
Overview
Video 1
Sophos Cloud UTM9 is a AWS Security Competency approved NextGen Firewall solution that helps customers with their shared security responsibilities by offering multiple layers of protection in a single virtual appliance that scans, controls and reports on traffic entering and leaving a VPC.
Sophos UTM is nearing end-of-life and will not be supported after 30 June 2026. Sophos recommends you consider Sophos Firewall on AWS, or other solutions.
Security features include a Web Application Firewall (WAF), a pre-tuned and automatically updated Intrusion Prevention System (IPS), an Outbound Web Proxy/ Layer 7 Application Engine to protect and control connections to the Public Internet, an Advanced Threat Protection engine to identify and block unknown and evasive threats, and VPN Gateway features to securely connect remote sites and users. The UTM9 NextGen Firewall solution also provides detailed logs and reports which can be viewed on system and/or exported to the AWS CloudWatch Logs service and any Syslog compatible device. You can deploy Sophos UTM as a standalone solution on the EC2 Instance type of your choice, or use the Sophos provided CloudFormation template to deploy an Active/Passive High Availability pair of UTM's that spans across multiple Availability Zones and integrates with key AWS services such as Auto Scaling, CloudWatch, and S3 to comply with AWS Best Practice guidance on secure architecture.
Sophos UTM is part of a complete cloud security portfolio. A selection of Sophos AWS Marketplace offerings is included below, while more can be found at <www.sophos.com/cloud > .
- Sophos XG Firewall Standalone (Free Trial): https://soph.so/xg-firewall-paygÂ
- Sophos Cloud Optix (CSPM with Free Tier): https://soph.so/cloud-optixÂ
If you have any questions about Sophos solutions or if you need assistance with deployment or configuration, please contact the Sophos Public Cloud team at aws.marketplace@sophos.com .
Highlights
- Control infrastructure and security costs by combining multiple security tools into a single, easy to deploy and manage solution.
- Web App Firewall (WAF) protects your web apps against common threats like SQL injection and Cross-Site Scripting. Next-Gen Firewall protection and reporting with stateful traffic inspection, Layer-7 application control, secure proxies, and IPS.
- Sophos UTM9 may also be deployed as an Active/Active Auto Scaling solution which provides maximum uptime, elasticity and the Sophos Outbound Gateway (OGW) feature set. Please see the 'Sophos UTM9 Auto Scaling' listing for more details.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Cost/hour |
|---|---|
m4.large Recommended | $0.76 |
c4.xlarge | $0.90 |
c5.9xlarge | $2.25 |
c3.xlarge | $0.90 |
m4.xlarge | $1.15 |
m3.xlarge | $1.10 |
m5.xlarge | $1.15 |
m4.2xlarge | $1.50 |
m5.2xlarge | $1.50 |
m3.2xlarge | $1.45 |
Vendor refund policy
Terminate the EC2 instance(s) or delete the CloudFormation stack at any time to stop incurring charges. You may email aws.marketplace@sophos.com for questions regarding Sophos UTM charges and refund requests.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
You can manage your Sophos UTM on AWS from the Web Interface using HTTPS (TCP port 4444), the command shell using SSH (TCP port 22), and via the RESTful API.
Sophos UTM requires a valid email address for administration purposes. This email address is not used for any other purpose and remains local to the Sophos UTM AMI. Please refer to the Sophos Privacy Policy for more details. https://www.sophos.com/en-us/legal/sophos-group-privacy-policy.aspxÂ
Sophos UTM on AWS Quick Start Guide https://www.sophos.com/en-us/medialibrary/PDFs/documentation/SophosUTMAWS.pdfÂ
For additional information about deploying on AWS please see: https://www.sophos.com/en-us/support/documentation/sophos-utm.aspxÂ
Resources
Support
Vendor support
For customers who participate in the AWS Product Support Connection, Sophos provides technical support via phone and web portal. Phone: +1-844-591-2756 Web portal:
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Standard contract
Customer reviews
Integrated firewall and VPN have provided cost savings and strengthened customer security
What is our primary use case?
My main use case for Sophos UTMÂ is to support several customers; we have some enterprise customers as well, but they use different firewalls, and for the smaller customers, usually we have our local Sophos, and then they have their own Sophos at their premises. We usually have site-to-site VPNs and monitor their on-premise equipment with our monitoring system.
