What is our primary use case?
Our main use case for Sophos XGS is to protect our network and internet connection, which consists of Aruba, HP, Avaya, and Sophos switches. It's a very new product for us at this time, having previously used a variety of other security solutions including Sophos SG (now UTM), Sophos XG, as well as those from vendors such as Fortinet, Hillstone, and WatchGuard. At the moment, I am only working with Sophos SG, XG, and XGS, with the new Sophos switches.
Sophos XGS is deployed on-premises as we tend not to work in the cloud for our kind of environment. We have many different departments where it is currently in use, including accounting, IT and development, administration, and so on, and there are probably around 200 users throughout these departments.
What is most valuable?
All the features are valuable, in my opinion, but for us the most important features are the network security, application control, and web server protection. Sophos Sandstorm is another good feature off the top of my head.
What needs improvement?
Having previously worked with the Astaro Security Gateway platform (now called Sophos UTM), I can attest that the configuration and dashboard for this older platform was easier to manage than that of both Sophos XG and XGS. If it were up to me, I would prefer to go back to the older SG dashboard. I am hoping that in future, the dashboard for Sophos XGS will be simpler and easier.
For how long have I used the solution?
I have been using Sophos XGS for about three or four months.
What do I think about the stability of the solution?
So far, the stability of Sophos XGS is better than Sophos XG. With XG, we have faced so many problems with not only the interface, but also with the system itself including the hardware and software. Thus, in comparison with XG, XGS appears more stable at this point.
Currently, our maintenance of Sophos XGS only needs to managed by one person, because alongside the Sophos switches, all the management can be done through the central management system.
What do I think about the scalability of the solution?
I would say it's scalable, as we already have around 200 people using it across not just one single department, but several, including accounting, IT and development, and administration.
When it comes to expanding our usage further, in general, I am not sure. We are currently watching the situation in Lebanon, and whether we have plans to extend it depends on what's happening in the country.
How are customer service and support?
The technical support is helpful.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Although I am using Sophos XGS in a personal capacity at our company, we are also partners and resellers of not only Sophos XGS, but also many other products from different vendors. For example, I have worked with Hillstone, Fortinet, WatchGuard, and Genesis products, and whichever product we end up using depends on the client's requirements.
How was the initial setup?
It was very easy to set up and it only took a couple of minutes. However, even so, it is still not as easy compared to Sophos SG version 9 (UTM).
What about the implementation team?
We did the whole deployment of Sophos XGS in-house. And further, for maintenance and management, we only require one person, since everything can be managed centrally when you have the Sophos switches.
What's my experience with pricing, setup cost, and licensing?
The licensing is reasonable. Comparing the cost of Sophos XGS with that of Fortinet or Palto Alto firewalls, for instance, it's not that expensive. However, the overall cost depends on the hardware you're using in addition to the licensing cost.
What other advice do I have?
Because it's such a new product for us, I would need some more time to determine whether there are any issues with bugs or hardware failure, so for now I would rate Sophos XGS an eight out of ten because it otherwise ticks all the boxes for us in terms of features.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller