Bernard Otieno - PeerSpot reviewer
Technical Engineer at Harnssen Group Limited
Reseller
Top 10
Easy to set up with good technical support and good stability
Pros and Cons
  • "We've deployed quite a number for our users and our customers, and the feedback is quite positive in terms of management and also administration."
  • "XG is at its end of life. People are moving to XGS."

What is most valuable?

I enjoy synchronized security, where you have to synchronize both the firewall and the endpoint. When I deploy a firewall, I integrate it with the endpoint so that they can send the security heartbeat from the endpoint to the firewall. In the Sophos firewall, there's deep inspection, which works quite well. Sophos has the web application firewall inbuilt. This is unlike other firewalls, where you have to integrate with another standalone web application firewall. Being inbuilt in Sophos, you just have to configure an application so that it's more of a policy, and you're good to go. It's pretty simple in terms of the user. 

We've deployed quite a number for our users and our customers, and the feedback is quite positive in terms of management and also administration.

The technical support is pretty good. 

The initial setup is easy.

There's quite a number of items on offer. When you look at Gartner, it's doing well. The uptake in the market has been wonderful and currently, it's competing with other top firewalls such as Check Point, Fortinet, and Palo Alto.

What needs improvement?

XG is at its end of life. People are moving to XGS. With those changes on the horizon, a client might end up in, maybe 10 years, having four or five appliances, which they might not use. I don't know what Sophos is doing to maybe change this. Right now, we've moved from XG to XGS.

Another feature, which might be good and which other vendors are maybe exploring is the NAC. Sophos doesn't have a NAC solution. 

Maybe they can improve on their WAF. Currently, they have the inbuilt. 

They could work on their SD-WAN solution. I have seen it. It's not that competitive compared to other vendors. We've had some device issues.

For how long have I used the solution?

I've been dealing with the solution for the last four years.

What do I think about the stability of the solution?

In terms of when it's in the network, it's stable compared to other firewalls, where I have had some issues. I had a case with another firewall, which the client changed to Sophos and it was not that stable as the client had to go and actually restart the firewall. The challenge comes in terms of stability when, let's say, the engineer doing the scoping does the round-sizing for the firewall. This causes the IPS to become overloaded or overworked, so it disconnects the traffic at the port level. In terms of stability, I might say sometimes we might experience challenges maybe when the sizing is not done correctly. That's why we might experience that disconnect at the interface level where the internet gets disconnected, however, that's the case of sizing, not the product itself. In terms of stability, it's stable in the network.

Buyer's Guide
Sophos XG
April 2024
Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
771,212 professionals have used our research since 2012.

How are customer service and support?

In terms of Sophos' support, they have been wonderful. I had a device issue and I found the return policy to be quite simple. 

Their technical support is pretty straightforward. When you raise a ticket, the feedback is immediate, and you are assigned a support person. It's been a wonderful experience.

Even to the end-user, it's a pretty straightforward system that they have. A user would just log into support.id, then key in their credentials and raise a support ticket. It's pretty simple.

Which solution did I use previously and why did I switch?

I'm also familiar with Check Point, FortiGate, and Palo Alto. We also used to use Sonic Wall, however, we've moved to Sophos.

How was the initial setup?

The initial setup is pretty straightforward. It's not overly complex.

Which other solutions did I evaluate?

I've compared Check Point, CloudGen Network Security, and Sophos XG previously for clients. Not being biased to any vendor, normally, in this region, what normally happens is the budget. You might recommend Check Point to a customer, however, Check Point is a bit expensive, so you might end up losing the deal. What you would recommend, is Check Point as the Quantum, as the firewall. Sophos is doing quite well in terms of the endpoint for the workstations and the servers, the physical and the virtual. Likely it would be a good idea to recommend Sophos Security. That said, if the client has the budget, you'd recommend Check Point as a firewall. It's always good to do a bit of comparison and advise the client as to what is best for them.

What other advice do I have?

We've actually deployed and supported quite a number of the products, from XG105 to XG3430.

Sophos is on-prem mostly, however, now there's another product for Sophos, for the endpoints, which is cloud-based.

I'd rate the solution at a ten out of ten. It's one of the best products. We have deployed quite a number of them - almost 20 - and I've not seen any of my clients complain.

Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
PeerSpot user
Senior Consultant at Wavednet Group
Consultant
Enhanced security features, easy to use for all users, and has informative reports
Pros and Cons
  • "The solution has very good security features, is easy to use for administrators and users, and has informative reports."
  • "I would like to see in future releases a tool to scan for malicious packets and give the location of where they are coming from."

What is our primary use case?

We are an IT solution company and we provide network security. This solution is used for securing your network.

What is most valuable?

The solution has very good security features, is easy to use for administrators and users, and has informative reports.

What needs improvement?

I would like to see in future releases a tool to scan for malicious packets and give the location of where they are coming from. Nowadays all over the world is suffering from ransomware threats. If they could map where those packets are coming from and make the packet monitoring more efficient it will be helpful to prevent more of these kinds of threats.

For how long have I used the solution?

I have been using the solution for approximately five years.

What do I think about the stability of the solution?

The solution has been highly stable.

Which solution did I use previously and why did I switch?

We have used SonicWall and Fortinet in the past.

How was the initial setup?

The installation is very easy for anyone. The configuration is straightforward, all the information is available through a quick Google search.

What's my experience with pricing, setup cost, and licensing?

The price can be a bit steep but for the number of features, it is worth it. Additionally, the enterprise version of this solution is priced well for all the features that you receive.

If you are thinking about implementing Fortinet, SonicWall, or any other product you will pay extra for additional security features and might need to purchase additional licenses. If they just spend a little more on this solution they will get the extra features for the same amount.

Which other solutions did I evaluate?

This solution has security features that in other solution you have to purchase them as add-ons, such as malware and email filters. Comparing this solution overall to competitors it is by far the best.

What other advice do I have?

I rate Sophos XG an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
Buyer's Guide
Sophos XG
April 2024
Learn what your peers think about Sophos XG. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
771,212 professionals have used our research since 2012.
IT Consultant at Crotus
Consultant
Email security features are good, but the technical support needs improvement
Pros and Cons
  • "We have found that the simplicity of the XG 210 is its most valuable feature."
  • "When I call, I have to wait at least one to two hours to reach them."

What is our primary use case?

Our primary use case for this solution is to act as the main broadband device in our data center. The XG 210 model is being used for a hospitality solution.

How has it helped my organization?

The main improvement for us is with our email. The email options and email security features are good. 

What is most valuable?

We have found that the simplicity of the XG 210 is its most valuable feature. There are a lot of options available for the default firewall rules, such as email and web, that are used to secure the network.

I like all of the options, but the most important thing is that it is easy to understand how to configure everything, compared to other firewalls.

What needs improvement?

We are having a lot of issues with conflicts and user sessions, and Sophos has suggested that we change the device to the XG 400.

Aside from these issues with scalability, the email security features are good, but there are not many options. We would like to know why an email is being blocked, and how we can allow delivery. It does not keep emails in the queue for delivery. It can only log whether it is delivered or not delivered. If I need more details then I have to log in using SSH to get that information.

When an email comes in from the outside it is detected. When we check the log it only tells us that it is not delivered. We would like to create an exception, but there are not many options available for this. For example, a domain space is not allowed. Only the user name can be used to do that. We need a domain-based exception for email.

Next, the XG 210 is easy to configure, but when we are looking for more details then we can only get this information through SSH. It is quite difficult. If we can get all of those details then it would help us to understand, so this needs to be improved.

There are a lot of options and it gets confusing sometimes. If they can give limited options, with more information, then it would be good for the large sites.

For how long have I used the solution?

Less than one year.

What do I think about the stability of the solution?

The product is stable, but by stable, I mean that we still have issues. The issues are more technical, which is why they suggest that we change the device to fix the problems.

What do I think about the scalability of the solution?

Our main data center has more than seventy servers that host a web server and internal applications. This is where we use the XG 400.

We have installed the XG 210 model at a smaller data center. We have between three and four hundred users at the most. However, because we have more than three hundred sessions, the vendor has suggested that we change to the XG 400. We do not yet know if this will fix our problem.

At our remote sites, we use the XG 135 model, and we do not have many issues.

How are customer service and technical support?

I am not sure why Sophos suggested using the XG 210 model after doing a site check, but we are facing issues and they suggested that we replace the model.

