Get Better High Performance Protection

A comprehensive suite of next-gen protection that stops network threats. Dead.

Stop unknown threats. Dead.

XG Firewall offers the best protection against the latest advanced threats like ransomware, cryptomining, bots, worms, hacks, breaches and APTs.

  • Powerful Sandstorm sandboxing
  • Deep learning with artificial intelligence
  • Top performing IPS
  • Advanced threat and botnet protection
  • Web protection with dual AV, JavaScript emulation and SSL inspection

An industry first, XG Firewall integrates Deep Learning technology into our Sophos Sandstorm sandboxing. It’s been developed by data scientists at SophosLabs to deliver the industry’s best detection rates without using signatures. It catches previously unseen malware lurking in suspicious payloads quickly and effectively. It’s just one of the ways that XG Firewall stops unknown threats dead in their tracks.

XG Firewall’s IPS engine stops the latest zero-day exploits against network vulnerabilities from penetrating your network without slowing you down. You get proven Next-Gen IPS protection that has stopped threats like Wanna and Petya. Dead.

XG Firewall integrates some of the best technology from our leading Intercept X next-gen endpoint protection like deep learning, exploit prevention and CryptoGuard Protection to identify malware exploits and ransomware before it gets on your network. Sophos Sandstorm provides the best prevention protection possible with deep behavioural, memory and network analysis of suspicious content during run time. It’s super aggressive cloud-based analysis is your best protection against today’s latest threats.

Powerful multi-layered, call-home protection combines analysis from DNS, IPS, web, and traffic filters to identify and block botnet and command-and-control (C&C) call-home attempts.

Advanced threats are instantly identified and if you’ve enabled Synchronized Security with Sophos Central Endpoints or Intercept X you can automatically isolate infected systems until they can be cleaned up.

Sophos' award-winning, high-performance behavioral anti-malware engine is backed by SophosLabs and a 30-year history of protecting enterprises from the latest threats.

Dual-engine scanning offers the option of scanning traffic with the Sophos engine for excellent performance and protection, or adding a second engine scan for even more protection.

Sophos Web Protection engine is backed by SophosLabs and includes innovative technologies like code emulation, behavioral analysis, live protection, and pharming protection to identify and block the latest web threats. Dead.

XG Firewall makes configuration easy, with pre-packaged Web policies activated in seconds, edited anytime, and simulated quickly and easily to verify or help troubleshoot policy settings.

XG Firewall high performance SSL inspection that ensures web threats and inappropriate content are not slipping through a key blind spot in most network traffic.

Certificate validation and protocol enforcement options ensure your network is protected from spoofing and that unwanted traffic trying to bypass filtering or traffic shaping is stopped. Dead.

Get Better Threat Visibility

Sophos XG Firewall provides unprecedented visibility into your network, users, and applications directly from the all-new control center. You also get rich on-box reporting and the option to add Sophos iView for centralized reporting across multiple firewalls.

- Select a feature on the Dashboard to learn more.

  • Sandstorm and Advanced Threats

    The Sandstorm widget provides an indication of suspect payloads and the sandboxing analysis results. Clicking it provides detailed reporting insights into suspicious file downloads.

    The ATP widget provides an immediate indication of the presence of advanced threats on your network like botnets. Clicking it will reveal helpful details about the infected system, including the hostname, IP address, and source of the malicious traffic.

  • Security Heartbeat™

    The Sophos Security Heartbeat widget indicates the health status of all your Sophos Central-managed endpoints. If any systems are running unwanted applications or infected, they will show here as yellow or red.

    Clicking the widget reveals full details on the affected computer, including the user, hostname, IP address, and even the process responsible, enabling you to quickly take action. You can also use Security Heartbeat status in your policies to limit access to network resources for affected systems.

  • System Panel

    The system panel displays the real-time status of system performance, services, connections, and other system parameters. Green indicates everything is fine, orange indicates a warning, and red indicates something needs immediate attention.

    Each item is clickable to reveal additional details and graphs, as well as helpful system and network tools you can use for troubleshooting purposes such as ping, traceroute, packet capture, command-line access, and much more.

  • Traffic Insight

    This provides an overview of traffic processed in the last 24 hours, including web activity, allowed and blocked apps and web categories, as well as network attacks.

    You can quickly determine when your peak traffic periods are and how effective your policies have been at blocking unwanted activity and traffic.

  • Top Risk Users

    Unique to Sophos, User Threat Quotient (UTQ) is an indication of a user’s risk level based on recent web and advanced threat activity. This widget is green when risk levels are low, and turns red when a threshold of risky activity is detected indicating the number of high-risk users.

    The score is analyzed over a seven day period, and clicking on it will take you directly to the detailed UTQ report.

  • Connections

    The connections widget shows the status of various connected devices and users, including Remote Ethernet Device (RED) VPN connections, pending and active wireless access points, remote SSL VPN connections, and the current live users count.

