SOPHOS XG3CTCHAU XGS 3300 Security Appliance
Sophos XGS Firewall Range – Next-Generation Network Security
Sophos XGS Firewalls combine high-performance networking, SD-WAN, VPN and advanced threat protection in a single security platform. Designed for organisations ranging from small offices and branch locations to distributed enterprises and large campuses, the Sophos XGS Series provides comprehensive visibility and control over users, applications, encrypted traffic and emerging cyber threats.
Every Sophos XGS appliance runs Sophos Firewall OS and incorporates the Sophos Xstream architecture, helping accelerate trusted traffic while reserving processing resources for encrypted traffic inspection and deep packet inspection. The range includes compact desktop firewalls, versatile 1U rackmount appliances and high-capacity 2U enterprise models, making it easier to select a firewall suited to the organisation’s connectivity, performance and resilience requirements.
High-Performance Sophos Next-Generation Firewalls
Sophos XGS Series firewalls are purpose-built to protect modern networks in which cloud applications, encrypted traffic, remote users and distributed locations have become commonplace.
Key capabilities across the Sophos XGS Firewall range include:
- Zone-based stateful firewalling, NAT, VLANs and advanced routing
- Integrated SD-WAN with performance-based link selection
- Site-to-site and remote-access IPsec and SSL VPN
- Xstream FastPath traffic acceleration
- TLS 1.3 inspection and streaming deep packet inspection when licensed
- Application identification and control
- Intrusion prevention and advanced threat intelligence
- Cloud-based management and reporting through Sophos Central
- High-availability options for improved business continuity
- Flexible copper, fibre, multi-gigabit and modular connectivity
- Optional Wi-Fi 6 on selected XGS desktop “w” models
- Optional 5G connectivity on selected second-generation desktop models
The current range extends from the fanless XGS 88 for small offices through to the XGS 8500 for demanding enterprise and campus-edge deployments.
Sophos Firewall Base Licence – What Is Included?
A Base Firewall Licence is included with every Sophos XGS hardware appliance. It provides the essential networking and firewall capabilities required to deploy the appliance as a router, firewall, VPN gateway and SD-WAN device.
The Sophos Firewall Base Licence includes:
- Zone-based stateful firewall
- Network routing and switching features
- Network Address Translation
- VLAN support
- Traffic shaping and Quality of Service
- Integrated SD-WAN capabilities
- Performance-based WAN link monitoring and selection
- WAN load balancing and failover
- Site-to-site IPsec and SSL VPN
- Remote-access VPN up to the appliance’s supported capacity
- Sophos Connect VPN client support
- SD-RED Layer 2 site-to-site tunnels
- Xstream architecture and Network Flow FastPath
- Built-in wireless functionality and legacy Sophos APX management where supported
- Local firewall configuration and core reporting capabilities
- High-availability functionality
- Firewall RED functionality
The Base Licence provides networking, VPN and stateful firewall functionality, but it should not be mistaken for a complete next-generation security subscription. Services such as intrusion prevention, web filtering, application control, malware scanning, zero-day sandboxing and cloud DNS protection require the appropriate security subscriptions.
A support subscription or another eligible firewall subscription is also required for firmware and feature updates, full Sophos technical support, Sophos Central firewall management and the standard allocation of Central Firewall Reporting.
Sophos Xstream Protection – Comprehensive Firewall Security
Sophos recommends adding the Xstream Protection bundle to obtain the broadest level of protection from an XGS Firewall. Xstream Protection combines the principal Sophos Firewall security subscriptions, centralised management features and Enhanced Support into one licence.
Network Protection
Network Protection adds:
- Next-generation intrusion prevention system
- Xstream TLS 1.3 inspection
- Streaming deep packet inspection
- Sophos X-Ops threat intelligence feeds
- Active Threat Response
- Sophos Security Heartbeat
- SD-RED device management
- Clientless HTML5 VPN
- Detailed network and threat reporting
The intrusion prevention system analyses traffic for exploits, attacks and suspicious activity, while Active Threat Response can block known indicators of compromise without requiring administrators to create conventional firewall rules.
