup?

The initial setup was simple. It was not complicated.

If you are familiar with the technology, the implementation will not be difficult.

It also depends on the business needs.

From testing and switching from SG to XG, it took approximately one week to deploy.

What about the implementation team?

We had help from the vendor. The maintenance and the VPN connection is done in-house.

What's my experience with pricing, setup cost, and licensing?

It is not expensive, it's a reasonable price.

There are some additional fees for additional tools.

What other advice do I have?

I can recommend Sophos XG to others who are interested in using this solution.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Chef IT at a healthcare company with 51-200 employees
Real User
Stable, with an intuitive and user-friendly dashboard
Pros and Cons
  • "This solution does everything and anything a firewall can do."
  • "There is an area that is very specific to our setup, where working tools you cannot easily establish a VPN between two internal networks."

What is our primary use case?

This solution does everything and anything a firewall can do.

What is most valuable?

I am tempted to say that all of the features are valuable. 

When you choose a firewall you have to make a strategic decision, much more than a tactical one. We decided that everything we use within it, goes through and it's got protection.

The dashboard is intuitive and user-friendly.

What needs improvement?

Training on the devices is an area that needs improvement. Their training mechanisms are not perfect, and this is where you lose a good appreciation of the product.

The documentation for implementation is not good. For example, when you look up the details on a firewall rule to validate it, the details are not there.

If you click on the help file, they say a zone is an area where you can define specific logical network areas. This is where they stop, with nothing more. If you want to go further into the concept of it, which you know there is, you have nothing. Then you have to revert to the internet and go onto newsgroups to try to see if anybody has had your type of experience. Then you find someone, they explain it to you then say, "Oh, it only makes sense". So, then when you want to implement this, it's much easier at that time. So, that's the best-case scenario that I can explain.

There is an area that is very specific to our setup, where working tools you cannot easily establish a VPN between two internal networks.

When you want to establish a VPN with different wizards, they assume that you're always going through your internet link. 

If you want to create, with the zero-trust concept, which is where you don't trust anybody or any device, you want to make sure that everything on your network is segmented and everything is relative, depending on its flexibility, behind its firewall or a firewall segment. At some points, you might want to establish VPNs between certain network segments. 

Since you cannot establish VPN tunnels from the Sophos interfaces, plus if you are doing something that's going through the internet, then you lose flexibility. 

Currently, let's say we have a factory V-LAN and you don't want anybody within the factory V-LAN to be able to connect to another unless it is to a specific V-LAN, and you want to use VPN technology, you can't do it because you can't establish the connection again between two internal interfaces.

For how long have I used the solution?

I have been working with Sophos XG for six years.

What do I think about the stability of the solution?

It's a stable product.

What do I think about the scalability of the solution?

In regards to scalability, it's difficult to ascertain at this time because we haven't scaled it necessarily. 

The use cases that we have are very particular, and we're not in a mode of having scaled it yet. We have approximately 100 users in our organization who are using  Sophos XG.

How are customer service and technical support?

Their support, we have a mixed review of it. It's good, but where it's bad, is because they're an international company that relies on many different continents to be able to get the support at different levels.

When we get into the people that are from India, that's where the support becomes not as efficient as we would want it to be. They have different rules of operating under and they don't show themselves to be flexible. Whereas where I am, currently I'm in Canada. When I speak to the support people within Canada, they're much more flexible when it comes to trying to follow us up on what we're trying to do and get the thing working. They're more flexible.

How was the initial setup?

It was a combination of 75 percent straightforward and 25 percent complicated.

What's my experience with pricing, setup cost, and licensing?

It's approximately $6,000 for each device. We have three devices and it was somewhere around $18,000.

What other advice do I have?

I would recommend Sophos XG to others who are interested in using it.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Information Systems Infrastructure Manager at a comms service provider with 1,001-5,000 employees
Reseller
Local support and good training, but the wireless controller and scalability can be better
Pros and Cons
  • "I like the firewall, inbound, and outbound modules the most. The VPN feature also works well. It is very easy to configure rules in Sophos XG. We have got local service here in Zimbabwe from Sophos, which is something that I like a lot. We have got good local support, and they come on-site when we have any challenges. Sophos provides a lot of good training all around Zimbabwe. They are quite dominant here, similar to other solutions like Fortinet or WatchGuard."
  • "When you are using it as a controller for the wireless access points, it doesn't perform well. It is not suitable for the public cloud. It is more suitable for enterprise data. It is not really the equipment for cloud data centers. I am looking for a data center firewall."

What is our primary use case?

I am using it for unified management.

What is most valuable?

I like the firewall, inbound, and outbound modules the most. The VPN feature also works well. It is very easy to configure rules in Sophos XG.

We have got local service here in Zimbabwe from Sophos, which is something that I like a lot. We have got good local support, and they come on-site when we have any challenges.

Sophos provides a lot of good training all around Zimbabwe. They are quite dominant here, similar to other solutions like Fortinet or WatchGuard.

What needs improvement?

When you are using it as a controller for the wireless access points, it doesn't perform well.

It is not suitable for the public cloud. It is more suitable for enterprise data. It is not really the equipment for cloud data centers. I am looking for a data center firewall.

For how long have I used the solution?

I have been using Sophos XG for more than five years. I started with Cyberoam, which was bought by Sophos.

What do I think about the stability of the solution?

It is stable. I have managed to secure my network. It has been good so far.

What do I think about the scalability of the solution?

It is not so scalable. If you want to upgrade, you have to buy another appliance. I don't see so much scalability. You can only change a port from 1 gigabit to 10 gigabits. There are other solutions like Fortinet that are more scalable.

How are customer service and technical support?

Their support is good. We get local support from them.

How was the initial setup?

The initial setup is straightforward. The deployment took two days.

What's my experience with pricing, setup cost, and licensing?

The pricing is flexible. Sophos looks at a country's economy and offers flexible pricing. This is how they have managed to penetrate the market.

What other advice do I have?

I would definitely recommend it. It has good support and training.

I would rate Sophos XG a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
System Administrator Server and Networks at a manufacturing company with 201-500 employees
Real User
Good filtering capability, but the interface is slow and it is difficult for beginners to understand
Pros and Cons
  • "The most valuable feature is web filtering."
  • "The reaction time of the GUI is terrible when compared to other manufacturers."

What is our primary use case?

We use this product to protect all of the connections to our sites and for web filtering.

What is most valuable?

The most valuable feature is web filtering.

What needs improvement?

The behavior with the zones was a little bit tricky to understand and the beginning of the project.

Sophos XG is difficult to manage and it is difficult to understand when you first begin.

The reaction time of the GUI is terrible when compared to other manufacturers. 

For how long have I used the solution?

We have been using Sophos XG for about a year and a half.

What do I think about the stability of the solution?

This is a stable product, although the web GUI is slow. We plan to use it for another couple of years.

What do I think about the scalability of the solution?

This is a small site, and we have 15 users.

How was the initial setup?

The initial setup for Sophos XG was not straightforward. We already had experience with Sophos UTM, but they are completely different systems. The deployment took us one week to complete.

What about the implementation team?

We deployed this solution in-house.

Which other solutions did I evaluate?

I now have a proof of concept with a FortiGate firewall and we are trying some test cases on it.

What other advice do I have?

For now, this is not a product that I can recommend.

I would rate this solution a six out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user1274955 - PeerSpot reviewer
Senior Director of IT Operations at a tech services company with 11-50 employees
Real User
A good tool that offers stable and reliable protection
Pros and Cons
  • "It's a good security tool and it aligns with the rest of our security stack."
  • "The VPN is in need of improvement."

What is our primary use case?

This firewall is being used to protect our site.

What is most valuable?

It's a good security tool and it aligns with the rest of our security stack.

What needs improvement?

The VPN is in need of improvement. For us, it is hard to set up and it not working properly.

For how long have I used the solution?

We have been using the Sophos XG at one of our sites for about a year.

What do I think about the stability of the solution?

This product is part of our infrastructure and we use it every day. The internet stays up with no outages, so I think that Sophos XG is a stable product.

What do I think about the scalability of the solution?

We have not had the need to scale to this point. Our entire organization is protected by it.

How are customer service and technical support?

I have not been in contact with technical support.

Which solution did I use previously and why did I switch?

Prior to this solution, we were using Meraki. My company has a better partner channel with Sophos, which is why we switched.

What about the implementation team?

Our in-house technical team deployed this firewall.

What other advice do I have?

My advice for anybody who is looking into implementing this product is to trust your techs.

This is a good product, although there is always room for improvement.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
CTO at Kingsway Hospitals
Real User
A great UI with very intuitive features; comprehensive documentation ensuring issues are easily resolved
Pros and Cons
  • "Great interface and in-built help is very intuitive."
  • "Lacking network access control, user profiling and analytics dashboards."

What is our primary use case?

Our primary use case of this solution is for protection and to have better governance for our LAN usage. I've got a lot of people working from outside on the corporate infra and all policy based decisions happen there. The solution is basically a firewall that protects us from various internet threats, but other than that provides controlled and properly managed access using various rules of VPN and other fingerprints of people logging in. I'm the CTO of the company and we are customers of Sophos.  

What is most valuable?

The interface is great and easy to understand. Any firewall engineer who has medium to moderate experience on bylaws, can easily understand the UI. The language presented on various features and the in-built help, is very intuitive. If you have a problem you can figure it out there and then. As a result, there is less probability that we'll call tech support.

What needs improvement?

The solution really needs some additional features like network access control. If they could incorporate some user profiling and present the analytics of the login user usage patterns, or a typical proper management dashboard to take a decision on the firewall rules, that would be useful. Basically, MI's and the dashboard could be more user friendly. The information is there but the dashboards are not in a graphical format. In short, I'd like to see network access control, user profiling and analytics dashboards. It would make the solution a more competitive product on the market. 

For how long have I used the solution?

I've been using this solution for over four years. 

What do I think about the stability of the solution?

This is a stable solution. I haven't had any firewall crashes or any non-performing rules for over two years. We are a hospital so all the lights of all the devices should be on 24/7, 365 days a year.

We manage and control around 250-300 internal users. There would probably be another 75-100 logging in externally.