    Clicking the various components of this widget will take you directly to the respective setup or reporting screen.

  • Messages

    The messages panel displays important system notices, warnings, and alerts with blue, yellow, and red icons respectively. Examples include default password warnings, HTTPS and SSH WAN access warnings, registration notifications, license notifications, and firmware updates.

    Click any message to review the full details and take action.

  • Reports

    This panel displays the top five reports that may have data of interest or require action based on automatic background analysis. Examples include high-risk applications, objectionable websites, web users, intrusion attacks, web server attacks, and more.

    Clicking any of the listed reports will open the full report, or you can choose to download a PDF version.

  • Active Policies

    The Active Policies panel right on the control center indicates exactly how many policies you have of each type, how many are unused, disabled, changed, and recently added.

    Unused policies are a good indication of policies that may benefit from some housekeeping, as they can present potential openings or vulnerabilities in the network that are no longer required.

  • Navigation

    The menu items are logically organized, offering quick access to all areas of the system. In fact, you’re never more than two clicks from anywhere.

    The navigation provides immediate access to monitoring and analysis tools, all protection and policy settings, firewall configuration, and system settings.

  • Synchronized App Control

    This widget displays the number of previously unidentified apps that Sophos Synchronized App Control has discovered on your network including apps that are matched to known apps, new apps, and the total count of apps discovered.

    Click through to the Synchronized App Control screen where you can assign applications to categories and policies to get your network under control.

Get a Firewall That Thinks Like You

So you don’t need to think like a firewall.

We’ve rethought the way policies are managed. Sophos XG offers an all-new unified policy model that enables you to see and manage all your user, application and network policies in a single place.

Most firewall products will have you setting up and managing security across multiple modules or screens. Not Sophos. We provide a powerful unified security model that allows you to easily establish and manage your security posture in one place.

XG Firewall offers industry leading authentication options and enables user-level enforcement for threat protection, sandboxing, application control, traffic shaping, web filtering policy, IPS protection, Security HeartbeatTM and routing - all on a single screen to make management simpler and easier.

XG Firewall makes it easy to manage all your network security in one place including your network and user-based firewall rules alongside all your web application firewall protection for business applications and servers, as well as your NAT rules.

An industry first, Sophos Security Heartbeat links your endpoints and your firewall to combine their intelligence to immediately identify systems compromised by advanced threats, enabling you to establish policies that automatically isolate or limit infected systems until they can be cleaned up.

If you’re like most network admins, you’ve probably wondered whether you have too many firewall rules, and which ones are really necessary and which ones are not actually being used. With Sophos XG Firewall, you don’t need to wonder anymore.

Pre-defined policy templates let you protect common applications like Microsoft Exchange or Sharepoint fast. Simply select them from a list, provide some basic information and the template takes care of the rest. It sets all the inbound/ outbound firewall rules and security settings for you automatically.

Get the World’s Best Endpoint Protection

Sophos Intercept X is not only the world’s best endpoint protection, it integrates with XG Firewall in ways SonicWall just can’t match to provide Synchronized Security that delivers breakthrough benefits for network application visibility, health monitoring, and a coordinated defense against the latest threats and attacks.

But don’t take our word for it…

  Sophos Intercept X SonicWall’s OEM of SentinelOne
Forester WAVE
Didn’t meet criteria
Gartner EPP MQ
MRG Effitas Exploit Test
Top Ranked
Missed 1 of 35 Exploits
Missed 18 of 35
MRG Effitas Unknown
Malware and PUAs
Top Ranked
Blocked 99.2% of malware
Blocked 100% of PUAs
Blocked 85% of
malware Blocked 52.5%
of PUAs
SE Labs
Top Ranked
100% Total Accuracy
Not included

Sophos Intercept X

SonicWall’s OEM of SentinelOne

“No other company is close to delivering this type of communication between endpoint and network security products.”

Chris Christianson, vice president of security programs at IDC

Get Automated Incident Response

Sophos XG Firewall is the only network security solution that is able to fully identify the source of an infection on your network and automatically limit access to other network resources in response. This is made possible with our unique Sophos Security Heartbeat™ that shares telemetry and health status between Sophos endpoints and your firewall.

Monitor Network Health

XG Firewall not only monitors host network activity, but also receives health status directly from your endpoints so you have constant visibility into the health of your entire network.

Identify Infected Systems

XG Firewall instantly alerts you to compromised systems on your network with full details including the IP address, the user, and the process, so you're not left digging for information.

Automatically Isolate Infections

XG Firewall uniquely integrates the health of connected hosts into your firewall rules, enabling you to automatically limit access to sensitive network resources from any compromised system until it's cleaned up.

Why They Switched

Gartner, partners, and customers agree: Sophos XG Firewall is rated among the highest in the industry for security effectiveness, performance, ease-of use, and value.

What are you waiting for?

Get started today by planning your migration and seeing how XG Firewall can improve your network.