XG Firewall logo

XG Firewall

by Sophos · Since 1985
No reviews yet
Active1+ countriesCloud
Quick facts
VendorSophos
Year launched1985
StatusActive
LocationThe Pentagon, Abingdon Science Park, Abingdon, Oxfordshire OX14 3YP, GB
Countries served1+
Languages11
Integrations
Free tier
Free trialYES
Contact salesYES

About XG Firewall

XG Firewall is a network security software from Sophos designed to protect organizations from online threats. It provides features such as advanced threat protection, web filtering, and intrusion prevention so businesses can secure their networks and manage internet usage effectively. The software allows users to monitor and control access to potentially harmful websites and applications. XG Firewall offers real-time visibility and reporting capabilities, making it easier for IT teams to respond to incidents quickly. Key capabilities: advanced threat protection web filtering intrusion prevention network traffic analysis user identity management Best for: IT professionals that need to secure networks and manage web access.

Sophos Firewall, the successor to XG Firewall, is a robust Next-Generation Firewall (NGFW) designed to provide comprehensive network protection across small to large organizations. Its standout feature, Synchronized Security, allows real-time integration with Sophos endpoints to automatically detect and isolate compromised systems, preventing lateral movement of threats like ransomware. The platform leverages the high-performance Xstream DPI engine for deep packet inspection, intelligent TLS decryption, and advanced web and application control, ensuring that encrypted traffic is thoroughly inspected without major performance degradation. Zero-day threat protection is strengthened through cloud-based sandboxing powered by SophosLabs Intelix, while SD-WAN capabilities offer performance-based routing and simplified VPN overlay orchestration for distributed or remote offices. The firewall is highly flexible in deployment, with hardware appliances, software installations on user-provided servers, virtual appliances for private clouds, and cloud-based virtual machines on AWS and Azure, all managed via a modern, web-based interface or centrally through Sophos Central for unified policy administration and zero-touch deployment.

Pros & Cons

What users like
  • +Strong integration that works seamlessly with the Sophos ecosystem including endpoints servers UTM and cloud management
  • +Ease of use with a user-friendly interface simple deployment and intuitive configuration
  • +Comprehensive security with antivirus IPS/IDS app and content filtering SD-WAN VPN orchestration and ZTNA
  • +Unlimited VPN options with no extra licensing required for VPN connections
  • +Centralized management where synchronization technology allows managing multiple firewalls from one console
What users flag
  • Logs and reporting limitations where reporting is not granular enough and competitors offer stronger analytics
  • Telemetry gaps with no third-party threat data ingestion such as SHA values
  • Interface issues where some users find it slow cumbersome or poorly designed for real-time traffic visibility
  • Update problems in older versions where past updates caused crashes and HA instability
  • Learning curve that can be complex for new admins and requires experience to configure effectively

Features

Key features

Active Threat Response (Synchronized Security)
Identifies and instantly blocks active threats using threat intelligence and coordinates automated response with other Sophos products (like Endpoint/Intercept X) to prevent lateral movement.
Xstream Architecture and Acceleration
Accelerates important SaaS, SD-WAN, VPN, and cloud traffic at the hardware or software level using a dedicated architecture.
Intelligent TLS 1.3 Decryption
Removes the enormous blind spot of encrypted traffic with fast, effective, and customizable intelligent Transport Layer Security inspection.
Cloud-Delivered Network Security Platform
Full integration with Sophos Central for Zero-Trust Network Access (ZTNA), DNS Protection, Zero-Day Threat Protection, and Network Detection and Response (NDR).
Xstream SD-WAN with Orchestration
Optimizes network performance using performance-based routing and enables easy, point-and-click setup of complex hub-and-spoke or full mesh overlay networks.
Single Cloud Management (Sophos Central)
Provides one console for managing all Sophos products (Firewall, ZTNA, Endpoint, etc.), cloud reporting, and zero-touch deployment.

Additional features

Automatic Threat Response
Automatically identifies, blocks, and coordinates an automated response to active threats.
Synchronized Security
Coordinates with other Sophos products (like Sophos Endpoint/Intercept X) to further isolate threats and prevent lateral movement.
Threat Intelligence Integration
Uses threat intelligence from SophosLabs, Sophos MDR analysts, or third-party sources to identify and block active threats.
Immediate Insights
Delivers immediate insights into compromised devices, users, and applications.
XGS Series Appliance Performance
Provides Xstream-accelerated performance for modern, encrypted networks.
Xstream Architecture
Accelerates and offloads important SaaS, SD-WAN, VPN, and cloud traffic.
Xstream Flow Processors
Integrated processors on some models perform Transport Layer Security (TLS) and Deep Packet Inspection (DPI).
Customizable Connectivity
Offers add-on modules for high-speed copper, fiber, Power over Ethernet (PoE), 5G, and Wi-Fi connectivity.
TLS 1.3 Decryption
Removes blind spots with intelligent, fast, and effective TLS inspection that supports the latest standards.
Deep Packet Inspection (DPI)
Stops ransomware and data breaches using high-performance DPI with next-gen intrusion prevention (IPS), web protection, and application control.
Deep Learning and Sandboxing
Uses deep learning and sandboxing powered by SophosLabs Intelix threat intelligence for zero-day protection and threat classification.
Application Boost
Accelerates SaaS, SD-WAN, VPN, and trusted cloud traffic automatically or via policy, utilizing the Xstream FastPath.
Xstream FastPath Acceleration (SD-WAN)
Accelerates SD-WAN IPsec VPN tunnel flows using hardware crypto capabilities.
Performance-Based Routing (SD-WAN)
Automatically optimizes traffic routing based on real-time WAN link metrics like latency, jitter, and packet loss.
Point-and-Click Orchestration (SD-WAN)
Easily sets up complex hub-and-spoke or full mesh SD-WAN overlay networks.
Cloud-Based Network Detection and Response (NDR)
Uses AI in the cloud to identify high-risk domains and encrypted payloads.
Instant High-Speed Blocking (DNS Protection)
Provides immediate blocking of the latest risky URLs via DNS Protection.
Zero-Day File Protection
Offers protection from new zero-day file-based threats using AI and cloud-based sandboxing.
Secure Application Access (ZTNA)
Makes applications invisible to hackers while providing secure access for remote workers with built-in Zero-Trust Network Access.
Cloud SD-WAN Tools
Provides easy cloud-hosted tools for securely interconnecting remote locations and public cloud infrastructure.

Pricing

Free trial
Free version
Request a quote
Promo Offer

Countries & Languages

1
Countries served
11
Interface languages
10
Billing currencies

Available in

All Countries.

Interface languages

GermanEnglishSpanishFrenchItalianJapaneseDutchPolishPortugueseRussianChinese

Billing currencies

🇺🇸USD🇪🇺EUR🇬🇧GBP🇦🇺AUD🇨🇦CAD🇯🇵JPY🇨🇭CHF🇸🇬SGD🇭🇰HKD🇿🇦ZAR

No reviews yet

Be the first to drop a review

Alternatives to XG Firewall

Nokia Network Software Suite logo

Nokia Network Software Suite

Nokia Network Software Suite is a network software platform from Nokia that supports operational efficiency…

UDM Pro logo

UDM Pro

UDM Pro is a centralized management solution for modern office IT systems. It excels by…

CIAgent logo

CIAgent

CIAGENT by SNMP Research is a specialized IT management solution designed to support network monitoring,…

Network Detective Pro logo

Network Detective Pro

Network Detective Pro is an IT assessment and reporting platform designed primarily for Managed Service…

I

Infiot

Endian Secure Digital Platform logo

Endian Secure Digital Platform

Compliance Support: Helps meet GDPR IEC 62443 and NIS2 regulatory requirements

Often compared with XG Firewall

Compare any two tools →
Nokia Network Software Suite logo
Nokia Network Software Suite
Network Security
0.0
UDM Pro logo
UDM Pro
IT Management
0.0
CIAgent logo
CIAgent
IT Management
0.0
Network Detective Pro logo
Network Detective Pro
Managed Service Providers (MSP)
0.0