Web and Application Protection
Web Protection provides:
- Web security and malware protection
- Category, URL and keyword-based web policies
- User- and group-based internet controls
- Application identification and control
- Synchronized Application Control
- Synchronized SD-WAN application identification
- Web and application activity reporting
- Xstream TLS and deep packet inspection
This allows administrators to control how users access websites, cloud services and network applications, including applications that would otherwise be difficult for a conventional firewall to identify.
Zero-Day Protection
Zero-Day Protection helps detect previously unknown or evasive threats through:
- Machine-learning file analysis
- Cloud-based sandboxing
- Dynamic run-time analysis of suspicious files
- Sophos threat intelligence
- Detailed malware and sandbox analysis reports
Potentially dangerous files can be analysed in an isolated cloud environment before they are allowed to reach users or internal systems.
DNS Protection
Xstream Protection includes Sophos DNS Protection, a cloud-based DNS security service that can block malicious, unwanted or non-compliant websites during domain resolution.
DNS Protection provides an additional security layer that can stop users and devices from connecting to known malicious destinations before a web session is established. This feature is included in the Xstream Protection bundle and is not sold as an individual Sophos Firewall subscription.
NDR Essentials and Additional Threat Feeds
Bundle-only capabilities include:
- Sophos NDR Essentials
- Sophos MDR and XDR threat feeds
- Support for third-party threat intelligence feeds
- Active Threat Response using additional indicators of compromise
Sophos NDR Essentials uses cloud-hosted, AI-assisted network detection to identify suspicious domains, domain-generation algorithms and potentially malicious encrypted payloads without placing the full analysis workload on the firewall.
Sophos Central Orchestration and Reporting
Xstream Protection also includes:
- Centralised firewall management
- Group firewall policy and configuration management
- Zero-touch firewall deployment
- Cloud backup management
- Firmware update scheduling
- SD-WAN and VPN orchestration
- MDR and XDR data-lake integration
- Central Firewall Reporting Advanced
- Up to 30 days of reporting data under typical traffic conditions
- Saved, scheduled and exportable reports
Enhanced Support
Enhanced Support is included for the subscription term and provides:
- 24/7 Sophos technical support
- Firmware and feature updates
- Advanced replacement warranty cover for the appliance during the licensed term
Email Protection, Web Server Protection and Enhanced Plus Support are not included in Xstream Protection and can be purchased separately where required.
Sophos Synchronized Security
Sophos Synchronized Security connects Sophos Firewall with Sophos-managed endpoints through Security Heartbeat. Instead of operating as separate security products, the firewall and endpoint agent continuously exchange information about device health, users, applications and detected threats.
When Sophos Endpoint identifies a compromised computer, Security Heartbeat can immediately notify the XGS Firewall. Firewall policies can then automatically restrict or isolate that device, helping prevent it from communicating with servers, other endpoints or external destinations while the threat is investigated and remediated.
Synchronized Security provides:
- Real-time sharing of endpoint health information
- Automatic isolation of compromised devices
- Protection against lateral movement within the network
- Active Threat Response
- Destination Heartbeat protection
- Synchronized Application Control
- Synchronized User ID
- Improved visibility across endpoint and network activity
- Faster investigation and coordinated remediation
This automated response reduces the time between detecting a threat and containing it. It also limits reliance on an administrator noticing an alert and manually creating firewall rules.
Enhance Sophos XGS Firewall with Sophos Endpoint
Sophos Endpoint is licensed separately from the firewall and Xstream Protection bundle. However, deploying Sophos Endpoint alongside an XGS Firewall significantly strengthens the organisation’s overall security posture.
The endpoint agent can observe processes, applications, users and potentially malicious behaviour directly on protected computers and servers. The firewall provides visibility and enforcement at the network boundary and between network zones. Together, they provide complementary layers of protection.
Benefits of combining Sophos XGS Firewall and Sophos Endpoint include:
- Endpoint and network telemetry shared through Sophos Central
- Automatic containment of infected or compromised devices
- Reduced opportunity for ransomware to spread
- Greater protection against lateral movement
- Accurate identification of applications using endpoint telemetry
- User identity sharing without a separate identity client
- Coordinated investigation across endpoint and firewall events
- Consistent policy and visibility from a single cloud platform
- Improved context for Sophos XDR or Sophos MDR investigations
Synchronized Application Control is particularly useful for encrypted, custom or previously unidentified applications. Sophos Endpoint identifies the application on the device and shares that information with the firewall, enabling more accurate application policies and reporting.