At our own company, we also use Sophos UTMÂ as a mail gateway, and we use it for the VPNs for the road warriors, providing remote access for employees.
What is most valuable?
In my opinion, the best features Sophos UTM offers are part of the firewall itself, so we don't need an extra appliance, we don't need to set up extra open-source VMs or anything. It's just part of the gateway that is connected to the internet anyway, and we protect our Exchange servers with it. This works fairly well in my opinion, and it's good.
What I appreciate most about the features is that you can have modules with Sophos UTM, so network protection including the reverse proxy, or that you can have a module for the email protection, a module for the network protection, and so on. You really can only purchase the functions you need and still have the possibility to add later, so that's excellent.
Sophos UTM has positively impacted my organization certainly in all of those areas because any security system you have is better than none. The ease of use and the pricing have made it very easy even for smaller clients to have certain security measures in place. I would count that as a win for security and cost saving at the same time.
I can share specific outcomes regarding Sophos UTM; we've seen reduced costs certainly. Either the clients wouldn't have any security measures at all, just an ISP provided router, but those don't serve very well security-wise. Or they would have had larger, more expensive firewalls, and Sophos UTM really is easier on the budget. We've also seen time saved, definitely. We streamlined all our clients into using Sophos UTM if they want to have their on-premise infrastructure monitored, and that really saves a ton of time.
What needs improvement?
The needed improvements for Sophos UTM include that the GUI could be a little more high-resolution-aware because it's still stuck in the small, low-resolution admin days, and those are long over.
I choose a rating of nine out of ten for Sophos UTM because, as I mentioned, the graphical user interface is stuck in the past, and some things here and there are not implemented to the full, such as the reverse gateway thing, reverse proxy, and web application firewall. If you want to really implement some rules that are a little bit more difficult, Sophos always recommends getting the dedicated WAFÂ , or web application firewall, but I would prefer to have more features on the web application firewall in the firewall itself because it would make more sense. Other than that, it's a very smooth experience, and I really appreciate it.
For how long have I used the solution?
I have been using Sophos UTM since before it became Sophos. I used it from the Astaro days, actually, before they were bought by Sophos, so since 2009. I have been using Astaro and all the way up until recently when it became Sophos UTM.
What do I think about the stability of the solution?
Sophos UTM is very stable.
What do I think about the scalability of the solution?
In terms of scalability, Sophos UTM is very good. You can have large appliances or small appliances, you can change them, you can have high availability clusters, so very, very scalable in my opinion.
How are customer service and support?
The customer support for Sophos UTM used to be better when it was still Astaro, but those days are long gone. The customer support has been good to mediocre, but not very good.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I previously used different solutions; for the smallest of our customers, I usually use OPNsense , for example, the open-source firewall, because they don't want to pay any money whatsoever, besides needing more time to set up and everything. For larger customers, we usually had a FortiGate, for example, but FortiGate is a little bit more expensive and a little bit harder to set up, so I count Sophos UTM really good for that.
How was the initial setup?
My experience with pricing, setup cost, and licensing with Sophos UTM is that I was astonished to find that the prices are a little lower than competitors, and I'm really pleased with the functionality that you get for the price.
What was our ROI?
I have seen a return on investment with Sophos UTM, and I can share that the price is around thirty percent better, especially if you count in the employee time.
Which other solutions did I evaluate?
Before choosing Sophos UTM, I evaluated other options including FortiGate, OPNsense , and SonicWall, which was one customer using.
What other advice do I have?
The customer support for Sophos UTM used to be better when it was still Astaro, but those days are long gone. The customer support has been good to mediocre, but not very good.
In my opinion, the best features Sophos UTM offers are part of the firewall itself, so we don't need an extra appliance, we don't need to set up extra open-source VMs or anything. It's just part of the gateway that is connected to the internet anyway, and we protect our Exchange servers with it.
I choose a rating of nine out of ten for Sophos UTM because, as I mentioned, the graphical user interface is stuck in the past, and some things here and there are not implemented to the full, such as the reverse gateway thing, reverse proxy, and web application firewall.
What I appreciate most about the features is that you can have modules with Sophos UTM, so network protection including the reverse proxy, or that you can have a module for the email protection, a module for the network protection, and so on.
