Sophos Firewall for AWS delivers advanced threat protection for AWS environments and assets. Protect networks, applications, ensure security of ingress and egress traffic, and maintain high web-application availability.
Sophos Firewall integrates leading technologies into a single next-generation solution without compromising security. Highlights include deep packet inspection with IPS, ATP, URL filtering, and in-depth reporting; Bidirectional AV for WAF with authentication offloading, path-based routing, country-level blocking; and self-service SSL and HTML5 VPRN technologies to make connecting from anywhere and on any device a reality - without administrative overhead.
Preconfigured templates and centralized policy management save time managing user, application and network policies, and provide pre-packaged web filtering, IPS, traffic shaping and app control policies for Active/Active and Active/Passive deployments spanning multiple availability zones.
Sophos synchronized security allows organizations to link endpoints, cloud workloads, and firewall to relay health status and immediately to respond to threats on your network.
If you have questions about Sophos solutions or need assistance with deployment and configuration, contact us at aws.marketplace@sophos.com.
The cloud formation template to deploy Sophos Firewall will optionally collect Sophos Central account credentials (email and password used to login to https://central.sophos.com). These credentials are used only once by the firewall to connect to Sophos Central and enable management services. This step is optional, and can be performed at any time after deployment, following the instructions available here.
Highlights
Sophos Firewall combines advanced networking controls, protections such as Intrusion Prevention Systems (IPS) and Web Application Firewall (WAF), plus user and application controls. Saving time taken to deploy and integrate multiple products.
Web App Firewall (WAF) protects your web apps against common threats like SQL injection and Cross-Site Scripting. Next-Gen Firewall protection and reporting with stateful traffic inspection, Layer-7 application control, secure proxies, and IPS.
Sophos Firewall includes extensive reporting. Sophos Firewall provides full insights into user and network activity, surfaced using easy-to-understand indicators so you can take preventive measures before problems occur.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay by the hour based on the EC2 instance type you run the firewall on. Pricing scales with instance size and family rather than by tiers or features. The list covers compute-optimized instances (c4, c5), general-purpose instances (m4, m5, m7i), and one burstable instance (t3.medium). Larger instances within each family carry higher hourly rates to match more vCPU and memory. You choose the instance that fits your throughput and performance needs. Billing runs on usage, so you only pay for the hours each instance runs, with no upfront commitment.
Top-of-mind questions for buyers
What does one billable hour on a given instance type cover?
You are billed for each hour the firewall instance runs on the EC2 instance type you select. The rate reflects that instance's vCPU and memory. Each running instance meters its own hours separately, so the count matches actual runtime for every instance you deploy.
Am I charged when the firewall instance is stopped or powered off?
The hourly software charge applies only while an instance runs. A fully stopped instance stops accruing software fees. You may still incur underlying AWS storage costs for the stopped instance, but the firewall license meters running time only.
How do I move to more capacity if my throughput needs grow?
You choose a larger instance within a family, or a different family, to add vCPU and memory. This is a deployment change you make, not an automatic tier upgrade. The new instance then meters at its own hourly rate for the hours it runs.
www.sophos.com
Helpful?
Vendor refund policy
Terminate the EC2 instance(s) at any time to stop incurring charges. You may email aws.marketplace@sophos.com for questions regarding Sophos XG Firewall charges and refund requests.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
This CloudFormation template allows you to deploy a Sophos XG Firewall Standalone. The template will bring up a single XG Firewall instance with two ENI network interfaces attached to the instance, each interface is in a distinct subnet.
The first interface is dedicated to the private subnet to be protected by the XG Firewall, the second interface is dedicated to the public/external subnet. The IGW is automatically attache to the public subnet.
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
You can manage your Sophos XG Firewall on AWS from the Web Interface using HTTPS (TCP port 4444), the command shell using SSH (TCP port 22), and via the API.
Sophos XG Firewall requires a valid email address for administration purposes. This email address is not used for any other purpose and remains local to the Sophos XG Firewall AMI.
For customers who participate in the AWS Product Support Connection, Sophos provides technical support via phone and web portal. Phone: +1-844-591-2756 Web portal:
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Deep packet inspection with IPS technology for threat detection and prevention
Web Application Firewall
WAF with bidirectional antivirus protection, authentication offloading, and path-based routing to defend against SQL injection and Cross-Site Scripting attacks
URL Filtering and Content Control
URL filtering capabilities with country-level blocking and pre-packaged web filtering policies
Centralized Policy Management
Centralized management of user, application, and network policies with preconfigured templates for Active/Active and Active/Passive deployments across multiple availability zones
Synchronized Security Integration
Synchronized security linking endpoints, cloud workloads, and firewall to relay health status and enable coordinated threat response
Application Layer Visibility and Control
Complete application layer-7 visibility and control of traffic with next-generation firewall capabilities in AWS environments
AI/ML-Powered Threat Detection
AI/ML-powered inspection engine with researcher-grade signatures for detection of zero-day threats, exploits, malware, spyware, and command and control attacks
Dynamic Policy Management
Policy definitions that dynamically apply to cloud assets based on AWS tags, Application IDs, User IDs, geographies, or zones without manual intervention
Cloud Infrastructure Integration
Seamless integration with Gateway Load Balancer, AWS Auto Scaling, and Transit VPC with AWS Transit Gateway for protection across dynamic and large-scale deployments
Advanced Threat Prevention Service
Cloud-delivered Advanced Threat Prevention security service with market-leading threat coverage against known and zero-day threats while maintaining performance
Next Generation Firewall Architecture
High-performance firewall solution with core firewall, VPN, NAT, and advanced L4-L7 security services including application security, IPS, and anti-virus capabilities.
