TrustRadius: an HG Insights company

Sophos Firewall

Score8.8 out of 10

49 Reviews and Ratings

What is Sophos Firewall?

Sophos XG Firewall provides comprehensive next-generation firewall protection powered by deep learning and Synchronized Security. Sophos Firewall supplies insights and exposes hidden user, application, and threat risks on the network, and say the product is differentiated by its ability to respond automatically to security incidents by isolating compromised systems, with Security Heartbeat™.

Categories & Use Cases

Media

Sophos Firewall v17.5 Control Center

Top Performing Features

  • Firewall Management Console

    Either command-line or web-based interface for centralized control and management

    Category average: 8.4

  • Proxy Server

    A proxy server changes your IP address and masks the origin of your network traffic

    Category average: 8.2

  • Policy-based Controls

    Firewall policy controls enable administrators to create firewall policies controlling what data is allowed to traverse the firewall

    Category average: 8.8

Areas for Improvement

  • Reporting and Logging

    Custom and summary reports, and log files enabling analysis of security incidents, application usage and traffic patterns

    Category average: 7.8

  • Visualization Tools

    Visualization tools present administrators with data on applications traversing the network, who is using them, and the potential security impact.

    Category average: 7.7

  • VPN

    VPN's implement encryption and anonymize IP addresses

    Category average: 8.9

Sophos XG Firewall is top tier when it comes to protecting your network at the perimeter.

Use Cases and Deployment Scope

The Sophos XG Firewall is used as our main firewall in all of our locations (4). It is serving as the gateway, web filter, application control, IDS/IPS, etc for all locations. It is also tied into our MDR service to help their analysts remediate issues with found.

Pros

  • Web filtering. This allows us to monitor web usage and block certain categories from being access at the perimeter.
  • Application Control. With application control we can block certain applications that get categorized from working accessing the Internet.
  • Synchronized Security. When utilizing the Sophos Endpoint product you can use Synchronized Security to minimize Lateral Movement in a network. If a machine is shows a Red status you can auto-isolate it and it is unable to communicate with anything else on the network.

Cons

  • Implementation of SSL/TLS decryption. There shouldn't be a need to distribute the SSL certificate to each machine if the machine already has the endpoint installed. The certificate should be either embedded in the installer or it passed from the firewall to Sophos Central and then down to the endpoint.
  • The ability to not have the VPN portal open to the web even if it is containerized. Utilize Sophos Central to deploy out the policies if you are using a provisioning file.
  • Tighter integration with Sophos Central. The web filtering between the XGS and Sophos Central don't have feature parity.

Return on Investment

  • With adding a second node, we've been able to minimize downtime which in turn leads to productivity increasing.

Usability

Alternatives Considered

Fortinet FortiGate and Cisco Meraki MX

Other Software Used

Sophos Managed Detection and Response, CrowdStrike Falcon Identity Protection, KnowBe4 Security Awareness Training, KnowBe4 PhishER/PhishER Plus

Good experiences sophos firewall.

Use Cases and Deployment Scope

Sophos Firewall is the default gateway for the network, handling all internet traffic (both inbound and outbound). We use all features of Xstream Protection + Web Server Protection and E-mail Protection. The Sophos Firewall resolved all issues I had with the old firewall (pfSense), including WebFilter, IPS Protection, Failover link, and load balancing. Today, Sophos XGS is very important in the environment.

Pros

  • IPS
  • Web Filter
  • SDWAN

Cons

  • DLP on E-mails Protection.
  • More settings on Webservers Protection.
  • Mobile app to alerts Sophos Firewall.

Return on Investment

  • More visibility of environment.
  • More security.
  • More control Internet access.

Usability

Alternatives Considered

GFI KerioControl and pfSense

Other Software Used

Sophos Intercept X, Sophos Intercept X for Server, Sophos Mobile, WatchGuard AuthPoint

Comprehensive cybersecurity solution.

Use Cases and Deployment Scope

We use Sophos XG firewall to safeguard the company network from cyberattacks such as ransomware, malware, phishing, etc. It is a next-generation firewall that provides comprehensive cybersecurity features and advanced threat protection. It offers many advanced features, such as deep packet inspection, automatic response, centralized management, web filtering, application control, bandwidth optimization, etc., in one place.

Pros

  • It provides you with advanced threat protection against cyberattacks.
  • It gives you deep visibility on risky users, applications, threats, etc.
  • It gives you an automatic response whenever threat is detected.
  • It offers many features like web filtering and application control and helps optimize bandwidth.
  • It ensures continued connectivity by providing features like load balancing, failover, etc.

Cons

  • Pricing.
  • Subdomain blocking should be improved.
  • In some cases, application control may not give you the required result.

Return on Investment

  • It helped us to safeguard the company network from cyber attacks.
  • It helped us to optimize bandwidth.
  • It ensured us continued connectivity with its failover and load balancing features.

Usability

Alternatives Considered

Palo Alto Networks Next-Generation Firewalls - PA Series

Other Software Used

TeamViewer, JioMeet, SAP HANA Cloud

Sophos XG Firewall

Use Cases and Deployment Scope

Currently i am using it as a primary device, I have a physical controller and central portal access to manage it from anywhere, i don't have any issue with this product, the support is good, they provide 24x7 support, and also interface is very user friendly, it's easy to use, easy to access access points from the firewall only it has the Access point controller includes itself.

Pros

  • Advance Threat Protection
  • VPN Support, WIFI support, Data Backup and notifications.
  • Web filtering, Applications support policy
  • High availability

Cons

  • When we add mac address into rule the internet goes down automatically for 1 minute, it should be fixed.
  • Sometimes policy tester gives a fake information, might be there is some network issue or other i don't know.
  • After some time, the firewall interface changes after updating.

Return on Investment

  • This is the user-friendly device,
  • Auto notifications facilities available
  • Advanced-level security features available
  • I haven't faced any bad experiences with this, but sometimes the firewall stops working for 40 to 60 seconds when we update the policy.

Usability

Other Software Used

Azure VMware Solution, AWS IAM Identity Center, Sophos Intercept X

Best firewall which protects you from latest cyber attacks.

Use Cases and Deployment Scope

Sophos Firewall is best and easy to use and manage it, We are using Sophos Firewall in HA mode as active/passive, it provides us the comprehensive network security solutions that helps us to protect our organization networks from latest cyber threats. Business Problem Addresses : WAN Failover, DDOS and ATP protection and Network Security. Scope of Use: We use the Sophos Firewall to address our problem regarding the Network Security, Web filtering, Traffic shaping, Application controls and advanced threat protection.

Pros

  • Web Filtering
  • Application Controls
  • VPN Connectivity
  • IPS

Cons

  • Enhancement in Integrations
  • Captive Portal Configuration
  • Customization for certain features

Return on Investment

  • Positive : Enhanced Security
  • Positive : Increased Productivity
  • Positive : Secure VPN and remote access
  • Negative: License Cost

Alternatives Considered

Palo Alto Networks Advanced Threat Prevention, Fortinet FortiGate and Cisco ASA 5500-X with FirePOWER Services

Other Software Used

Cisco Umbrella, Cisco AnyConnect, Cisco Secure Endpoint