What do I think about the scalability of the solution?

This is definitely a scalable solution. The way we've configured it, if a device goes down, it can be shut off and removed from the network for repairs or updates and our second firewall automatically takes the load.

How are customer service and technical support?

We only used technical support during our initial deployment. After that, we didn't need support because the product was working perfectly well. We trained ourselves on the newer software and we are capable of managing and maintaining our own firewalls. In addition, Sophos provides online documentation which is very user friendly. If you follow the steps you get the result. 

Which solution did I use previously and why did I switch?

I previously used Cisco's firewall ASA and it was extensively implemented in my earlier role. The main reason to migrate to Sophos was due to their aggressiveness in terms of pricing but also the fact that they had features that Cisco did not have.

How was the initial setup?

The initial setup was very straightforward. Deployment took somewhere between six and eight hours. 

What's my experience with pricing, setup cost, and licensing?

There's no annual licensing fee. When we purchased the product, it was with a five year agreement bundled in with the product price and the recent rollout is not yet five years old. When we renew, we'll renegotiate. I can't differentiate between the product costs and the licensing costs at this point. We're very lucky that we get one of the best deals in the country in terms of pricing. The Sophos-backed pre-sales and implementation team were very cooperative and collaborative which really helped us make the decision to choose Sophos.

What other advice do I have?

I would definitely recommend this solution but it's only suitable if it fits the needs of the company so I would suggest carrying out some research. Why does the company need a firewall? What rules do they want to deploy on the firewall? Based on the answers to those questions the company can make a call. 

I would rate this solution a nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Manager IT at a retailer with 201-500 employees
Real User
Stable IPS features and good technical support, but the reporting needs to be improved
Pros and Cons
  • "The most valuable feature is the intrusion prevention system."
  • "The two main areas where this product needs improvement are routing and reporting."

What is our primary use case?

We use this firewall as part of our security solution.

What is most valuable?

The most valuable feature is the intrusion prevention system.

What needs improvement?

The two main areas where this product needs improvement are routing and reporting.

The security can be improved, as well.

For how long have I used the solution?

I have been using Sophos XG for more than two or three years.

What do I think about the stability of the solution?

Stability has not been a problem for us.

What do I think about the scalability of the solution?

I am satisfied with the scalability.

How are customer service and technical support?

The technical support from Sophos is excellent.

Which solution did I use previously and why did I switch?

I previously used the Microsoft Firewall. It is easy to use but it doesn't the IPS and malware detection capabilities that Sophos has.

How was the initial setup?

The initial setup and configuration are not difficult for somebody with firewall experience. However, for somebody who has not worked on one in the past, it will be complicated.

What about the implementation team?

We had assistance with the deployment.

What's my experience with pricing, setup cost, and licensing?

The price is cheaper than that of some competing vendors.

Which other solutions did I evaluate?

Prior to implementing Sophos, I tried using a solution by Fortinet. However, it was much more expensive.

What other advice do I have?

My advice for anybody who is implementing this solution is to ensure that somebody with firewall experience handles the deployment.

Overall, I find that this is a good product. That said, there are improvements that need to be made in the routing, reporting, and security.

I would rate this solution a seven out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user1375350 - PeerSpot reviewer
Technical Analyst- Presales and delivery at TechNexa Technologies Private Limited
Real User
Endpoint firewall and proxy that is user-friendly, easily scaled, and has good synchronization features
Pros and Cons
  • "it's user-friendly, not complex."
  • "The uploading and downloading of reports should be included."

What is our primary use case?

The primary use case of this solution is as an endpoint firewall and proxy.

What is most valuable?

The features that are most valuable are synchronized security, the security hard build, the application synchronization, and the events synchronization.

it's user-friendly, not complex.

What needs improvement?

The uploading and downloading of reports should be included.

We are looking for a firewall to block the uploads from the user, not the downloads. I would like to see this feature updated.

In the next release, I would like the uploading and downloading reports to be included.

For how long have I used the solution?

I have been using this solution for almost two years.

We will be upgrading to the newest version that was released two or three months ago.

What do I think about the stability of the solution?

This product is stable.

What do I think about the scalability of the solution?

This solution is easily scalable. We have 15 to 20 users.

How was the initial setup?

The initial setup is straightforward.

It's easy to understand and to install.

What about the implementation team?

I am a technical analyst and handling the pre-sales. We provide and implement the solution to our customers.

What other advice do I have?

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Chief Operational Officer at Merchant Light LLC
Reseller
Easy to set up, keeps extensive logs, and scans all traffic for malware
Pros and Cons
  • "The most valuable feature is that it scans all of the data for any kind of malware."
  • "It would be helpful if they had a set of standard templates because it would assist in the beginning, when you are just getting started."

What is our primary use case?

We are going to be hosting our own website and we are using the Sophos XG because we want to make sure that it is well protected. We also want to make sure that the rest of our LAN is not compromised.

In addition to using this firewall ourselves, we resell the product to our customers. We have a well-trained team that can perform the implementation and deployment.

How has it helped my organization?

Our network is now much better protected than it was. If you don't have your network and your infrastructure secured, as a business, which is about more than just putting a firewall in place, then you're asking for trouble. There is a lot of hunting going on, and it's not just the large corporations. It's the small businesses, too.

What is most valuable?

The most valuable feature is that it scans all of the data for any kind of malware.

It logs everything that goes in or out, and the logs are helpful.

The simplicity of the setup is very good. I can add whatever ports I need and it's pretty easy to set up.

What needs improvement?

It would be helpful if they had a set of standard templates because it would assist in the beginning, when you are just getting started. They do have a template, but I mean specifically for different use cases. For example, an existing template for setting up a web page would suggest what kind of security we need to have in place. They do have help menus and videos, but additional templates would be useful.

For how long have I used the solution?

I have been using Sophos XG for about eight months.

What do I think about the stability of the solution?

The stability has been rock solid and it hasn't gone down once.

What do I think about the scalability of the solution?

For me, there is essentially no limit when it comes to scaling. I have never used all of the connections but the limitation is between 50,000 and 200,000. I would say that scalability is enormous. If we had a bigger network then I would probably get a bigger Sophos.

At this point, we're just starting and only have three or four people who are regularly using it.

How are customer service and technical support?

The technical support is awesome.

Which solution did I use previously and why did I switch?

We did have a Cisco router prior to using Sophos XG, but I don't know much about Cisco or how to get it operational. I also realized that it was getting old, so we switched to a high-end Sophos model. With malware in this day and age, where we have a 6000% increase in the number of malware attacks compared to two years ago, we wanted to be well protected.

How was the initial setup?

The initial setup is straightforward. If I can do it then anyone can do it. The deployment took a couple of hours. Because we are new to this type of solution, our strategy will be to begin by blacklisting everything and then whitelisting only the things that we need.

What about the implementation team?

Our in-house team handled the implementation and deployment. We have more than 200 people that are very well trained, so we can set up pretty much anything. 

What's my experience with pricing, setup cost, and licensing?

We paid for our licensing for three years, upfront, and there are no costs in addition to the standard fees.

Which other solutions did I evaluate?

I evaluated several options and sought out advice before selecting Sophos XG.

What other advice do I have?

I am happy with this solution, which is one of the reasons that we are selling it. I don't like to sell or recommend things that I have not used. I have tried a lot of the features but I would say that there is a lot more potential I haven't even tested at this point.

I would rate this solution a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
it_user1359756 - PeerSpot reviewer
Owner/President at TeamLogic IT of Oklahoma City
MSP
Easy to manage, performs well, and the pricing is good
Pros and Cons
  • "The cloud-based interface makes it easy to manage."
  • "The weakest point is the technical support because they are difficult to get into contact with."

What is our primary use case?

We are a managed service provider and the primary firewall that we sell and maintain is Sophos XG. It is also used in the company.

What is most valuable?

The most valuable feature is that it is a next-generation firewall.

The fact that it is integrated between endpoints and the firewall, and then the firewall and a central Sophos operation center, is very good.

The cloud-based interface makes it easy to manage.

The integration with the Intercept X approach means that Sophos XG can do things that none of the others are doing.

What needs improvement?

The main area that needs improvement is the documentation.

Sophos needs to be a little better at communicating with partners about changes, issues, patches, and so forth. 

The weakest point is the technical support because they are difficult to get into contact with.

For how long have I used the solution?

We have been using the Sophos XG series for three years.

What do I think about the stability of the solution?

This solution has been very stable and it's a good product, otherwise, I wouldn't be using it.

How are customer service and technical support?

The technical support team is knowledgeable and they are good, although it is very hard to get a hold of them. You sometimes have to wait in queue for over an hour to speak with somebody. To me, that is the most frustrating thing about Sophos.

Which solution did I use previously and why did I switch?

We did not use another similar solution prior to Sophos XG. Since the MSP business started, it has been our primary firewall product because of the pricing and support.

How was the initial setup?

The initial setup is complex, as is setting up any next-generation firewall today. You have to know what you're doing with firewalls in general, although beyond that, it isn't as bad as some of the firewalls that I have seen.

The deployment typically doesn't take longer than a few hours or a day, depending on the type of client and what it is that we have to do.

What's my experience with pricing, setup cost, and licensing?

The Sophos pricing, in general, is better than SonicWall, Fortinet, WatchGuard, or anybody else. Because of the partner program, the pricing I get is extremely good compared to what I would get from any of the others.

Which other solutions did I evaluate?

I have evaluated several firewall products and I think that Sophos is better in terms of ease of use, performance, and pricing.

What other advice do I have?

I would highly encourage others to evaluate Sophos and adopt it. I've discovered that compared to other products, it is easier to manage and I think that it operates better.

Overall, I think that they've got a pretty complete set of features and they seem to be on a really good path. My only complaints are about the documentation and the availability of technical support. 

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
it_user1363380 - PeerSpot reviewer
Manager IT at QPS Bioserve Pvt Ltd.
Real User
Easy to use, robust, and the default templates are helpful
Pros and Cons
  • "This solution is very user-friendly and even a non-professional can configure the policies."
  • "The cloud support needs to be improved."

What is our primary use case?

I was using the Sophos XG firewall in my last job, where it was part of our security solution.

We had multiple locations with the internet being provided from a central location. Each of our locations was connected point-to-point using MPLS lines. Using Sophos meant that we didn't need to have a router.

What is most valuable?

The default templates are helpful because if you want to create new policies, they make it easy to do anything you want.

Sophos XG is a very robust technology.

This solution is very user-friendly and even a non-professional can configure the policies.

There are unlimited SSL VPN clients and it is free with Sophos.

What needs improvement?

The cloud support needs to be improved. As it is, they only have support for Microsoft Azure. They should expand it to include providers like Amazon and Alibaba.

What do I think about the stability of the solution?

I have not heard complaints of bugs or glitches occurring.

What do I think about the scalability of the solution?

Sophos is a scalable technology that is being regularly updated.

How are customer service and technical support?

I have been in contact with technical support many times and they are very good.

Which solution did I use previously and why did I switch?

Currently, in my new company, I am using Fortinet. This is a very basic firewall and ultimately, I would like to update them.

How was the initial setup?

The initial setup is not complicated. For somebody with an intermediate level of knowledge, it will take between three and four hours to deploy. For a more experienced person, it may take two or three.

Which other solutions did I evaluate?

I am currently in the process of evaluating the different firewalls that are available in India.  One of the options is Sophos, and I am also considering others such as SonicWall and Palo Alto.

With Fortinet and SonicWall, there is a limit of 10 people who can simultaneously connect using the VPN.

What other advice do I have?

Sophos XG is a firewall that I would recommend for people who are looking for good security in a medium-scale organization.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior System Administrator at a financial services firm with 201-500 employees
Real User
Has a simple setup and has good stability
Pros and Cons
  • "The simplicity of the setup is the most valuable feature."
  • "Their technical support needs improvement. I've been on hold with them for hours waiting for their support."

What is most valuable?

The simplicity of the setup is the most valuable feature.

What needs improvement?

Their technical support needs improvement. I've been on hold with them for hours waiting for their support.

For how long have I used the solution?

I have been using Sophos XG for five years. 

What do I think about the stability of the solution?

They seem pretty stable. They're pretty good devices when they're up and running. Once you get them up and running they seem to work quite well. It runs 24/7.

What do I think about the scalability of the solution?

They're very scalable.

How was the initial setup?

The setup is easy. We did the deployment ourselves. 

What other advice do I have?

If you pay for the premium support, you'll get better support from Sophos.

I would rate Sophos XG an eight out of ten. 

The integration with their Sophos Central isn't great. That needs some work. If they could work on the integration with Sophos Central, that would be great.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Administrator IT at Shopfront Limited
Real User
Synchronized security centrally monitors endpoints in real-time
Pros and Cons
  • "This kind of strategic technology makes it much easier to remove malware and address vulnerabilities quickly."
  • "It would be great if the user can have a portal to check on activities related to their account."

What is our primary use case?

We primarily use this solution for bandwidth control, intrusion prevention, and network security.

How has it helped my organization?

We now have visibility into our network.

What is most valuable?

Sophos operates using a Synchronized Security in its XG platform. It is facilitated by an active connection with all of the network endpoints. This connection operates like a heartbeat, notifying the firewall instinctively when an endpoint has been infected or compromised. The firewall then quarantines the problem area and provides detailed information on how the endpoint was compromised. This kind of strategic technology makes it much easier to remove malware and address vulnerabilities quickly.

What needs improvement?

It would be great if the user can have a portal to check on activities related to their account.

For how long have I used the solution?

We have been using Sophos SG for two years.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Technical & Pre-Sales Manager at GateLock
Real User
Top 5Leaderboard
Multifaceted security protection to protect us and our customers
Pros and Cons
  • "All of the features are amazing, especially Sandstorm, which prevents bad traffic or downloaded files from reaching our customers' and partners' networks."
  • "Network security is in need of improvement."

What is our primary use case?

This solution is implemented for medium and large enterprises to protect their network from attacks and to filter the web traffic through web protection and application protection modules.

This solution includes Email protection, IPS, Antivirus gateway, ATP, Reporting, VPN, Sophos Wireless controller, load balancer, WAF, and traffic shaping.

How has it helped my organization?

  1. It's protecting our networks from threats.
  2. Block URLs and web applications based on business needs.
  3. Not expensive when compared to other vendors, with a great added value.
  4. Impressive synchronized security with its endpoint solution.

What is most valuable?

All of the features are amazing, especially Sandstorm, which prevents bad traffic or downloaded files from reaching our customers' and partners' networks.

What needs improvement?

Network security is in need of improvement.

For how long have I used the solution?

I have been using this solution for five years.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user633438 - PeerSpot reviewer
Information security specialist at a non-tech company with 201-500 employees
Real User
Enables us to trace any user and pinpoint any vulnerability or malicious software
Pros and Cons
  • "We are able to trace any user and pinpoint any vulnerability or any malicious software. We are able to synchronize between the local and active directories so we can catch users easily through their login names and IDs."
  • "There needs to be a way that we can distinguish between educational institutions on Youtube and other Youtube videos. You can do this on Fortinet. Basically, they can block all other Youtube videos besides those that are from educational institutions. With Sophos, you either allow for all Youtube videos or none at all. They need to allow for more specification on different websites."

What is our primary use case?

We use the solution for application control and web filtering. We also use it as a VPN point, and we use it on other occasions for tracing and reporting about usage and high application rates.

How has it helped my organization?

We are able to trace any user and pinpoint any vulnerability or any malicious software. We are able to synchronize between the local and active directories so we can catch users easily through their login names and IDs.

What is most valuable?

The reporting on the solution is excellent.

What needs improvement?

There needs to be a way that we can distinguish between educational institutions on Youtube and other Youtube videos. You can do this on Fortinet. Basically, they can block all other Youtube videos besides those that are from educational institutions. With Sophos, you either allow for all Youtube videos or none at all. They need to allow for more specification on different websites.

They only have one single location for training videos. They must offer them elsewhere as well. When the site goes down, everything stops, and you can't access the videos when you need them, so they need to diversify that. It's limiting.  

For how long have I used the solution?

I've been using the solution for two years.

What do I think about the stability of the solution?

The stability of the solution is excellent.

What do I think about the scalability of the solution?

The scalability is good. We could only handle around 5,000 users but even when we reached 3,000 users, Sophos only consumed around 24% and 40% of Prime usage. 

How are customer service and technical support?

The solution's technical support is not the best. When I take a step to open a case with Sophos support I can't understand them at all; I can't understand their accent. I always appreciate if they can communicate with me through e-mail instead, which makes it much easier. 

Many cases take a long time to be resolved. Some cases they seem to ignore or don't reply to for a long time so I have to remind them that the case is still open before they will respond. 

How was the initial setup?

The initial setup was straightforward. The implementation took about a day. There were only two people needed for deployment.

What about the implementation team?

We had a consultant assist with the setup. They were very good.

What other advice do I have?

We use the on-premises deployment model.

I would rate the solution nine out of ten. It's a very good firewall. It helps a lot with protection, and every organization needs a firewall to ensure they are protected.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
‎Chief Operating Officer at Al Manar
Real User
An excellent firewall solution with reasonable licensing rates and a straightforward setup
Pros and Cons
  • "Price-wise the solution offers acceptable rates. You can find cheaper solutions on the market but when you go cheaper you have fewer features. Today, based on iQuate market the price is very reasonable and affordable, and it's good if you get a good discount. Discounts can be offered by the vendor. If it's a competitive upgrade which means the customer is upgrading from another vendor, Sophos provides extra discount so they can win the deal. In general, it is a good price."
  • "They should expand their DDoS feature. It's basic. They need to enhance it."

What is our primary use case?

We primarily use the solution internally in our company and we also deploy it for our customers.

What is most valuable?

We have many Sophos solutions that we use together. We use Sophos UPM and Sophos XG. Next, there are just firewalls. The Sophos UPM is the basic firewall; Sophos XG is a mix of Cyberoam and Surface (Sophos acquired Cyberoam three years ago). We use all the features within these solutions and we have a full set of licenses. They offer IPS, IBS, BPM, web publishing, web protection, etc. We're using everything. 

What needs improvement?

They should expand their DDoS feature. It's basic. They need to enhance it.

Technical support needs to be improved.

The solution needs a mobile application for the administrator. Today, as an administrator, you cannot manage the solution from your tablet or from your mobile. You can only go through a web console. Other vendors have mobile apps. Some vendors also have the ability to manage and check the chart report and change some settings from a mobile application. This would be an excellent add-on for administrators who are traveling. It could help a lot. 

For how long have I used the solution?

I've been using the solution for seven years.

What do I think about the stability of the solution?

For the past seven years, we haven't had any issues with the hardware or software. It's stable. If a customer misconfigured it, they might face issues. Out of the box, however, it's stable; it is an appliance that customers can depend on.

What do I think about the scalability of the solution?

The solution is scalable. Sophos has plans for customers who want to upgrade or add another appliance in the same environment. As a customer, I've deployed to as many as 300 users or as few as 30.

How are customer service and technical support?

Technical support isn't as good as it needs to be. In most cases, these days, the partner has to work hard to support the customer. The response time and the experience of the support team are not as expected. As a partner, we've never opened a case. Our customers, however, have told us they have had issues.

How was the initial setup?

The solution is straightforward. Deployment took about 30 minutes.

What's my experience with pricing, setup cost, and licensing?

Price-wise the solution offers acceptable rates. You can find cheaper solutions on the market, but when you go cheaper you have fewer features. Today, based on iQuate market the price is very reasonable and affordable, and it's good if you get a good discount. Discounts can be offered by the vendor. If it's a competitive upgrade which means the customer is upgrading from another vendor, Sophos provides extra discounts so they can win the deal. In general, it is a good price.

What other advice do I have?

We are a Sophos partner. We both use the solution and recommend it to clients.

Compared to other competitors, I'd rate the solution nine out of ten. However, for very large enterprises, the largest firewall appliance from Sophos might not be enough for thousands of users. If I was rating the solution for enterprises, I would rate it eight out of ten because of this. 