When I call, I have to wait for at least one to two hours to reach them. Sometimes they will pick up the call immediately, but most of the time they will not. I usually have to wait one hour before they pick up the phone.

When a ticket is created we have to wait three days before getting a reply from them. When they create a ticket for a critical issue, the response is delayed. This is a new device, and we expect support from Sophos. At least the partner should support the product, but the partners are always looking for money. Even if they deploy the device, for example, the XG 450, then they only offer support for one day. After that, there is no support.

Which solution did I use previously and why did I switch?

We have been using the Sophos XG 135 model at our remote sites and it works.

This year we deployed the XG 210 model at our data center, but prior to this we used Barracuda. We switched because Barracuda is too expensive. The options are very limited because you have to pay for each additional option. Each one represents a different service, like ADP (Active DDoS Prevention) or firewall. In contrast, Sophos is only a single payment, so we switched even though we lost some options that we liked.

How was the initial setup?

The initial setup is very easy.

Our deployment took only two to three days. The problem is that we had a lot of issues, especially with the email. The SMTP did not work, so I could not continue with the deployment. It took between fifteen and twenty days to resolve this. I do not know what they did to fix it, but we were delayed between twenty-five days and a month.

We had contacted the Sophos partner for help, but they were not able to fix our issue. After the problem was resolved I re-initiated the deployment. Only one staff member is required to maintain the solution.

What's my experience with pricing, setup cost, and licensing?

Even when you purchase the product from Sophos, they ask for a separate contract for support which is on an hourly basis.

For licensing the XG 210, we paid approximately $3000 for three years. There are no additional fees on top of this.

Which other solutions did I evaluate?

Other than the Barracuda and the Sophos models, I did not evaluate other solutions.

What other advice do I have?

Because of the problems that we are having, I cannot recommend this solution to anyone at this time.

I would rate this solution five out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Network Engineer at The Shri Ram School
Real User
Top 20
Improves the network security posture of organizations, but the support and web filtering capabilities must be improved
Pros and Cons
  • "IPS works smoothly."
  • "SD-WAN can be improved."

How has it helped my organization?

The product has improved our network security posture. We got some phishing and malware attacks. We found out that someone was attacking our network. Since we installed the solution, we are not facing any attacks.

What is most valuable?

IPS works smoothly. The policies and rules work fine. The network performance and reporting tools of Sophos XG are good.

What needs improvement?

We are facing a little bit of an issue with the product's web filtering capabilities. It must be improved. SD-WAN can be improved.

For how long have I used the solution?

I have been using the solution for almost two years.

What do I think about the stability of the solution?

I rate the tool’s stability a seven or eight out of ten.

What do I think about the scalability of the solution?

I rate the tool’s scalability a seven or eight out of ten. Almost 5000 people are using the solution in our organization. We have installed the firewall. It is always running.

How are customer service and support?

The support takes a lot of time to resolve issues.

How would you rate customer service and support?

Neutral

How was the initial setup?

I rate the ease of setup a seven out of ten. The deployment took a few weeks.

What about the implementation team?

The deployment was done in-house. We needed two to three people for the deployment.

What's my experience with pricing, setup cost, and licensing?

I rate the pricing a seven or eight out of ten.

What other advice do I have?

I will recommend the product to others. The solution is not extremely good, but it is good. Overall, I rate the product a seven or eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
CEO at a tech services company with 1-10 employees
Real User
Migration from pfSense or Astaro is easy
Pros and Cons
  • "The two most valuable feature of Sophos XG is, one the option to filter according to different applications and two, the integration with the Active Directory."
  • "Integration with Active Directory is not reliable."
  • "Over the last six months, we have noticed that the hardware is slow, especially the VPN connections."

What is our primary use case?

We are using Sophos XG, but not the latest version. The solution works as the main gateway. We are a small company of 250 employees so we also use the solution as a router.

The hardware and VPN connections are slow so we are planning on upgrading the solution. Next month we will be replacing the Sophos XG we have as it is reaching the end of life next year. We will be purchasing the XG 3000 to gain more options in the VPN tunnels.

What is most valuable?

The two most valuable feature of Sophos XG is, one the option to filter according to different applications and two, the integration with the Active Directory.

What needs improvement?

Over the last six months, we have noticed that the hardware is slow, especially the VPN connections.

