Sophos Firewall XGS – Powerful Protection and Performance

Powerful Protection and Performance

The Sophos Firewall Xstream architecture is engineered to deliver extreme levels of visibility, protection, and performance to help address some of the greatest challenges facing network administrators today.

TLS 1.3 Inspection

According to the latest statistics, approximately 90% of web traffic is encrypted, making it invisible to most firewalls. An increasing amount of malware and potentially unwanted apps exploit the fact that organizations are simply not using SSL inspection. Network administrators’ main fears are that SSL inspection will have a performance impact or cause something to break, impacting the user experience. Sophos Firewall removes the blind spots caused by encrypted traffic by allowing you to use SSL inspection while maintaining performance efficiency.

Deep Packet Inspection

We believe you should never have to decide between security and performance. Sophos Firewall includes a highspeed deep packet inspection (DPI) engine to scan your traffic for threats without a proxy slowing down the process. The firewall stack can completely offload the processing to the DPI engine, significantly reducing latency and so improving overall efficiency. Sophos Firewall blocks the latest ransomware and breaches with high-performance streaming DPI including next-gen IPS, web protection, and app control, as well as deep learning and sandboxing powered by SophosLabs Intelix

Application Acceleration

A significant portion of your network traffic is important business application traffic destined for branch offices, remote users, or cloud application servers. This trusted traffic, which needs no additional security scanning for threats or malware, can be intelligently directed to the FastPath, reducing latency, and optimizing overall performance. This provides added capacity and headroom for traffic that does need deep packet inspection. Sophos Firewall accelerates your SaaS, SD-WAN, and cloud traffic such as VoIP, video, and other trusted applications automatically or via your own policies – putting them on the FastPath through the Xstream Flow Processor

Sophos-Firewall-XGS

SD-WAN

Managing application traffic routing over multiple WAN links, and interconnecting a distributed network are essential elements of any SD-WAN solution. Often these tasks are much more challenging than they should be. Sophos Firewall with Xstream SD-WAN provides a powerful, integrated SD-WAN solution, with performance-based link selection and routing, zero-impact transitions between links in the event of a disruption, central cloud-managed orchestration, and Xstream FastPath acceleration of VPN tunnel traffic, making it one of the best, most flexible SDWAN solutions available in a firewall today.

Sophos Central

Sophos Central is at the heart of everything we do. Our cloud management platform provides a single pane of glass to not only manage your firewalls, but also your full portfolio of Sophos security solutions

Sophos-firewall-xgs

Simply manage multiple firewalls

Sophos Central is the ultimate cloud management platform for all your Sophos products. It makes day-to-day setup, monitoring, and management of your Sophos Firewall easy. It also provides helpful features such as alerting, backup management, one-click firmware updates and rapid provisioning of new firewalls. Ì Manage all your Sophos Firewalls and other Sophos products from a single console Ì Configure changes and apply them to a group of firewalls or manage each firewall individually Ì Create a backup schedule and store up to five backups in the cloud Ì Schedule firmware updates across your entire network with just a few clicks

Firewall Reporting in the cloud

Sophos Central includes powerful reporting tools that enable you to visualize your network, web, application activity, and security over time. You get a flexible reporting experience that combines a variety of built-in reports with powerful tools to create your own custom reports, enabling you to report what you want how you want. Ì Increase your visibility into network activity through analytics Ì Analyze data to identify security gaps, suspicious user behavior or other events requiring policy changes Ì Use the pre-defined modules or customize each report for specific use cases

Synchronized Security

Security Heartbeat™: Your firewall and your endpoints are finally talking

Sophos Firewall is the only network security solution that is able to fully identify the user and source of an infection on your network, and automatically limit access to other network resources in response. This is made possible with our unique Sophos Security Heartbeat that shares telemetry and health status between Sophos endpoints and your firewall and integrates endpoint health into firewall rules to control access and isolate compromised systems. The good news is, this all happens automatically, and is successfully helping numerous businesses and organizations to save time and money in protecting their environments today.

Sophos-firewall-xgs

Synchronized Application Control

Using Security Heartbeat, we can do much more than just see the health status of an endpoint. We also have a solution to one of the biggest problems most network administrators face today – lack of visibility into network traffic. Synchronized Application Control utilizes the Heartbeat connections with Sophos endpoints to automatically identify, classify, and control application traffic. All encrypted, custom, evasive, and generic HTTP or HTTPS applications which are currently going unidentified will be revealed.

Lateral Movement Protection

Lateral Movement Protection automatically isolates compromised systems at every point in the network to stop attacks dead in their tracks. Healthy endpoints assist by ignoring all traffic from unhealthy endpoints, enabling complete isolation, even on the same network segment, to prevent threats and active adversaries from spreading or stealing data

Synchronized User ID

User authentication is critically important in a nextgeneration firewall but often challenging to implement in a seamless and transparent way. Synchronized User ID eliminates the need for client or server authentication agents by sharing user identity between the endpoint and the firewall through Security Heartbeat. It’s just another great benefit of having your firewall and endpoints integrated and sharing information

Sophos-firewall-xgs

Sophos XGS Series Appliances

All XGS Series firewall appliances are built upon a dual-processor architecture, combining a high-performance, multi-core CPU with a dedicated Xstream Flow Processor for targeted acceleration at the hardware level. This gives you all the flexibility and adaptability of an x86 based firewall plus a significant performance boost over legacy firewall designs

Sophos XGS Series Desktop: SMB and Branch Office: XGS 87 and XGS 87w; XGS 107, XGS 107w; XGS 116, XGS 116w; XGS 126, XGS 126w; XGS 136, XGS 136w

Sophos XGS Series 1U: Distributed Edge: XGS 2100, XGS 2300, XGS 3100, XGS 3300, XGS 4300, XGS 4300, XGS 4500

Sophos XGS Series 2U: Enterprise Edge: XGS 5500, XGS 6500

Download Full

 

We’re Ready To Help You

Get in touch with us today and let’s start transforming your business from the ground up.