I would recommend the solution, however. We often recommend the solution to our clients and it works very well for them.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
Chairman at BASL
Real User
Excellent integration with the Sophos firewall and has a user-friendly interface
Pros and Cons
  • "I like the fact that it can self remove malware and do updates on the cloud via Sophos Central."
  • "On reports, they sometimes give a summary, but it lists different users as unknown. There are times that I really want to know which user or which IP is causing a problem."

What is our primary use case?

I use the solution as my endpoint firewall and at the same time, I use it for load balancing and spillover.

What is most valuable?

What I like the most is the reporting. 

The integration with the Sophos firewall is brilliant. I don't need to be physically present in the office. I can monitor everything from Sophos Central. That is a great feature and it's one thing that I really appreciate about the solution.

I like the fact that it can self remove malware and do updates on the cloud via Sophos Central.

The interface is good.

What needs improvement?

Although I enjoy the reporting elements of the solution, it can still be improved. I still can't drill down. There is some information that I would really, really like to see, but I still can't access it.

On reports, they sometimes give a summary, but it lists different users as unknown. There are times that I really want to know which user or which IP is causing a problem. 

For how long have I used the solution?

I've been using the solution for ten months.

What do I think about the stability of the solution?

There is something that have observed and I don't know what exactly the problem is. Right now, from my ISP I'm supposed to have unlimited bandwidth, but I observed behind the firewall my bandwidth seems low. I'm not exhausting what I have from my ISP. I've checked the TOS and there's no limit. When I spoke with one of the resellers they said that they too had experienced it before and that probably I should restart the device.

That they observed that the clients that restarted had their internet service improve. I don't think that is a good solution. I don't want to have to restart my device to have the internet service improved.

I've checked the setup. I even checked with the reseller, who told me everything is okay. I've gone for XG training. Even after the XG training, I've gone back to look at my setup. I can't see anywhere the bandwidth is being shared. I'm not sure if it's the device itself, but I've checked everything.

What do I think about the scalability of the solution?

The scalability is okay. We have about 200-250 users.

How are customer service and technical support?

Technical support can be improved upon. There are times that I've had some issues that I've tried escalating in technical support and it takes a while before we really get it resolved. 

Once I was getting a particular malware from an unknown source on one of my servers which was behind the firewall. I asked their support why. Later they advised that I should install Intercept X for servers on that particular device. I was confused about how it was behind a firewall; the firewall should be able to detect which system is getting infected. The system doesn't really go to the internet and nobody browses on it. The only thing I could imagine that could cause it was a Windows update. If it was from an update they least it should have been able to say, "Okay, it was from this particular update that this malware was filtered in."

Out of ten, I would give their service a five.

Which solution did I use previously and why did I switch?

The solution we were using previously was Cyberoam.

The Cyberoam device was about five years old and had started malfunctioning. It wasn't giving us the output it had previously provided. At that time, Sophos had already bought Cyberoam. We had the option to either upgrade the OS to a Sophos OS or to a Sophos device.

We decided to go for a Sophos device since the Cyberoam device was already problematic.

How was the initial setup?

The initial setup is straightforward.

What about the implementation team?

I used a reseller to assist with implementation.

What's my experience with pricing, setup cost, and licensing?

We pay on a yearly basis. 

We have Sophos XG, but we also have Intercept X for our endpoint and recently we just deployed Intercept X for the servers. I've not done a calculation of the costs of all three to know what my yearly maintenance costs would be.

What other advice do I have?

Once you have basic networking skills and firewall management it's easy to set up. With Sophos Central, I think it's a good solution for any IT department.

I would rate the solution eight out of ten.

As it is now, the solution is good, but I believe that there's still room for more improvement. I still believe the reporting could be improved. Sophos, from my experience, seems to affect my bandwidth. I didn't set any limit, so I don't know where that is coming from, but it's something that we've noticed with the XG.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Support Services Manager at a wholesaler/distributor with 51-200 employees
Real User
An easy to use firewall solution that improves our security
Pros and Cons
  • "The solution seems pretty stable. We've had no issues so far."
  • "It's easy to use, but it's hard to configure exact settings. They need to make it easier to access advanced features."

What is our primary use case?

We use the solution mainly as a firewall.

What is most valuable?

The solution improves security.

What needs improvement?

It's easy to use, but it's harder to configure when you want detailed settings. They need to make it easier to access advanced features.

For how long have I used the solution?

I've been using the solution for three years.

What do I think about the stability of the solution?

The solution seems pretty stable. We've had no issues so far.

What do I think about the scalability of the solution?

We haven't had to scale anything so far, so I'm unsure about the scalability of the solution.

How are customer service and technical support?

I've never had to deal directly with technical support.

Which solution did I use previously and why did I switch?

We did not previously use a different solution.

How was the initial setup?

Implementation is straightforward. The only thing that was difficult was that we had some special cases and we had to dig in a lot to find the information for accessing very specific features. Deployment took about a week, however, we did about 6 months of research beforehand. You can deploy the solution with maybe one or two people, but we used five. We only need one person for ongoing maintenance.

What about the implementation team?

We handled the implementation ourselves.

What's my experience with pricing, setup cost, and licensing?

We don't have any costs above the licensing of the solution itself.

What other advice do I have?

We are using the on-premises deployment model.

The solution is easy to implement, however, if you do decide on this solution, I would make sure that you have someone that has experience with this kind of solution or to hire someone to implement the solution properly. It will make everything much easier in the long run.

I would rate the solution 9.5 out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Lead Advance Engineer at IHCC
Real User
Very easy to use but bugs find their way through their security
Pros and Cons
  • "What I like about his program, is that it is easy to use and easy to manage."
  • "The program is rather expensive."

What is our primary use case?

Our primary use case of this program is for antivirus and security purposes.  

What is most valuable?

What I like about this program is that it is easy to use and easy to manage.

What needs improvement?

Sometimes we experience difficulties with our server and that is usually due to a bug. Somehow bugs seem to find their way through Sophos' security. The issue is usually resolved when we contact technical support. In the next version, I would like to see an improvement in this. The developers should test everything after any update to ensure that bugs don't come though with the update.

For how long have I used the solution?

We have been using Sophos XG for three years now.

What do I think about the stability of the solution?

I've used FortiGate before and I would say that Sophos is just as stable, both being around 70% as stable as other products on the market.

What do I think about the scalability of the solution?

The scalability is good. We have 300 to 400 antivirus end users, and our company has around 1,000 users. We do have plans to increase usage because we are growing our projects around the world to countries like the US, Germany, Pakistan, India, UAE (Dubai) and Egypt.

How are customer service and technical support?

The technical support is okay. Whenever we call them with an issue, they come to us and resolve the issue. Sometimes they take time, but I still think it's good. I will rate the technical support eight out of ten.

Which solution did I use previously and why did I switch?

We only use Sophos because it can integrate with other product like FortiGate and we can easily connect the two programs. This makes the program scalable and easy to use. Many other products on the market are not compatible with each other and that is why we chose Sophos. 

How was the initial setup?

The initial setup was rather complex but we had no issues with the deployment.

What's my experience with pricing, setup cost, and licensing?

We bought a license for three years and we will renew it but I think the price is too high. If it could be less expensive, more end-users or partners will be able to afford it.

What other advice do I have?

It is a good product and I will definitely recommend it. I rate this product a seven out of ten. In the next version I would like to see an advanced level and not only a basic level. Nowadays it is a very useful feature to be able to upgrade.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user736143 - PeerSpot reviewer
Operations Manager at iBound
Real User
Excellent endpoint protection and easy filtering but needs a slightly better UTM
Pros and Cons
  • "The filtering is very easy to do. You can segment and create profiles for usage very easily."
  • "The UTM itself needs improvement. When you're navigating it seems like it takes forever to load anything. The hardware is okay. It's just the software that could be more responsive."

What is most valuable?

The endpoint protection plan is the most valuable feature of the solution. 

The filtering is very easy to do. You can segment and create profiles for usage very easily.

What needs improvement?

The UTM itself needs improvement. When you're navigating it seems like it takes forever to load anything. The hardware is okay. It's just the software that could be more responsive. 

For how long have I used the solution?

I've been using the solution for four years.

What do I think about the stability of the solution?

We do updates periodically, but the solution is very stable. We haven't had to go back to the site to reconfigure it or anything like that.

How are customer service and technical support?

At the moment, we haven't had a reason to contact technical support.

How was the initial setup?

The initial setup is very straightforward.

What about the implementation team?

We implemented the solution ourselves.

What's my experience with pricing, setup cost, and licensing?

We tend to go for the bundle because it's pricing is competitive. If a unit comes out and they bundle the hardware with the software, it seems to work for us. I've seen that with future upgrades coming up, that features like this will be taken away. The option to get a combo with hardware means the software portion is mostly free, and then you pay upfront for the three-year license for everything.

However, with the changes, I don't think that's going to be available anymore. It might sway our clients away from Sophos. Maybe there's something that can be worked out. Other than that, we've been happy with the price. It's competitive if you compare it to the competition, from a price point of view.

What other advice do I have?

We use a variety of deployment models, including public cloud, private cloud, and on-premises.

For what we are using the solution for, its practically perfect. We don't need other features added. The solution offers exactly what we need.

I would rate the solution seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
Chief Technology Officer at Leystel Nigeria Limited
Reseller
An easy to manage solution that streamlines processes and management
Pros and Cons
  • "The SL VPNs are the most valuable feature. I have a lot of systems out of the head office that need to connect to the local networks, and they all connect wirelessly via the Sophos VPN client."
  • "The initial set up process can be a little tricky, especially when you are registering with Sophos using your registration number. Setup is not necessarily complex, but it's not trouble-free. You do have connectivity issues at the initial setup with registering the device on the Sophos platform to access the advanced features. It doesn't always go through the first time around. That may be an issue with the quality of our automation. I'm not sure exactly what it is."

What is our primary use case?

We use the solution as an internet firewall, and a VPN concentrator.

How has it helped my organization?

It streamlines the process of creating VPN access for users. Because of the AD integration, it makes it very easy to manage these users from different locations from a central source. It also helps us to get a good idea of what our risks are, or if there's any risky activity going on with the users. 

What is most valuable?