Sophos would benefit if they could improve the integration with Active Directory. It does not function consistently and we have to reconfigure it to make it function again. 

Integration with IPA, which is like Active Directory for Linux servers, would be a nice feature to include.

For how long have I used the solution?

I have been using Sophos XG for three years.

What do I think about the stability of the solution?

This solution is very stable. We have not had any problems in the three years we have been using Sophos XG. We did have one infection that gained access to one server in the DMZ but it was because the rules were not well configured and not because of the product.

What do I think about the scalability of the solution?

We haven't had to scale the solution. 

How are customer service and support?

Support from Sophos XG has been fine for what we have required.

Which solution did I use previously and why did I switch?

We had been using Astaro. We selected Sophos XG because we knew it would be easy to set up and configure as the two solutions are similar.

How was the initial setup?

Previously we were working with Astaro, so the setup and configuration of Sophos XG was easy. The implementation took less than a month.

What about the implementation team?

The company that sold the firewall solution provided support hours while we were migrating the rules of our old firewall. They provided us with advice on some of the rules, especially on the routing to connect to a branch office.

What's my experience with pricing, setup cost, and licensing?

We purchase an annual standard license.

What other advice do I have?

I recommend Sophos XG if you are coming from pfSense or Astaro as the migration will be really easy. The learning path will also be easy. If you are coming from Barracuda or Cisco it will be more difficult especially the web interface of the firewall is not intuitive.

I would rate Sophos XG an 8 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Infrastructure/Telcom Coordinator at Schnellecke Group AG & Co. KG
Real User
The price is right and it's easy to manage, so it's a good fit for our current needs
Pros and Cons
  • "Sophos XG's price is right, and it's easy to manage. It's a good fit for our current needs at the moment."
  • "Sophos XG's user interface has some room for improvement."

What is our primary use case?

We're using Sophos XG within one business unit for security. We use it for the firewall and mapping some services.

What is most valuable?

Sophos XG's price is right, and it's easy to manage. It's a good fit for our current needs at the moment. 

What needs improvement?

Sophos XG's user interface has some room for improvement. 

For how long have I used the solution?

We started using Sophos XG in June of this year, so it has only been a few months. 

What do I think about the stability of the solution?

I think Sophos XG is stable.

What do I think about the scalability of the solution?

Sophos XG is scalable. We have about 600 users here in Mexico, and everyone is behind this solution. I think it's possible we might increase usage, and we've discussed this with our corporate office in Germany. We could decide to go with another product, but we might expand Sophos if it performs well.

How are customer service and support?

Support is one area where I have some issues. Sophos support isn't that good. 

Which solution did I use previously and why did I switch?

In some companies where I've worked, I used Fortinet and ASA with FirePOWER from Cisco. In some places, I used Meraki with the MX and the Advance Security licensing. I have some issues with other technologies. Last year, they had Sophos UTM on the devices, but there was an opportunity was to switch our clients to Sophos XG and try out the solution.

How was the initial setup?

Setting up Sophos XG is too easy. It took about two hours. The only part of the solution that I deployed was the firewalls. It's something I do all the time in my business unit, so it was quick. We have two people responsible for deployment and maintenance, including me. 

What about the implementation team?

I had some support from a partner.

What's my experience with pricing, setup cost, and licensing?

A Sophos XG license costs approximately $45,000 

What other advice do I have?

I rate Sophos XG nine out of 10. Our experience so far has been good, but maybe we'll come across another solution that's at the same or a higher level.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Manager of Information Technology at Sundown M Ranch
Real User
Plug-and-play with a modern interface and helpful technical support
Pros and Cons
  • "The initial setup is straightforward."
  • "I'd like to see better reporting. While the logs are great, the reports are not."

What is our primary use case?

We primarily use the solution as our firewall.

How has it helped my organization?

I'm able to have very granular control over my organization's input and output data that goes in and out of our networks.

What is most valuable?

The firewall portion of the solution is the best part The rest is really just fluff. 

The initial setup is straightforward.

We have found the stability to be quite good.

What needs improvement?

User management is the area that, by far, needs the most work. The way that they try to transparently utilize user groups from the active directory to the Sophos firewall is outdated.

I'd like to see them do a little bit better of a job with the content filtering. It has content filtering, however, it rarely works. Sometimes it just fails altogether. I'd like to see a better job done. 

