We can recommend Sophos XGS for industrial software companies, small businesses at the entry-level, as well as enterprise companies. We offer it for a range of customers, from entry-level to high-end.
Sophos Cloud Firewall (PAYG)
SophosExternal reviews
External reviews are not included in the AWS star rating for the product.
Best Next generation firewall
Evaluating Sophos: Comprehensive Security Solutions for Modern Threats
Good integration with third-party platforms and remote access feature
What is our primary use case?
What is most valuable?
The reporting in XGS is a major benefit for us. In other platforms, we can't get reports for one or two months. Secondly, it's very easy to handle and understand, and the deployment process helps enhance our skill set.
The integration with Azure SSO and IPsec is also great. I like the remote access feature, and I would like to see IPS included as well, where we get more detailed reports and can identify and block issues from a single source.
There are a lot more features I haven't explored yet. We just implemented it based on our colleagues' recommendations and are currently working through the support checklist.
Migration and support processes are improving. Even people new to Sophos are finding it easier to manage now.
What needs improvement?
A lot of training is required. When I train our engineers, they aren’t able to get sufficient training from Sophos-hosted sessions. We only find textbooks and some videos on Sophos portal.
More live sessions or time-bound training would help us understand how to pitch the firewall or use specific features, like advanced photo settings or integration with SD-WAN.
We need to know which feature is suited to different environments. Right now, that knowledge gap makes us more dependent on OEM support, which could be reduced by up to 40% if more training was available.
For me, reporting is a major area for improvement. Detailed reports help pinpoint issues like usage bottlenecks or abnormal activities, allowing us to fine-tune the firewall. IPS in XGS is great because it provides timely attack reports we can present to management. Integration with Active Directory could also be better. Sophos Central integration is good, but the firewall’s performance is slow when accessed through Sophos Central. Our clients also experience slow access when using their credentials. That’s a bottleneck I’d like to see resolved.
For how long have I used the solution?
I have been using it for the last three years.
How are customer service and support?
The customer service and support have been very good. It's much better now than it was a year ago. Back then, responses were slower, but now their technical support is good. However, RMAs (Return Merchandise Authorization) can still take a while. For instance, recently it took two days to analyze a faulty box.
Maybe it was due to the weekend, but after I raised the request on a Friday, the replacement box only arrived by Thursday. This caused a delay, and we didn't have any alternatives for providing Internet services to our clients during that period. It takes longer with XGS devices. So, I would deduct points for the delays in RMA and pricing.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Along with XGS, we push antivirus with laptop encryption, and also Sophos Intercept X for endpoint protection. We push all these products, along with the red devices (hardware appliances).
We're not pushing Sophos MDR because of the pricing. Clients aren't accepting it because competitors offer lower prices, and clients don't fully understand the additional features of MDR.
For endpoint protection, I only push Sophos antivirus with all the compliance features, like web filtering, data encryption for laptops, and protection for remote users. For MDR, we focus on larger companies.
We deal with corporate offices. For those types of clients, we push for MDR/XDR. However, they are also checking out other features and platforms because we've had some large opportunities.
What's my experience with pricing, setup cost, and licensing?
Compared to other products [like Fortigate, SonicWall and Palo Alto], Sophos's pricing is a little higher.
The second thing is that support is very good, but we're having more issues getting pricing for the Sophos device on time from our vendors. Whenever we request pricing, we simply drop an email.
We create comparison sheets for Sophos XGS when pitching to our clients. We highlight the benchmarks and advanced features, like reporting, that aren't available in other products. We emphasize the value of the bundle that comes with the firewall role. This is a major factor in convincing clients to choose Sophos XGS. The reporting capabilities and overall features are good.
What other advice do I have?
I would recommend using Sophos. We push Sophos to most of our clients. Almost 99% of them use it. Only a few clients prefer FortiGate due to company policies, and some use Check Point, but we mostly recommend Sophos XGS.
Overall, I would rate it an eight out of ten.
When compared to older versions, after the 2021 update, there have been significant improvements. Routing has become easier, and integration with third-party platforms like Azure and IPsec is seamless. Creating policies for different VLAN compliance requirements is also simpler, and the flexibility now is much better than earlier versions.
Engineered to deliver extreme levels of visibility, protection, & performance to help address some of the greatest challenges facing network administrators today
What is our primary use case?
The prominent use cases for Sophos XGS depend on the type of customer. Local governments, schools, production companies, sales companies, and the finance sector use it.
What is most valuable?
It’s popular because it’s easy to manage, the cloud console is excellent, and it supports VPNs. It can also integrate with endpoints, though this is optional. Regarding threat intelligence, customers in Central Europe often prefer managing their threat hunting rather than using the more expensive service from Sophos. This feature is handy for large international companies with many employees. Threat intelligence requires separate licensing and is optional. Customers can either manage it themselves or purchase the additional service from Sophos, which includes further actions and is more expensive. Smaller companies often don’t have the budget for this.
What needs improvement?
One area for improvement would be including automatically generated certificates for HTTPS, which was available in earlier versions but might not be in the latest.
For how long have I used the solution?
I’ve worked with Sophos XGS for over ten years, starting with Astaro and then Sophos.
What do I think about the scalability of the solution?
Sophos XGS is not expensive and is scalable. It can fit small schools and companies with just ten employees, showing its flexibility for different sizes.