The SSL VPNs are the most valuable feature for me. I have a lot of systems out of the head office that need to connect to the local networks, and they all connect via the Sophos VPN client.

What needs improvement?

The initial set up process can be a little tricky, especially when you are registering with Sophos and you have a poor internet connection. Setup is not necessarily complex, but it's not trouble-free. You do have connectivity issues at the initial setup with registering the device on the Sophos platform to access the advanced features. It doesn't always go through the first time around. That may be an issue with the quality of our connection. I'm not sure exactly what it is. 

The single sign-on client I get maybe a 60% success rate on. There are times when it will use single sign-on for verification of users to access Internet resources. It still doesn't always catch the user. The user gets sent to the web login. Even though the single sign-on is helping, it doesn't always work. 

I would like to see a better single sign-on performance. I'd like to see a more streamlined way of managing your licensing as well.

For how long have I used the solution?

I've been using the solution for eight months.

What do I think about the stability of the solution?

There are no issues with stability. It's a very stable system and you almost never have serious problems for any reason. It's only when you do an upgrade that you have to restart. Stability-wise, for the on-premise solution, I'd give it 4 stars.

What do I think about the scalability of the solution?

Once you've bought the specific version, you are locked into the limitations of that plan. You can't exceed the number of VPNs, connections, etc. There's no way to increase that capacity, per se. You do have options where you can increase the port count and so on. However, in terms of scalability, you have to buy the capacity you require.

On the system I have now, it's not fully populated, but we have about 100 users. The plan is to eventually support about 1,400 users.

How are customer service and technical support?

I don't use the solution's technical support. I typically just use the documentation. There are lots of guides and videos available. In most cases, I search the guide. There's a step-by-step guide to deploy so I don't have to contact technical support.

How was the initial setup?

The initial setup isn't hard, but it can be tricky. Since I've been using several Sophos devices, I now find it's fairly simple. I get the deployment done in two hours, including integration. For others, it may take about a day to get everything done. 

There's almost no maintenance. There's really only the requirements of adding users and populating VPN connections. One person does that on a part-time basis.

What about the implementation team?

I handled the implementation myself.

What was our ROI?

We do see an ROI. It would be the cost of the support. If I had to hire a CCNP in Nigeria, I would be paying about $10,000 per annum for a CCNP minimum. For a less experienced person, I can get for about $6,000. I am probably saving about $4,000 a year in personnel costs from going with the XG rather than the ASA.

What's my experience with pricing, setup cost, and licensing?

We are paying about $1,500 yearly for the Enterprise Plus. As far as I know, there aren't costs above this standard fee.

Which other solutions did I evaluate?

We evaluated Cisco ASA as well as the FortiGate before ultimately choosing Sophos.

I chose Sophos over FortiGate because I'd already had experience with Cyberoam and it was a fairly similar migration in terms of configuration from the UTM over. But in terms of features and capabilities, I think FortiGate is pretty similar to the Sophos. Cisco ASA I choose not to go with because it's much harder to configure. I also needed to be able to have someone other than myself manage it and not need to have someone with CCNP sitting down just to add VPN users etc. I felt that the Sophos solution was a better option because it gave me all the functionality of the ASA, but it's much easier to manage.

What other advice do I have?

We use the on-premises deployment model.

We definitely plan to increase the usage and also add high variability too. Right now, it is the main internet gateway and firewall for my network.

We're using both Sophos XG and Sophos UTM.

I would warn those considering implementation that, once you've got it, you're stuck with it. You can't really increase the capacity very much beyond what you have. It's always good to have the expertise available to take care of the box because even though it's a lot easier than the Cisco ASA, you still need someone that has a little expertise in managing it.

You can get very good performance without spending all of your money and without having to send a lot of high-end techs in-house to monitor processes.

I would rate the solution nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
PeerSpot user
Network & Hardware Administrator at Nile Projects & Trading Co.
Real User
Secure and stable tunnels with web filtering and application control give us confidence in our security
Pros and Cons
  • "It gives me a very good, stable connection in all tunnels."
  • "I would like to have remote access to clients using a static IP for a certain period of time."

What is our primary use case?

We use this solution for connecting site-to-site and client-to-site VPN for two protocols, IPsec and SSL VPN. We use encrypted tunnels to achieve fully secure connectivity between sites and clients.

It gives me a very good, stable connection in all tunnels.

How has it helped my organization?

Of course, it improves my organization to achieve fully secure connectivity between sites and clients.

It has a good web filtering database and a good application control database in addition to intrusion prevention. Together, these give me confidence in our security.

What is most valuable?

All of the features in this solution are good. The most valuable is the IPsec VPN tunneling and SSL VPN tunneling, both site-to-site and client-to-site.

The log viewer is extremely helpful for analyzing all incoming and outgoing traffic.

What needs improvement?

I would like to have remote access to clients using a static IP for a certain period of time. This would allow me to log in to any client, remotely, with a known and fixed IP address.

For how long have I used the solution?

We have been using this solution for five years.

Which solution did I use previously and why did I switch?

This is the first solution that we implemented.

What's my experience with pricing, setup cost, and licensing?

It's a suitable price and license.

Which other solutions did I evaluate?

We did not evaluate other options before choosing this solution.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Project Manager at a mining and metals company with 1,001-5,000 employees
Real User
Offers a high level of visibility of what's happening on your network or on your client machines
Pros and Cons
  • "Sophos XG has cybersecurity. It integrates with the antivirus software."
  • "The only issue that Sophos XG now needs to improve is the product's reporting capability."

What is our primary use case?

I use Sophos XG as a content filtering, web filtering, and application filtering utility, as well as to integrate with the endpoint antivirus software. 

I have Sophos Endpoint Antivirus installed on the user machines as well, i.e. the Central Cloud Management version. That's our main use. 

Sophos XG has cybersecurity. It integrates with the antivirus software.

How has it helped my organization?

I have a serious problem because our offices are scattered around the world in very remote areas. We cannot deploy proper branch office guides, active directory sites, and software services. 

It is impossible to apply any sort of group policy on the user machines, which makes it very hard to control issues like USB ports, access to cameras, or access to any preferences on the user machines. 

With the integration between Sophos UTM and the installed endpoint antivirus, you can now manage all those features from your cloud subscription. You can allow and block whatever you want from the cloud. 

You can allow whatever USB ports you want for specific devices with specific IDs, serial numbers or modems. The machine gets updated online or updated from the antivirus settings, i.e. the UTM unit itself.

The UTM unit itself has a cache update on it. Once the clients behind the UTM get updated, they get access or they get denied access to the hardware resources they are applying for. This is a major benefit for us.

What is most valuable?

The application filters available with Sophos XG are brilliant. The sandboxing and the way the firewall or the UTM integrates with the installed endpoint antivirus clients on the user machines is brilliant. You get the chance to isolate network threats before they become active or become distributed on your network. 

With the cloud version of Sophos XG, you get the proper visibility of your network and the user machines. With the cloud versions of the antivirus, i.e. the cloud central management of the antivirus, you get high visibility.

With the application between the installed Sophos UTM, you get a high level of visibility of what's happening on your network or on your client machines. You get protected against threats. You get proper visibility. That solves a major issue.

What needs improvement?

There was a big issue with the Cyberoam and with the SG units as well, i.e. the previous Sophos UTM model. With Sophos XG, you get the chance to block what sites operate on SSL or that operate with HTTPS, without the need of extracting and distributing a certificate. 

On older Cyberoam and Sophos SG old versions, if you wanted to block something like YouTube or Facebook or any other websites that operate with HTTPS, you had to extract the certificate. Then you had to export that certificate. Then you had to re-import that certificate in all the user browsers. 

The only problem was if you needed to use an active directory where those certificates would be automatically thrown into the user browsers once they logged in to the domain. 

For a scenario like mine where you don't have a group policy, it is a disaster and ends up with you setting the rules to block certain websites with HTTPS on the firewall, even while they are not being blocked so that the user will still have access to them. This problem is now 100% sorted out with Sophos XG.

Now you can actually block whatever you want, whether it's using HTTPS or HTTP keys from the firewall without the need for extracting certificates. That's a major improvement. That problem with the HTTPS settings was a huge issue. 

I know other people must be enjoying that it's sorted out now. It was a serious and major issue for Sophos. The only issue that Sophos XG now needs to improve is the product's reporting capabilities.

For how long have I used the solution?

I have used Sophos XG for over 10 years.

What do I think about the stability of the solution?

Sophos XG is stable enough for our requirements.

What do I think about the scalability of the solution?

We have about 450 Sophos XG users currently using this edition and 300 for the antivirus platform installed on the machines, plus in-service, around 310. We also have around 15 additional units deployed around the world.

How are customer service and technical support?

I'll give Sophos XG technical support an eight out of ten for their service.

Which solution did I use previously and why did I switch?

I used Cyberoam previously, although I always used it as a UTM only. What made me move to Sophos is that they were acquired, i.e. they acquired Cyberoam to start with the development. At that time the software had many features that were not available with FortiGate, in terms of content filtering, and it was an appliance when Websense was the software to be installed on a server. 

There was a problem with our operating system with some of the updates, i.e. with the operating system or the hardware. I moved from Websense to Cyberoam because it wasn't applying properly.

How was the initial setup?

The initial setup is definitely something different than the old Cyberoam and it's a bit complex. If you've been dealing with UTMs and you understand the concept, it is still complex but then I find it enjoyable.

Sophos XG is not hard to configure. Too much detail is always good. 

I required three or four hours for the initial setup. One day for the testing, fine-tuning, optimizing, and categorizing. Three days for the first unit with the initial setup and the customization including testing. Finally, three days for testing all the rules, the QA, and then putting everything live. 

What about the implementation team?

I used to work for an integrator myself years ago, as well as my team. We are all trained. We are all professional in what we are doing. No external help was used.

What was our ROI?

Our ROI is 100%. I've got the ransomware attacks being blocked. I've got the users' consumed bandwidth by using proxy bypasses and all sorts of applications being blocked now. 

It's saving on the companies and the employees working hours and time. It's saving on minimizing virus infections and applications that the users like to use on their machines in order to bypass blocking USB ports or cameras. 

