Sophos Cloud Firewall (PAYG) logo

    Sophos Cloud Firewall (PAYG)

    Sold by
    Sophos Firewall for AWS delivers advanced threat protection for AWS environments and assets. Protect networks, applications, ensure security of ingress and egress traffic, and maintain high web-application availability.

    Ratings and reviews

    4.7
    936 ratings
    7 AWS reviews
    |
    929 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (936)
    Vaibhav P.

    Unified Sophos Central Management with Synchronized Security that Just Works

    Reviewed on Aug 17, 2026
    Review provided by G2
    What do you like best about the product?
    Having managed Sophos Central across a couple hundred endpoints and servers, the biggest win is unified management You don't need four different consoles to handle Intercept X endpoint protection, server lock-down, web filtering, and mobile management. Everything sits behind one portal.
    From an administration standpoint:

    1.Synchronized Security (Heartbeat): The automated isolation feature actually works as advertised. If an endpoint catches something suspicious, Central communicates directly with our Sophos Firewall (or isolates the machine locally on the network) before the user even realizes there's an incident.

    2.Policy Management& AD Sync: Grouping devices via Active Directory or Azure AD sync keeps onboarding predictable. Setting up peripheral control (blocking unauthorized USB drives) and web policy rules takes minutes rather than hours.

    3.Live Response CLI : Being able to remote into a machine command line directly through the Central web console to pull logs, kill rogue processes, or check registry keys- without disturbing the end user-saves a ton of desk visits.

    4.Tamper Protection: The central management of temper passwords prevents users (and standard malware) from just shutting off protection services locally.

    From an end-user / operator perspective:

    The local desktop client is mostly silent. It doesn't bombard users with constant pop-ups or unnecessary notifications during standard daily tasks.
    What do you dislike about the product?
    1. Agent Resource Consumption on Older Hardware: While modern core-i5/i7 laptops with 16 GB RAM handle the agent without sweat, older dual-core machines or devices with 8GB RAM hit noticeable CPU and disk I/O spikes during background deep scans or major engine updates.

    2. Granular Role-Based Access Control (RBAC): Admin permissions can feel a bit all-or-nothing. It would be nice to have more fine-gained custom roles for tier-1 helpdesk techs without giving them broad policy-editing privileges.

    3. Exclusion Workflow can be Tricky: Setting up file or folder exclusions- especially wildcard path exclusions requires multiple passes and testing to get right.

    4. Console Session Timeouts: The cloud console logs you out relatively quickly for security reasons. While understandable, it can be annoying when you're mid-troubleshooting and step away for a quick phone call.
    What problems is the product solving and how is that benefiting you?
    1. Ransomware Mitigation & Auto-Rollback : The CryptoGuard tech built into Intercept X has saved us from potential ransomware threats twice. It actively detects unauthorized file encryption, kills the process, and rolls back compromised local files from cached copies. That alone paid for the subscription.

    2. Reduced Helpdesk Overheads : Before moving to Sophos Central, keeping endpoint definitions updated across remote/hybrid works was a headache. Because Central is 100% cloud-hosted, machines stay updated wherever they have an internet connection-no VPN connection required.

    3. Faster Incident Investigation: The threat graph visualizations break down root analysis step-by-step (e.g., User opened suspicious email link -> Executable dropped in Temp folder -> process spawned), making it simple to explain security incidents to management or audit teams.
    Computer Software

    Simple, Interactive GUI with Solid Reporting and Great Value

    Reviewed on Aug 14, 2026
    Review provided by G2
    What do you like best about the product?
    It is simple, has an interactive GUI. I can find and fix stuff fast without digging through CLI. The reporting is solid, and the cost to feature ratio is hard to beat. Works well for SMBs and mid market deployment.
    What do you dislike about the product?
    The central management console could be a bit more slick and it sometimes takes time to load. Advanced routing and VPN debugging sometimes forces you to CLI. Upgrade paths can get tricky and difficult to locate. Good box in all but not flawless.
    What problems is the product solving and how is that benefiting you?
    The locking down remote access with solid VPN, keeping malware out with good IPS and web filtering feature, and making segmentation simple. One other benefit is less time managing separate boxes, faster triage with a very clean dashboard. it's easy enough for administrator intern to handle without calling me every five minutes.
    Antony M.

    Easy-to-Configure Firewall with Responsive Support and Great Value

    Reviewed on Aug 08, 2026
    Review provided by G2
    What do you like best about the product?
    The ease of operating and understanding the firewall, first time working on firewalls i used sophos and i managed to configure the firewall, sync with office365 and ldap for auth was a great with. their support desk responsive. and the cost is great for medium sized company
    What do you dislike about the product?
    challenges when running packet inspections and slow performance and high cpu usage
    What problems is the product solving and how is that benefiting you?
    We had challenges running ipsec tunnels on dynamic public ip's now we can centralize our servers at Head office or Azure
    Tim G.

    Centralized console everywhere for complete control of firewall and client

    Reviewed on Jul 29, 2026
    Review provided by G2
    What do you like best about the product?
    The centralized console is accessible from any device and anywhere, and allows for complete control over the status of the firewalls and clients.
    What do you dislike about the product?
    The access points have a cumbersome and slow management, and furthermore, they do not allow the creation of VLANs to segregate the networks.
    What problems is the product solving and how is that benefiting you?
    Perimeter security and client control.
    Prateek T.

    Synchronized Security and Sophos Central Make XGS a Huge Time-Saver

    Reviewed on Jul 25, 2026
    Review provided by G2
    What do you like best about the product?
    The biggest selling point for our team has been Synchronized Security(the security Heartbeat link between our endpoint agents and the firewall). If an endpoint drops to red health status due to active malware or suspicious outbound calls, the XGS box automatically isolates that device at the network layer before it can move laterally into our server VLANs. that alone has saved us hours of manual incident response .