How are customer service and support?
Sophos has two levels of support. The first level is qualified but may not handle complex issues well. I usually skip it and go straight to the second level for better results.
How would you rate customer service and support?
Positive
How was the initial setup?
Deployment is quick and easy. Small installations take about three hours, and even remotely if necessary. It might take up to two days for more extensive infrastructures, including initial setup and follow-up checks.
What other advice do I have?
Sophos XGS does use AI, particularly for sandboxing and analyzing suspicious documents in the cloud. It’s practical, as I haven’t had any major security breaches in the past five years.Overall, I’d rate Sophos XGS as nine out of ten. It has improved significantly over the years.
Provides good IPS, IDS, and web application security, but it is very expensive
What is our primary use case?
We use Sophos XGS firewall for edge control.
What is most valuable?
The solution's most valuable features are IPS, IDS, and web application security.
What needs improvement?
Sophos XGS should improve its customer service and educate its implementation partner. It should also work on building relationships with customers directly because there is no Sophos office or person to handle the Pakistan region. If Sophos opens its local office, its business will increase. Sophos XGS should train the technical staff about new challenges in security.
For how long have I used the solution?
I have been using Sophos XGS for almost three years.
What do I think about the stability of the solution?
Sophos XGS is a stable solution.
What do I think about the scalability of the solution?
At our data center head office, we have two high-availability devices. On the remote side, we are using a single piece of equipment. All these are XGS 2000, 126, and 200 series. So, we have already chosen a scalable solution. Around 700 users are using the solution in our organization.
How was the initial setup?
The solution’s initial setup is straightforward. It took hardly one hour to deploy the solution.
What about the implementation team?
We have outsourced the solution's deployment to a service provider or implementation partner. A team of professionals went on-site and installed it, and the configuration will be done through our remote support.
We signed a three-year support contract with the implementation partner when we purchased the hardware. Now, they are providing support, but it is not good. We have lodged an official complaint against the implementation partner because they sometimes refuse to provide support.
Initially, we were going with another partner, but the distributor recommended Information Systems Associates Pvt Ltd to us. So, I have also lodged an official complaint against the distributor.
What's my experience with pricing, setup cost, and licensing?
Sophos XGS is a very expensive solution. It cost us $ 33,000. Huawei and Sangfor make much cheaper firewalls available in Pakistan. The equipment is being sold at throwaway prices. If we compare the market prices, the acquisition cost of Sophos XGS is much higher than that of the other market competitors. However, Sophos XGS is cheaper than Palo Alto.
Which other solutions did I evaluate?
Its competitor, Sangfor, provides an add-on EDR feature with the same firewall. Each and every node is connected with the firewall through EDR because all traffic is monitored. This functionality is not available in Sophos.
What other advice do I have?
The solution provides threat intelligence capabilities, but some other tools are much better than Sophos XGS. I would recommend the solution to other users.
Overall, I rate the solution a seven out of ten.
Supports integration and has good support
What needs improvement?
Sophos XGS changes every two years, so we must update our knowledge. We can only test it with real requirements or problems to find scalability and reliability. We can't find these in normal testing. We can see reviews based on Gartner reports, but sometimes, we really feel problems. It can create many issues, even compatibility problems with fiber modules. Only system integrators or installers find these problems.
How are customer service and support?
I think Sophos technical support's immediate response is good compared to Fortinet's. If the technical engineer is good, they get the solution immediately. If not, it might take two days. For improvement, immediate response is required, whether by email, phone call, or WhatsApp. Sometimes, we can't wait three or four days for a solution. In urgent situations, we might use a spare Sophos device while waiting for support.
How would you rate customer service and support?
Positive
What other advice do I have?
I recommend what my customer needs and what fulfills their requirements. I suggest products based on price, quality, scalability, and reliability. Customers now ask for specific features at a certain price, not product names. I'm a system integrator and face technical support problems before implementation. I need pre-sales tech reports. If the distributor and support are good, I'll support that product even if the price is high. Urgent deliveries can be a problem if distributors don't cooperate.
I don't blame any product; all are good nowadays. Cisco products have high prices and compatibility issues. Fortinet has easy power replacement, while the tool needs specific adapters. I rate Sophos XGS seven to eight out of ten. Some models are very good, others not so much. It depends on the project, market, price, and features needed.
Nowadays, we have to integrate everything. Most products support this at some level.
A cost-effective solution to control the network and for web browsing
What is our primary use case?
We use the solution to control the network and for web browsing. It provides threat protection.
What is most valuable?
It increases productivity in our company. Everything is protected.
What needs improvement?
Deployment could be easier.
For how long have I used the solution?
I have been using Sophos XGS for three years.
How are customer service and support?
I have the company we bought from Cisco, which provides technical support. If anything goes wrong, we call them for any help and support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
With Cisco, You have to buy everything separately and request many options. It's preferable to get a full bundle like Sophos offers. Sophos includes everything in one package, and any additional features are less expensive than Cisco.
It is 20% more expensive than Sophos.
How was the initial setup?
The initial setup is difficult. You need to take a course to learn how to deploy Sophos. With training and hands-on experience, it’s manageable now, but setting up Sophos for the first time was time-consuming. Deploying the security and configuring the network took a lot of effort initially, but the process becomes much easier once that's done.
What other advice do I have?
Overall, I rate the solution an eight out of ten.