It is saving the company money by saving bandwidth and saving employees time by not allowing them to access time-wasting websites.

What's my experience with pricing, setup cost, and licensing?

We have the annual license for Sophos XG. It all depends on what you would like to have in the package that you are purchasing.

Which other solutions did I evaluate?

I evaluated FortiGate but wasn't happy with it. I evaluated another group called WatchGuard. WatchGuard has good features in it, but it's for a smaller business scale than the Sophos clients.

I evaluated Cisco ASA or PIX but now, I use Sophos XG as the firewall. I have confidence in their unit. Before Cyberoam and Sophos, I used FortiGate and Websense for our UTM requirements.

What other advice do I have?

I recommend that everyone should have a proper understanding of new network requirements and then enjoy it. Sophos XG is definitely a good product.

On a scale of 1 to 10, I would give Sophos XG an eight.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Consultant at Crotus
Consultant
Email security features are good, but the technical support needs improvement
Pros and Cons
  • "We have found that the simplicity of the XG 210 is its most valuable feature."
  • "When I call, I have to wait at least one to two hours to reach them."

What is our primary use case?

Our primary use case for this solution is to act as the main broadband device in our data center. The XG 210 model is being used for a hospitality solution.

How has it helped my organization?

The main improvement for us is with our email. The email options and email security features are good. 

What is most valuable?

We have found that the simplicity of the XG 210 is its most valuable feature. There are a lot of options available for the default firewall rules, such as email and web, that are used to secure the network.

I like all of the options, but the most important thing is that it is easy to understand how to configure everything, compared to other firewalls.

What needs improvement?

We are having a lot of issues with conflicts and user sessions, and Sophos has suggested that we change the device to the XG 400.

Aside from these issues with scalability, the email security features are good, but there are not many options. We would like to know why an email is being blocked, and how we can allow delivery. It does not keep emails in the queue for delivery. It can only log whether it is delivered or not delivered. If I need more details then I have to log in using SSH to get that information.

When an email comes in from the outside it is detected. When we check the log it only tells us that it is not delivered. We would like to create an exception, but there are not many options available for this. For example, a domain space is not allowed. Only the user name can be used to do that. We need a domain-based exception for email.

Next, the XG 210 is easy to configure, but when we are looking for more details then we can only get this information through SSH. It is quite difficult. If we can get all of those details then it would help us to understand, so this needs to be improved.

There are a lot of options and it gets confusing sometimes. If they can give limited options, with more information, then it would be good for the large sites.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

The product is stable, but by stable, I mean that we still have issues. The issues are more technical, which is why they suggest that we change the device to fix the problems.

What do I think about the scalability of the solution?

Our main data center has more than seventy servers that host a web server and internal applications. This is where we use the XG 400.

We have installed the XG 210 model at a smaller data center. We have between three and four hundred users at the most. However, because we have more than three hundred sessions, the vendor has suggested that we change to the XG 400. We do not yet know if this will fix our problem.

At our remote sites, we use the XG 135 model, and we do not have many issues.

How are customer service and technical support?

I am not sure why Sophos suggested using the XG 210 model after doing a site check, but we are facing issues and they suggested that we replace the model.

When I call, I have to wait for at least one to two hours to reach them. Sometimes they will pick up the call immediately, but most of the time they will not. I usually have to wait one hour before they pick up the phone.

When a ticket is created we have to wait three days before getting a reply from them. When they create a ticket for a critical issue, the response is delayed. This is a new device, and we expect support from Sophos. At least the partner should support the product, but the partners are always looking for money. Even if they deploy the device, for example, the XG 450, then they only offer support for one day. After that, there is no support.

Which solution did I use previously and why did I switch?

We have been using the Sophos XG 135 model at our remote sites and it works.

This year we deployed the XG 210 model at our data center, but prior to this we used Barracuda. We switched because Barracuda is too expensive. The options are very limited because you have to pay for each additional option. Each one represents a different service, like ADP (Active DDoS Prevention) or firewall. In contrast, Sophos is only a single payment, so we switched even though we lost some options that we liked.

How was the initial setup?

The initial setup is very easy.

Our deployment took only two to three days. The problem is that we had a lot of issues, especially with the email. The SMTP did not work, so I could not continue with the deployment. It took between fifteen and twenty days to resolve this. I do not know what they did to fix it, but we were delayed between twenty-five days and a month.

We had contacted the Sophos partner for help, but they were not able to fix our issue. After the problem was resolved I re-initiated the deployment. Only one staff member is required to maintain the solution.

What's my experience with pricing, setup cost, and licensing?

Even when you purchase the product from Sophos, they ask for a separate contract for support which is on an hourly basis.

For licensing the XG 210, we paid approximately $3000 for three years. There are no additional fees on top of this.

Which other solutions did I evaluate?

Other than the Barracuda and the Sophos models, I did not evaluate other solutions.

What other advice do I have?

Because of the problems that we are having, I cannot recommend this solution to anyone at this time.

I would rate this solution five out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
SherifFouad - PeerSpot reviewer
ICT Manager at Capital Limited
Real User
Gives us customizable policies, modifiable templates, and customized rules for single users
Pros and Cons
  • "It has a very friendly interface like the Cyberoam iNG units, it has customizable policies, it has proper templates that you can even modify, and you can customize the rules, down to each single user."
  • "The dashboard is customizable as well. It gives you the feature of including what you need to see as soon as you open the dashboard and to remove the non-necessary stuff, which varies from one organization to the next and from one IT manager to the next. And it has a wide variety of reports as well, template and customizable reports."
  • "Let's say I set up a rule to block users from accessing YouTube or Facebook. The rule will only block the HTTP traffic, which is non-secure traffic... The problem comes when you are trying to block, or allow, similar traffic that uses HTTPS. You have to create a certificate and import it into the users' web browsers, whatever they are using... The problem occurs when you're dealing with roaming users who use laptops and have to move between different sites that have different types of policies applied to them. You have to import all sorts of certificates from each site into their browser. Doing so will most probably conflict with something else that is totally irrelevant and cause a problem."
  • "Since Sophos took over Cyberoam, the online technical library and support library have become super messy. To get a piece of information is becoming a nightmare. They need to reorganize the online technical support and technical library."

What is our primary use case?

It's being used as a UTM, no firewalling. So it acts as a bridge. It doesn't provide the IP services, it doesn't provide DNS, it doesn't provide DHCP services, and it doesn't operate as a router or a point of mapping. It's only being used for filtering: Web and application filtering, as well as antivirus. I usually disable the anti-spam on all those units, because I have a gateway anti-spam server in place.

What is most valuable?

The web and application filters, as well as the quality of service. It has a very friendly interface like the Cyberoam iNG units, it has customizable policies, it has proper templates that you can even modify, and you can customize the rules, down to each single user.

It gives flexibility in the rules and the filters that you apply, based on, for example, the level of usage and the managerial level, etc. It's highly customizable.

The dashboard is customizable as well. It gives you the feature of including what you need to see as soon as you open the dashboard and to remove the non-necessary stuff, which varies from one organization to the next and from one IT manager to the next. And it has a wide variety of reports as well, template and customizable reports.

What needs improvement?

The major problem that I am facing, and I know that others are facing as well, is with the HTTPS classic, in general, or any classic that works on Secure Socket Layers. Let's say I set up a rule to block users from accessing YouTube or Facebook. The rule will only block the HTTP traffic, which is non-secure traffic. But most websites right now, most of the reputable web services providers, for extra security for their own web servers and for the user's security, provide a connection over Secure Socket Layer.

The problem comes when you are trying to block, or allow, similar traffic that uses HTTPS. You have to create a certificate and import it into the users' web browsers, whatever they are using. Now, this is not a problem when you're dealing with users stationed and fixed in a specific site or location. They are using desktops, they will never take the desktops and go home with them, nor will they ever take the desktops and travel to another country, or another site with it. The problem occurs when you're dealing with roaming users who use laptops and have to move between different sites that have different types of policies applied to them. You have to import all sorts of certificates from each site into their browser. Doing so will most probably conflict with something else that is totally irrelevant and cause a problem.

A way around this is if you are using authentication with Active Directory. But most of the time, especially if you're operating in a remote site with a very slow internet connection, if it's available in the first place, authentication with Active Directory is impossible. 

So it needs an easier way to apply HTTPS filters, without importing certificates into users' browsers and without the need for using an Active Directory. There must be a way around it. There are workarounds. But with applied workarounds, it will work out once, it won't work out properly 10 other times. That is my only request.

Also, since Sophos took over Cyberoam, the online technical library and support library have become super messy. To get a piece of information is becoming a nightmare. They need to reorganize the online technical support and technical library. The easiest way to overcome this is to look at how the Cyberoam online technical library was structured and to build the Sophos technical library the same way. It is messy, totally unorganized, time-wasting. Instead of getting what you want in five minutes it takes half an hour.

What do I think about the stability of the solution?

Stability is good. I was so happy with the Cyberoam iNG unit, and I think the Sophos XG series is exactly the same as the Cyberoam iNG unit. It's a very good unit for a smaller or medium business. It's very stable and it takes overload easily, so it can add to the throughput. It has versatility, it will support extra users, it will support extra bandwidth, to a limit, and it keeps on working as a monster. I have barely replaced any of those units through the years.

What do I think about the scalability of the solution?

Scalability is brilliant.

How are customer service and technical support?

I usually deal with one of the major partners in Egypt. The name is Gateworx. I've been dealing with those guys since my previous company, back to 2002. Even when we're buying devices that will be used in other countries outside of Egypt, we get them from them.

They provide outstanding technical support and they provide outstanding pre-sales services. If I require a device to be delivered to a country outside of Egypt, they contact the partner directly and they set up everything, and I get the hardware delivered. They are outstanding.

This is one of the major reasons we didn't look at another UTM or firewall through the years. These guys were a proper representative of Sophos and Cyberoam.

Which solution did I use previously and why did I switch?

I've used heaps of them through the years. I've used Fortigate, which is now Fortinet. I've used Websense, they issued something like that years ago. ISS issued something like that years ago.