Anti-Virus and Malware Protection
Cloud-based anti-virus protection that detects and blocks spyware, adware, viruses, keyloggers, and other malware over POP3, HTTP, SMTP, and FTP protocols.
Intrusion Detection and Prevention
Intrusion detection and prevention (IPS) system integrated with application visibility and control through AppSecure for threat detection and workload protection.
VPN and Secure Connectivity
IPsec and full mesh VPN termination services enabling secure connectivity from on-premises data centers, campuses, and branches to AWS cloud across geographically dispersed VPCs.
AWS Cloud Service Integration
Native integration with AWS services including Elastic Load Balancer, Auto-Scaling Groups, CloudWatch, Security Hub, Key Management Service, Elastic Network Adapter support, and Gateway Load Balancer with L3 gateway and L4 load balancer capabilities.
Centralized console everywhere for complete control of firewall and client
Reviewed on Jul 29, 2026
Review provided by G2
What do you like best about the product?
The centralized console is accessible from any device and anywhere, and allows for complete control over the status of the firewalls and clients.
What do you dislike about the product?
The access points have a cumbersome and slow management, and furthermore, they do not allow the creation of VLANs to segregate the networks.
What problems is the product solving and how is that benefiting you?
Perimeter security and client control.
Wlado R.
Gateway VLAN fast and efficient, seamless integration with client and web app
Reviewed on Jul 23, 2026
Review provided by G2
What do you like best about the product?
Excellent performance in terms of speed when used as a VLAN gateway for network segregation. The integration with clients and web applications is functional and has proven effective.
What do you dislike about the product?
The Wi-Fi is slow and offers few segmentation possibilities. Also, managing Active Directory and configuring the SSL VPN are complicated.
What problems is the product solving and how is that benefiting you?
Effective perimeter security. Manage external access with dedicated logs. Web filtering.
Wosha L.
Excellent perimeter security and a fast, intuitive console
Reviewed on Jul 23, 2026
Review provided by G2
What do you like best about the product?
Firewall with excellent perimeter security and a fast, intuitive console that allows you to control everything easily. The connection with clients is also good.
What do you dislike about the product?
The Wi-Fi managed by the Access Points is slow in connecting devices and does not support VLAN management, limiting the possibility of segregation.
What problems is the product solving and how is that benefiting you?
Protection of clients and perimeter. Control of web applications.
Ophelie B.
Excellent integration with management endpoints and scripts
Reviewed on Jul 23, 2026
Review provided by G2
What do you like best about the product?
Integration with endpoints and scripts for management.
What do you dislike about the product?
Sophos access points do not ensure good network segregation.
What problems is the product solving and how is that benefiting you?
Integration between firewall and endpoint, with management through NAC and application filtering.
Dheeraj S.
Fantastic Synchronized Security and Centralized Cloud Management
Reviewed on Jul 21, 2026
Review provided by G2
What do you like best about the product?
Synchronized security The Automatic communication between the firewall and Sophos endpoint is fantastic if an endpoint gets infected the firewall instantly isolates it for the rest of the network. Sophos Central Management managing rules web filtering and site to site VPNs across multiple locations from one cloud dashboard is very convenient. Clear traffic Visibility the control Center dashboard gives an immediate view of bandwidth hogs suspicious traffic and application usage. Solid SD-Wan & Remote Access: Setting up IPsec/SSL VPNs for remote users and managing multi-WAN routing works reliably.
What do you dislike about the product?
Initial Setup Curve: Setting up advance features like web application Firewall (Waf) or complex NAT rules requires going through some technical documentation first. Firmware Update Timing: Rebooting for firmware updates can take a few minutes compared to simpler routers so maintenance window need to be planned carefully.
What problems is the product solving and how is that benefiting you?
NetworkThreat Containment : Prevents infected remote or local devices from moving laterally across corporate subnets. Bandwidth & Web Control: Blocks unauthorized streaming torrenting or malicious domains to keep critical applications running smoothly. Simplified Multi-sites Management: Eliminates the need to log into individual hardware boxes locally when pushing global policy updates.