    The integration with Sophos Central is easily the best future. Managing rules ,monitoring active traffic, and handling firmware updates across our XGS series appliances from a single dashboard saves our IT team a ton of time.
    The Synchronized security feature is also a massive win having the firewall automatically isolated a compromised endpoint before threat can move laterally across our network gives us great peace of mind.
    What do you dislike about the product?
    Local Web Admin UI: While Sophos Central is fast, logging directly into the local appliance web console can feel sluggish when you are pulling live packet traces, reviewing firewall rule hits, or digging into active connection tables under heavy load.
    On-Box Reporting: The built-in local reporting is adequate for basic bandwidth monitoring, but if you want deep, customizable historical reporting, you really have to rely on Sophos Central Centralized Reporting / Data Lake.
    The initial learning curve for custom NAT rules and object based policies can be a bit tricky if you are transitioning from older legacy firewalls . Also running full Deep Packet Inspection along with heavy SSL decryption requires proper sizing upfront, so you need to make sure you pick right XGS hardware model for your bandwidth needs.
    What problems is the product solving and how is that benefiting you?
    Lateral Movement Containment: Automated isolation of compromised hosts keeps minor endpoint infections from escalating into network-wide events.
    Multi-Site Management: Before upgrading , Managing remote VPN access and controlling bandwidth hogs across our [e.g., 2 office locations / 100+ employees] was over complicated . Sophos solved this by giving us seamless SSL VPN Deployment via Sophos connect and clear web filtering policies. It streamlined our daily network administration and improved overall threat visiblity.
    Bandwidth Optimization: Easily setting traffic-shaping rules for non-essential web traffic (like streaming services) during business hours ensures VoIP and critical cloud applications stay prioritized.
    Wlado R.

    Gateway VLAN fast and efficient, seamless integration with client and web app

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    Excellent performance in terms of speed when used as a VLAN gateway for network segregation. The integration with clients and web applications is functional and has proven effective.
    What do you dislike about the product?
    The Wi-Fi is slow and offers few segmentation possibilities. Also, managing Active Directory and configuring the SSL VPN are complicated.
    What problems is the product solving and how is that benefiting you?
    Effective perimeter security. Manage external access with dedicated logs. Web filtering.
    Wosha L.

    Excellent perimeter security and a fast, intuitive console

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    Firewall with excellent perimeter security and a fast, intuitive console that allows you to control everything easily. The connection with clients is also good.
    What do you dislike about the product?
    The Wi-Fi managed by the Access Points is slow in connecting devices and does not support VLAN management, limiting the possibility of segregation.
    What problems is the product solving and how is that benefiting you?
    Protection of clients and perimeter. Control of web applications.
    Ophelie B.

    Excellent integration with management endpoints and scripts

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    Integration with endpoints and scripts for management.
    What do you dislike about the product?
    Sophos access points do not ensure good network segregation.
    What problems is the product solving and how is that benefiting you?
    Integration between firewall and endpoint, with management through NAC and application filtering.
    Dheeraj S.

    Fantastic Synchronized Security and Centralized Cloud Management

    Reviewed on Jul 21, 2026
    Review provided by G2
    What do you like best about the product?
    Synchronized security The Automatic communication between the firewall and Sophos endpoint is fantastic if an endpoint gets infected the firewall instantly isolates it for the rest of the network.
    Sophos Central Management managing rules web filtering and site to site VPNs across multiple locations from one cloud dashboard is very convenient.
    Clear traffic Visibility the control Center dashboard gives an immediate view of bandwidth hogs suspicious traffic and application usage.
    Solid SD-Wan & Remote Access: Setting up IPsec/SSL VPNs for remote users and managing multi-WAN routing works reliably.
    What do you dislike about the product?
    Initial Setup Curve: Setting up advance features like web application Firewall (Waf) or complex NAT rules requires going through some technical documentation first.
    Firmware Update Timing: Rebooting for firmware updates can take a few minutes compared to simpler routers so maintenance window need to be planned carefully.
    What problems is the product solving and how is that benefiting you?
    NetworkThreat Containment : Prevents infected remote or local devices from moving laterally across corporate subnets.
    Bandwidth & Web Control: Blocks unauthorized streaming torrenting or malicious domains to keep critical applications running smoothly.
    Simplified Multi-sites Management: Eliminates the need to log into individual hardware boxes locally when pushing global policy updates.
    Computer Games

    Intuitive Interface, Strong Performance, and Helpful Support

    Reviewed on Jul 21, 2026
    Review provided by G2
    What do you like best about the product?
    I enjoy the interface; after a bit of adjusting, I was able to understand it quickly. It also performs very well in our environment. Although we have an enormous throughput, it has never bottlenecked. We’ve also had great support from Sophos, with the exception of one time, but switching technicians was straightforward and easy.
    What do you dislike about the product?
    I haven’t been able to fully understand how the AI detections in Sophos X Ops work in practice. It flags what I assume are false positives, and I haven’t had the chance to properly test the detection engine to confirm. Log research can also be very tedious. I’ve also had a lot of issues with syslog collection when trying to integrate it into our monitoring software.
    What problems is the product solving and how is that benefiting you?
    When we went through the initial onboarding, it was a more affordable solution than competitors like Fortinet. That said, when we first purchased it, a few features were missing; over time, though, updates have continued to add to the product.

    It’s also an excellent machine to keep updated. Being able to move between firmware images has been really useful for testing new environments.