Sophos UTM, along with Cyberoam UTM, since they are both the same - it's only a different interface and a different hardware look - they provide the best value for the money. You get the best features for the best cost. They are the best, to a certain limit for a certain usage. I never use any of those units as a firewall. What I usually do is, I have an edge firewall responsible for routing, switching, and firewalling. And then I deploy the UTM behind it, only for filtering.

The most important criteria when selecting a vendor include getting the best features that you can get for an equivalent cost, so you're paying for what you're getting. You don't want to be paying for the name or the brand or the reputation of it. Also important are pre-sales services and "1000-percent" technical support services, in the environment and the remote areas we operate in, the warranty services as well.

How was the initial setup?

The setup is straightforward. But what could be a straightforward setup for me might be complex for others. It depends on your level of experience, the training that you got, and the engagements.

They have a setup wizard, and I have had heaps of technicians, over the years to set it up, even initially.

Which other solutions did I evaluate?

I was looking at either Cyberoam iNG or Sophos XG.

What other advice do I have?

My advice would vary based on your requirements. If you have a dedicated edge firewall, like Cisco ASA, you should get Cyberoam iNG and Sophos XG. They will do the job brilliantly. They will take the load, they will do a fantastic job.

If you are looking at units that will do both jobs - being an edge firewall and a UTM at the same time - with routing features, if you are going with Cyberoam and Sophos XG, I'd always recommend that you buy a higher model than what will meet exactly their requirements. So let's say that I'm looking at features that could be fulfilled with an XG 125 or 115, but I want to use the same unit as a firewall. I'd step up and buy an XG 135. You will always need those extra machine resources when you're providing routing, switching, and firewalling as well. Both of those products provide the best support ever, for the money being paid.

I rate it at eight out of 10. It's not higher because of the HTTPS issue that I told you about. That's my major issue. That's a super-disastrous issue that, unfortunately, cannot be solved easily.

And, sometimes we'll get a specific detailed report, stressing a certain aspect and it's not straightforward. I'll be able to do it, but then I'll have to combine or merge more than one, two, or three reports to get the results that I want. So more specific reports would be good. But then, again, there is a work-around by customizing the reports you want and then getting several reports and comparing them together. It's workable. My only issue is trying to save time, administration time is an issue for us.

But other than that, I'm happy. The product is brilliant, support is brilliant.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user846270 - PeerSpot reviewer
Senior IT Infrastructure Solutions Engineer at a tech services company with 51-200 employees
Real User
Cloud portal allows me to manage firewall from any location; interface is user-friendly
Pros and Cons
  • "Valuable features include: the ease of setting up the VPN connection; the fact they have the cloud management option, so I can manage the firewall on a cloud platform from anywhere I am; the user interface is very user-friendly, so it's very easy for the administrator to make any policy changes."
  • "I would like the update process to be easier, to update the firmware of the boxes. I think it's much better automatically than having to do it manually: Download the file, do network discovery. I they can make the update process much more automatic that would help."

What is our primary use case?

We use it for VPN connectivity with remote sites, as well as general IPS and IDS.

It's a satisfactory solution so far, no problems. It's very easy to use, and we have technical support for any issues, so it's quite good.

How has it helped my organization?

It's cost-effective. We are not that big a company. It gives us the features that we need.

What is most valuable?

  • The ease of setting up the VPN connection. 
  • The fact they have the cloud management option, I can manage it on a cloud platform. So anywhere I am, I can always manage the firewall.
  • The user interface is very user-friendly, so it's very easy for the administrator to make any policy changes.

What needs improvement?

I would like the update process to be easier, to update the firmware of the boxes. I think it's much better automatically than having to do it manually: Download the file, do network discovery. If they can make the update process much more automatic that would help.

What do I think about the stability of the solution?

The stability, so far, is actually quite good. I think the only issue we have had is some flapping on the connection, but it was a bug. The support is quite good, so the issue was resolved in no time at all. We have not had many issues at all. It's been working fine.

What do I think about the scalability of the solution?

I don't think this applies in our own case because we just bought the medium-range box, so it's adequate for our needs.

How are customer service and technical support?

It's very good, very responsive, and they resolve our issues in no time at all.

Which solution did I use previously and why did I switch?

We were previously using a different solution, a Cisco ASA firewall, but it was not a next-generation of firewall, next-generation meaning it can do unified threat management. We wanted a new solution that would also give us next-generation features, like anti-malware and end-point management and the like. That informed our choice of Sophos.

When selecting a vendor, the stability of the solution and then the technical support are very important. Also, the cost-to-reward ratio, the value we get from the product compared to what we pay for it. In addition, ease of management; how easy is it to manage? If it's too complex to manage it's a problem because you don't want to spend too much time managing it.

How was the initial setup?

It was completely straightforward, but our internal network is not that complex.

Which other solutions did I evaluate?

We evaluated Sophos vs Fortinet and Sophos vs Cisco

The cost of Sophos was more competitive compared to the rest. We also considered the management and it was easier to manage than the rest. That's how we came to our conclusion.

What other advice do I have?

I would rate it an eight out of 10. I don't rate it "perfect" because it can always improve. But the features that come along with Sophos are very, very extensive. It gives me so many options, the ability to remotely manage my firewall from anywhere, given the cloud portal. The solution hasn't given us too many problems at all, and even when we did have an issue, it was resolved.

My advice is to take advantage of the trials, they have a trial on their website where you can see how the cloud management works; you can have a free account for one month and play around with it and see how easy it is to manage. That way you can know if it can handle the services you are going to require. Take advantage of training on their website as well. Check the industry ratings, they are pretty highly rated.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
MelvynLee - PeerSpot reviewer
MelvynLeeNetwork Cooperations at STEVENSON ASTROSAT LIMITED
Real User

Good advice. Thanks. I am currently coparing the Sophos XG125 against the Fortigate 60E. Both close on performance and facilities but I suspect Sophos is going to be cheaper.

PeerSpot user
IT Infrastructure & Security Manager at a university with 1,001-5,000 employees
Real User
Firmware flexibility allows us to run multiple rules with different configurations
Pros and Cons
  • "The most valuable feature, according to the setup we have at our work place here, is the flexibility of the system or the firmware that's running the appliance. It's so flexible, performing multiple rules with different configurations. According to the set up here, we need to implement several firewalls with different access levels, because we have a variety of users. For this requirement, it's very flexible and very easy to use."
  • "It is performing well. However, the only challenges that we are facing are the effectiveness with blocking the proxy and tuneling applications, aside from proxy and similar applications. So the application filter on the product is not really performing 100%. Every now and then there are some updates that are happening on such applications, and it takes time until it gets the appropriate updates and becomes capable of capturing such applications and blocking them. A new feature I would really like to see would be some sort of an enhanced application filter with greater efficiency when it comes to the applications that can bypass firewall policies. These applications are really a nightmare. Once they are on the network and not detected, or the appliance is not really successful in capturing them and unblocking them, the bandwidth gets wasted all the time."
  • "Scalability it is a bit limited. We did a sizing exercise before the purchase. But that was just to fit our current needs. There was no room for having an option to upgrade the device. The only option that we have if we are grow in the near future, is to go for another model with higher specs, which is actually more expensive. In other words it doesn't have that modularity ."

What is most valuable?

The most valuable feature, according to the setup we have at our work place here, is the flexibility of the system or the firmware that's running the appliance. It's so flexible, performing multiple rules with different configurations. According to the set up here, we need to implement several firewalls with different access levels, because we have a variety of users. For this requirement, it's very flexible and very easy to use.

What needs improvement?

It is performing well. However, the only challenges that we are facing are the effectiveness with blocking the proxy and tuneling applications, aside from  proxy and similar applications. So the application filter on the product is not really performing 100%. Every now and then there are some updates that are happening on such applications, and it takes time until it gets the appropriate updates and becomes capable of capturing such applications and blocking them.

A new feature I would really like to see would be some sort of an enhanced application filter with greater efficiency when it comes to the applications that can bypass firewall policies. These applications are really a nightmare. Once they are on the network and not detected, or the appliance is not really successful in capturing them and unblocking them, the bandwidth gets wasted all the time.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It's stable. So far we haven't experienced any instability issues with. 

What do I think about the scalability of the solution?

As for scalability, I think it is a bit limited. We did a sizing exercise before the purchase. But that was just to fit our current needs. There was no room for having an option to upgrade the device. The only option that we have if we are grow in the near future, is to go for another model with higher specs, which is actually more expensive. In other words it doesn't have that modularity feature. 

How are customer service and technical support?

From time to time I use technical support provided by the seller and sometimes I use the online support, but not that much actually. It has only been for a very few issues. And the support I have received is not bad.

Which solution did I use previously and why did I switch?

Before Sophos there was mix of various legacy solutions that were not really considered firewall grade. The only specific thing that was used was a software-based firewall, but it was used on a very limited scale and only temporarily.

How was the initial setup?

It was very straightforward. 

Which other solutions did I evaluate?

The other vendors on the list were Fortinet and Palo Alto. Although it was really great with outstanding features, Palo Alto was far beyond our budget. And as for Fortinet, I was not really happy with the ease of use of the firewall and the features that were coming with it. Sophos was better compared to Fortinet.

What other advice do I have?

When it comes to selecting a vendor I think the most important thing would be the level of support and how fast they can respond in critical cases.

I would rate Sophos at eight out of 10. I cannot give it the best rating because there are the issues that I mentioned, and I believe there are other products on the market that are much better, like Palo Alto. And there is another product that I've come across recently, which is called Clavister. It's a Swedish product, if I'm not mistaken. They are current with features and have more stability. So for Sophos, it would be the appropriate rating for the time being, unless they come up with some new features and add some enhancements.

There is no straightforward advice in this case because there are many factors that may limit the person who wants the solution. Budget is an issue. If you don't have any budget limitations I would recommend going for Palo Alto. If not, consider Sophos or Clavister.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user431136 - PeerSpot reviewer
Consultant Information Technology at a tech company with 51-200 employees
Real User
Efficiently protects against malware attacks, gives visibility into ports, apps, and websites
Pros and Cons
  • "My clients gain efficiency in protecting against attacks from malware such as ransomware and hacker attacks. It also provides them efficient internet access control, and full visibility of ports, applications, and websites."
  • "Excellent product, meets most of the security needs of companies of various sizes. You can buy it without fear."
  • "It could offer a DNS Filter for blocking botnet networks."