At our own company, we also use Sophos UTM as a mail gateway, and we use it for the VPNs for the road warriors, providing remote access for employees.
In terms of scalability, Sophos UTM is very good. You can have large appliances or small appliances, you can change them, you can have high availability clusters, so very, very scalable in my opinion.
I can share specific outcomes regarding Sophos UTM; we've seen reduced costs certainly. Either the clients wouldn't have any security measures at all, just an ISP provided router, but those don't serve very well security-wise.
Before choosing Sophos UTM, I evaluated other options including FortiGate, OPNsense, and SonicWall.
My advice for others looking into using Sophos UTM is that it's really good to have fairly good knowledge of Linux because Sophos UTM is built on Linux and it helps debugging, it helps, for example, network tracing, and issue fixing. Other than that, get the introduction course and get ready to deploy. It's really easy. I give Sophos UTM an overall rating of nine out of ten.
Long-term security deployment has supported laboratory operations and simplifies creating flexible proxy and zero trust rules
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
How are customer service and support?
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
What was our ROI?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
Has delivered strong cost benefit and reliable security features over time
What is our primary use case?
I am familiar with Sophos UTMÂ , which is the firewall. Sophos UTMÂ 's main use case is for protection and to control security features or navigation features, like implementing and controlling users' navigation. The clients that we implement and support with Sophos UTM are from different segments, with no specific segment.
What is most valuable?
Sophos UTM's valuable features include the cost, which is very competitive when compared with other vendors, balanced with the features that it delivers. Sophos UTM can deliver not only the basic but also the main features that a UTM demands, so the cost benefit is good.
Sophos UTM integrates well with other Sophos products through a console center for this purpose.
Sophos UTM's real-time insights into the network health have helped some of my clients, although the monitoring is adequate and does not provide high-quality monitoring. The functionality is not granular enough to monitor or identify issues effectively.
What needs improvement?
The update process could be improved with Sophos UTM overall since the experience and accuracy when updating the box could be better.
For how long have I used the solution?
I have been working with Sophos for around five years with my clients.
How are customer service and support?
I would rate the technical support with Sophos a seven because sometimes the time of the first resolution is not ideal, and we sometimes need to reopen the ticket and investigate more.
How would you rate customer service and support?
Positive
What other advice do I have?
I have experience with Sophos and other similar network products because we are a reseller of both Sophos and Huawei. I can answer questions about my opinions on Sophos or my experience. I have limited familiarity with the application control feature of Sophos UTM, as I only know and have experience observing it, not the management part. Some of my clients' companies use Amazon Web Services as a main cloud provider for their solutions. Sophos UTM pricing is competitive for both the license and the box from software and hardware perspectives. I would rate this review an 8 overall.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Has helped us strengthen protection with improved threat visibility and secure our network through detailed rule configuration
What is our primary use case?
We are still working with Sophos UTMÂ , so I can confirm that we have not switched to something else.
I have been working with Sophos UTMÂ since 2018.
The most valuable features in Sophos UTM are Mail Protection, Web Server, advanced endpoint, and the servers. Our systems are silent, secure, and we don't have many problems with security policy enforcement.
In terms of setting rules to guard the organization, especially on the network, we can set those rules, and through Sophos Central , we are able to see the equipment that has been registered and all the reports on the performance of each piece of equipment. For the endpoint equipment, there are close to 300 people using Sophos UTM in my company.
We have five administrators and around 10 servers, so we have advanced server protection that we are using.
What is most valuable?
We find the most valuable features in Sophos UTM to be Mail Protection, Web Server, advanced endpoint, and the servers. It helps us quite a lot, especially because since we use Sophos UTM, malware intrusions are not rampant.
It has helped us to set rules to guard our organization against any intrusion from outside. Our systems are silent, secure, and we don't have many problems with security policy enforcement. In terms of setting rules to guard the organization, especially on the network, we can set those rules, and through Sophos Central , we are able to see the equipment that has been registered and all the reports on the performance of each piece of equipment.
What needs improvement?
I would prefer to see additional features in the next release of Sophos UTM because cyber crime increases every day, so we also need to improve our game to prevent any chances for intrusion.
I cannot be specific regarding the features I would prefer to see in the future in Sophos UTM. In everyday life, there is room for improvement; it is the biggest room, so there is always a need to improve. Through the technical team, they can look at the loopholes and then be able to seal all the vulnerabilities that would bring problems.