I'd like to see better reporting. While the logs are great, the reports are not.

For how long have I used the solution?

I've been using the solution for six years at this point. 

What do I think about the stability of the solution?

The stability is great. There are no bugs or glitches and it doesn't crash or freeze. It's a reliable firewall. 

What do I think about the scalability of the solution?

The product is super scalable. If I had a giant organization, I'd have no problem putting the Sophos firewall in.

Right now, we have 155 on the solution. That's everyone from support to upper-level management. 

We use it every day.

We just recently upgraded. I have no reason or need to upgrade for years to come and therefore don't plan on scaling anytime soon.

How are customer service and support?

Technical support is fairly good. It's a pain to get ahold of them, however, once you get them, they're very thorough.

The only thing that s not so great is that sometimes they try to force me down to my reseller, whoever their partner is. I always have to make up a lie and say I already tried and only then will they help me. Besides that, it's not bad.

Which solution did I use previously and why did I switch?

I previously used Cyberoam. We really switched as Cyberoam was bought out by Sophos.

How was the initial setup?

The implementation process was pretty straightforward. Learning the ins and outs was a little complex. How, in terms of just getting it set up, I was able to get it set up in a couple of days.

Overall, the deployment took about three days. My strategy was, basically, going from my old Cyberoam to my new Sophos. I just copied each rule individually and tested them. Then I ran them in sync with each other for a couple of weeks. When I realized there were no problems, I pulled the Cyberoam out.

We have three people on staff that can handle deployment and maintenance responsibilities. I've got a system admin, myself, and a help desk/content specialist.

What about the implementation team?

I did not use an integrator, reseller, or consultant for deployment. I handled the process myself. 

What was our ROI?

From an ROI standpoint, the product I had before, even though they were basically the same thing, I found I was spending a lot of man-hours with it and calling support a lot and actually having to pay for support on the previous model. 

With this firewall, I rarely have to call support. When I do, it's free of charge. The ROI is 100% there. It might be a little more expensive up front, however, the quality is there for a medium-sized business.

What's my experience with pricing, setup cost, and licensing?

The licensing is based on a multi-year contract. It's a bit higher, in terms of price than other options. The billing process is pretty simple and straightforward. they don't have a complex licensing setup. 

Which other solutions did I evaluate?

I evaluated all the big players out there before choosing Sophos. I likely evaluated seven different options.

What other advice do I have?

I'm a customer and an end-user.

I'd advise those considering this product to stick with it and stay away from the fluff. For example, the Sophos Anti-Virus is not worth it. 

The firewall is fantastic. Definitely take their firewall courses, as there are going to be a lot of tasks that you feel should be easy and they're not. There's going to be a lot of troubleshooting. I've been working on it for five years and I still catch myself sometimes trying to figure out why a certain rule doesn't work doing this or that. Definitely take the training. I would highly recommend staying away from the other products.

I'd give the product an eight out of ten for a score. It does everything I need it to do. The user interface is very modern. It works. I was able to figure out some very advanced things. Even though it has a modern interface, I like the fact that I can always go into the console and it's a Linux box behind the scene - which is very nice for when you're trying to do very advanced tasks. For the most part, it was plug-and-play. The setup was really easy. The support is fantastic.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior Network Security Engineer | Project Manager at a consumer goods company with 10,001+ employees
Real User
Simple to use, easy installation, and performs well
Pros and Cons
  • "The solution has good performance and is easy to use."
  • "The solution could be more secure."

What is our primary use case?

We use Sophos XG for network threat protection in our data center.

What is most valuable?

The solution has good performance and is easy to use.

What needs improvement?

The solution could be more secure.

For how long have I used the solution?

I have been using Sophos XG for a few years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

We have approximately 100 users using this solution.

How was the initial setup?

The installation of Sophos XG is easy.

What about the implementation team?

 We have four technical engineers for installation and administrators for this equipment.

Which other solutions did I evaluate?

We have evaluated Palo Alto and FortiGate.

What other advice do I have?

We have replaced some of our hardware with Palo Alto and FortiGate solutions.

I am satisfied with this solution.

I rate Sophos XG an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Product Categories
Firewalls
Buyer's Guide
Download our free Sophos XG Report and get advice and tips from experienced pros sharing their opinions.