How has it helped my organization?

My clients gain efficiency in protecting against attacks from malware such as ransomware and hacker attacks. It also provides them efficient internet access control, and full visibility of ports, applications, and websites.

What is most valuable?

  • IPS
  • Very efficient
  • Web Filter
  • Captive Portal with Voucher and Application Control.

What needs improvement?

It could offer other important functions such as a DNS Filter for blocking botnet networks.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No stability issues.

What do I think about the scalability of the solution?

No scalability issues.

How are customer service and technical support?

Satisfactory.

Which solution did I use previously and why did I switch?

I still use Fortigate, also Sophos UTM. As I'm a solution consultant, I have different clients where each solution fits the environment.

How was the initial setup?

Simple and easy.

What other advice do I have?

Excellent product, meets most of the security needs of companies of various sizes. You can buy it without fear.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
Mr with 51-200 employees
Real User
The pricing is very competitive in the market and the support is awesome

What is most valuable?

  1. Internet security, where we have one single point of console; where I can manage my endpoint and my gateway. 
  2. Any messages coming in, I am getting the intermission immediately. 
  3. If my endpoint is getting infected, I get to know. 
  4. If my file is getting infected, I get to know from a single pane point of view.

How has it helped my organization?

The product has been upgraded, and one of the features we were looking for has been incorporated into the newer version. It has allowed me to customize for my needs as well.

For how long have I used the solution?

The past six months.

What do I think about the stability of the solution?

Nothing. No issues. It is quite stable.

What do I think about the scalability of the solution?

This is a little bit of a challenge. Scalability is one issue with the hardware device and hardware files. Any kind of hardware file which has been delivered has been a challenge.

How are customer service and technical support?

Sophos is being preferred only because of their technical support. The tech support there is very good. It is a five-star support system that they have there.

Which solution did I use previously and why did I switch?

Our previous solution was Check Point. I switched to Sophos just because of the pricing issue.

How was the initial setup?

It is very user-friendly to set up. Very straightforward.

What's my experience with pricing, setup cost, and licensing?

Pricing is very competitive in the market.

Which other solutions did I evaluate?

Only Check Point. That was the one product which I evaluated.

What other advice do I have?

The support is awesome. QA is very simple, and the administration is very straightforward.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
MelvynLee - PeerSpot reviewer
MelvynLeeNetwork Cooperations at STEVENSON ASTROSAT LIMITED
Real User

Good to know the support is dependable. Thanks Vikas.

Lead NOC Engineer at a energy/utilities company with 51-200 employees
Real User
Has an intuitive interface. Easy to look at the logs and troubleshoot issues.

What is most valuable?

For one, its ease of use is the most valuable feature. It's very easy to look at the logs and troubleshoot issues as they arise. Things just make sense and it is a very intuitive interface.

How has it helped my organization?

It is easier to use than Cisco ASA, so it has reduced our SLAs by a considerable margin.

What needs improvement?

The VPN and central management need to be improved, but that's being nit-picky.

The IPsec VPNs are a little on the buggy side and you sometimes have to jump through hoops to get it to work. When I looked at them last, they were still in development for the centralized management of the firewalls, so when I saw it, it was very much in its infancy.

One more thing to add to what they can improve is the firewall policy presentation, they have their own special way of doing it which takes time for some to get used to, especially if you’re used to Cisco ASA.

For how long have I used the solution?

I have used this solution for about a year.

What do I think about the stability of the solution?

There were no stability issues.

What do I think about the scalability of the solution?

There were no scalability issues, it is very scalable.

How are customer service and technical support?

I would rate the technical support a 10/10; they are very professional. I know a couple of those guys over there on a first name basis.

Which solution did I use previously and why did I switch?

Previously, we were using another solution. However, we switched as we needed to upgrade our infrastructure.

How was the initial setup?

The setup was pretty straightforward. They had someone come in, walk us through it and train us on the platform.

What other advice do I have?

Get the professional support contract; it is well-worth it and those guys know their product very very well.

It is a very solid product, easy to use and implement.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
MelvynLee - PeerSpot reviewer
MelvynLeeNetwork Cooperations at STEVENSON ASTROSAT LIMITED
Real User

Thanks Sean, a very informative review. I am seriously considering the XG125 but slightly concerned about the VPN aspect as VPNs are used predominantly in our network. Also considering the Fortigate 60E.

IT Project Consultant at a tech services company
Consultant
Very intuitive and easy-to-use interface making it much easier to setup access and business rules

What is most valuable?

  • URL Filtering: because of the importance of controlling what and individual might access from the organization’s network. Sophos XG has 90+ categories, providing a level of granularity that eliminates the need to create customized categories.
  • IPS (Intrusion Prevention System): because of the importance of preventing hackers from using exploits and other mechanisms that might compromise the network
  • Anti-malware: Sophos XG comes with two anti-malware engines: its own and Avira, making the UTM more effective at catching malicious code.
  • Control Center: an interface crammed with the most vital information like security issues, appliance performance, and Internet link status.

How has it helped my organization?

With a very intuitive and easy-to-use interface, it made it much easier to setup access and business rules, VPNs and to identify issues like Internet link outages and security issues.

What needs improvement?

Sophos XG lacks link load balancing options like ratio and spill over, both useful in some scenarios.

I also think they might consider improving the RAM of some of the appliances, since there are processes that are very memory intensive.

Lastly, I would say packet monitor is another area for improvement as it lacks capabilities like exporting the capture from inside the GUI tool.

For how long have I used the solution?

A year and a half.

What do I think about the stability of the solution?

Yes, on the SFOS Version 15, I had to upgrade the firmware of an appliance since it had a problem with the JAMVM process (an apparently known issue in which that process consumes almost all of the CPU resources).

What do I think about the scalability of the solution?

No.

How are customer service and technical support?

I would say that Sophos Brazil has an excellent support team.

Which solution did I use previously and why did I switch?

No.

How was the initial setup?

It was very straightforward. And I credit that to the great job Sophos did on its OS interface, providing different ways of accessing the same option, hiding some of the complexities of a firewall system, and deploying it with many pre-built policies, objects and rules that for most of the environments makes it unnecessary to spend hours tuning the system.

What's my experience with pricing, setup cost, and licensing?

Sophos is clearly trying to position itself as the market leader in the UTM niche. One way they are doing this is by having an aggressive pricing policy and this makes it a good moment to start using their products.

Which other solutions did I evaluate?

Yes, FortiGate.

What other advice do I have?

Try to have the help of a Sophos Partner for the correct sizing and purchasing of an adequate licensing bundle.

In addition, I would recommend having a PoC in place in order to make sure that the solution is what the organization needs.

It is important to notice that the XG is available for a 30 days free trial and that there are virtual appliances available for the main virtualization platforms on the market.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user704991 - PeerSpot reviewer
System Engineer with 51-200 employees
Vendor
​The product has much potential to be one of the best on the market according to bang for bucks. But look critically to the features you want and the features that are available with this product.

What is most valuable?

Sophos RED, because this makes it very easy to deploy new sites, without the need of static IP addresses and a completely new firewall setup. The rule-based use is the same as if it were internal to the central site.

Web Protection, because this feature implements rules on user/group basis and this is done on the firewall rules itself. So it is easy to check.

Sophos Sandstorm, because it implements sandboxing so downloaded files are checked by hash or checked by unpacking it in within the Sophos Cloud.

How has it helped my organization?

With its central management console, it implements an intuitive management console with change tracking. So it’s easy to see who has made changes and to keep track of changes.

What needs improvement?

Email Protection has room for improvement. It doesn’t have an intuitive rule base. I would much like it to be like the Sophos UTM software. The level of detail in the settings is much too low.

For how long have I used the solution?

I have been personally using this product for almost two years now.

In our business, we have been using the product alongside the Sophos SG for more than a year now.

What do I think about the stability of the solution?

The first firmware versions were not that stable and had a lot of bugs in it. From Version SF 16 and above, the stability has improved a lot.

What do I think about the scalability of the solution?

We didn’t encounter any issues with scalability as of yet.

How are customer service and technical support?

Technical support, I would rate it as a six, because the technical expertise level from this product is below the level I’m used to. Also, the response times have increased since the launch of Sophos XG.

Which solution did I use previously and why did I switch?

We used the Sophos UTM software. We did switch for some customers to the Sophos XG solution because of the customer’s needs.

How was the initial setup?

The initial setup is pretty straightforward. The only downside is that a Sophos Account is necessary to activate the box. It has an intuitive setup to take care of the basic settings needed to connect to the internet.

What's my experience with pricing, setup cost, and licensing?

Pricing of the hardware box is the same as Sophos UTM, but the licenses are a little more expensive. The most used license is the Enterprise Guard, it implements Network Protection and Web Protection in a bundle with support.

Which other solutions did I evaluate?

We evaluate other options for our customers constantly. We select the product which is best suited to the situation. We evaluate Sophos UTM, Sophos XG, and Meraki.

What other advice do I have?

The product has much potential to be one of the best on the market according to bang for bucks. But look critically to the features you want and the features that are available with this product. Don’t select this product just yet for email filtering, because it is underdeveloped.

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
PeerSpot user
CEO at Makros SPA
Consultant
It allow us to see literally everything when it comes to traffic in a very easy and intuitive way.

Valuable Features:

  • Web and Application filter
  • Wireless integration
  • Email protection with encryption
  • Reporting and Dashboards

Improvements to My Organization:

Mostly it's related to visibility as this platform allow us to see literally everything when it comes to traffic in a very easy and intuitive way.

Room for Improvement:

I would like to see the possibility to add or block some content directly from the log interface or the live view of the interface so that if I see that an IP address is consuming a lot of bandwidth, I can right click on it and set some kind of policy. Everything else its perfect. 

Deployment Issues:

There was no issue with the deployment.

Stability Issues:

There has been no issue with the stability.

Scalability Issues:

There have been no issues scaling it to our needs.

Other Advice:

Contact a good partner with experience and follow the online KB for doubts. its almost everything there 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user