For how long have I used the solution?
I have been working in this field for 18 years.
What do I think about the scalability of the solution?
So far, I have not had any problems with the scaling of Sophos UTM.
How are customer service and support?
We have not experienced any problems with the technical support because we are getting support from both the partner and Sophos directly.
I would rate the technical support by Sophos a 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before we used Sophos UTM, we were using Kaspersky.
How was the initial setup?
I took part in the implementation of Sophos UTM.
The implementation was straightforward, with no difficulties during the process.
It took approximately two hours to complete in my case.
What about the implementation team?
Four people were needed for the implementation.
I completed the implementation with the help of a Sophos partner.
The company that helped us is called Cloud Logic.
What's my experience with pricing, setup cost, and licensing?
The pricing would be more economical if sold directly to the user compared to going through a partner, as they need to take their percentage.
Which other solutions did I evaluate?
We evaluated other options before choosing Sophos UTM. We tried Sophos UTM and found it to be more helpful than what we were using initially, which was Kaspersky.
What other advice do I have?
For an organization similar to ours, we recommend working directly with Sophos instead of going through a partner. Additionally, having regular webinars would be beneficial so that people can be trained and given insights.
On a scale of 1-10, I rate Sophos UTM a 10.
Improves security management and simplifies remote access
What is our primary use case?
Most of my customers have more than one or two sites which are connected with the IPsec tunnel. For some people, they need VPN to enter the particular main HO site and access all other remote site subnets, such as when there is a file server hosted on another site. This was a simple use case: from one site, they will enter from SSL VPNÂ to one site and access all their remote sites using this VPN policy only. We don't need to require the VPN for all particular single sites; we create only one single VPN, and from that single console, they can access all these sites as well.
Currently I am working at AVH, which is a system integrator that provides solutions such as security and UTM solutions to clients. My task is the complete installation and implementation of these firewalls and, apart from that, post-support calls. If clients are facing any issues, they reach out to our company, and the company assigns me to their tech solutions.
For the initial setup, we create an SSL VPNÂ portal for this customer's public IP, and we make some local subnet so that the user will get some local subnet IP after connecting with Sophos UTMÂ . After that, we allow the security policy, which determines which resources they can access after connecting with Sophos UTMÂ . They access Sophos UTM VPN using the public IP, and then when they enter the site, they can access the limited resources we have allowed in the policies.
What is most valuable?
The most useful features I have worked with in Sophos UTM mostly involve the DNATing process and their web filters. Many customers require these web filters to be aligned, such as when they need to access resources over the VPN or over the DNATing process.
Application control reduces their bandwidth consumption. When users consume large amounts of bandwidth, this application filter can limit their usage, ensuring they won't face bandwidth failures. Users are limited to a particular bandwidth for a specific application only.
When connecting to Sophos UTM VPN, certain applications can be restricted from being accessible using this VPN policy. It is more secure with more granular security, allowing the user to only access specific, allowed applications.
I can very easily manage my Sophos UTM VPN users and get all the logs, details, and traffic monitoring over my single dashboard console.
What needs improvement?
For the challenges I've faced, zero trust is one area where I haven't worked much or have sufficient experience.
For how long have I used the solution?
I have around 2.5 years of experience in this particular domain.
What was my experience with deployment of the solution?
I currently don't have experience with deployment issues.
How are customer service and support?
I have connected with the Sophos UTM technical team one or two times.
How would you rate customer service and support?
Positive
How was the initial setup?
It is user-friendly and straightforward, so there are no certain challenges to configuring this VPN with Sophos UTM.
What other advice do I have?
Compared to other OEMs and other vendors' firewalls, Sophos UTM is very user-friendly. It has a user-friendly dashboard so that anyone, even a new beginner, can easily learn where the options are and how to configure UTM profiles. Different industries such as hospitality and manufacturing can have customized UTM profiles. The UTM is a granular and easy step, and non-standard categories can be manually added.
Regarding pricing, it's affordable for the features that Sophos UTM provides; there is no higher price, it is affordable.
When deploying on-premises, all customers have suggested this deployment type. Occasionally, there are certain failures; however, it's mostly user-friendly and reliable, with no major challenges in configuration. I definitely suggest checking it out.
On a scale from one to ten, I rate Sophos UTM a nine.