The result is an integrated cybersecurity ecosystem in which endpoint and network protection work together, providing faster threat response and greater visibility than isolated point products.
Sophos XGS Firewall Model Comparison
The following chart compares the key hardware and performance differences across the current Sophos XGS range. Performance figures are maximum laboratory results under Sophos test conditions; real-world throughput varies according to traffic profile, configuration, enabled security services and inspection policy.
|
Sophos XGS model |
Form factor |
Fixed ports / expansion slots (maximum ports) |
Firewall throughput |
IPsec VPN |
Threat protection |
TLS inspection |
Key hardware difference |
|---|---|---|---|---|---|---|---|
|
XGS 88 / 88w |
Desktop |
4 / 0 (4) |
9.9 Gbps |
6 Gbps |
2 Gbps |
600 Mbps |
4 × 2.5GbE; fanless; 88w adds Wi-Fi 6 |
|
XGS 108 / 108w |
Desktop |
7 / 0 (7) |
12.5 Gbps |
8.25 Gbps |
2.5 Gbps |
800 Mbps |
6 × 2.5GbE + 1 × SFP; fanless; optional second PSU; 108w adds Wi-Fi 6 |
|
XGS 118 / 118w |
Desktop |
10 / 1 (10) |
15.5 Gbps |
13 Gbps |
3.25 Gbps |
1.1 Gbps |
9 × 2.5GbE + 1 × SFP; optional 5G and second PSU; 118w adds Wi-Fi 6 |
|
XGS 128 / 128w |
Desktop |
10 / 1 (10) |
19.1 Gbps |
15.05 Gbps |
4 Gbps |
1.45 Gbps |
9 × 2.5GbE + 1 × SFP; optional 5G and second PSU; 128w adds Wi-Fi 6 |
|
XGS 138 |
Desktop |
8 / 1 (8) |
19.1 Gbps |
6.6 Gbps |
4.75 Gbps |
1.7 Gbps |
4 × GbE, 2 × 2.5GbE PoE and 2 × 10GbE SFP+; dedicated Xstream processor |
|
XGS 2100 |
1U short-depth |
10 / 1 (18) |
30 Gbps |
17 Gbps |
5 Gbps |
1.1 Gbps |
8 × GbE + 2 × SFP; one Flexi Port slot |
|
XGS 2300 |
1U short-depth |
10 / 1 (18) |
39 Gbps |
20.5 Gbps |
5.5 Gbps |
1.45 Gbps |
8 × GbE + 2 × SFP; one Flexi Port slot |
|
XGS 3100 |
1U short-depth |
12 / 1 (20) |
47 Gbps |
25 Gbps |
7.4 Gbps |
2.47 Gbps |
8 × GbE, 2 × SFP and 2 × 10GbE SFP+ |
|
XGS 3300 |
1U short-depth |
12 / 1 (20) |
58 Gbps |
31.1 Gbps |
10 Gbps |
3.13 Gbps |
8 × GbE, 2 × SFP and 2 × 10GbE SFP+ |
|
XGS 4300 |
1U full-depth |
12 / 2 (28) |
75 Gbps |
62.5 Gbps |
25.2 Gbps |
8 Gbps |
4 × GbE, 4 × 2.5GbE and 4 × 10GbE SFP+; two Flexi Port slots |
|
XGS 4500 |
1U full-depth |
12 / 2 (28) |
80 Gbps |
75.55 Gbps |
31.85 Gbps |
10.6 Gbps |
4 × GbE, 4 × 2.5GbE and 4 × 10GbE SFP+; optional internal second PSU |
|
XGS 5500 |
2U |
16 / 3 (48) |
100 Gbps |
92.5 Gbps |
46 Gbps |
13.5 Gbps |
8 × GbE + 8 × 10GbE SFP+; redundant PSUs, SSDs and fans |
|
XGS 6500 |
2U |
20 / 4 (68) |
120 Gbps |
109.8 Gbps |
53.5 Gbps |
16 Gbps |
8 × GbE + 12 × 10GbE SFP+; redundant PSUs, SSDs and fans |
|
XGS 7500 |
2U |
22 / 4 (70) |
160 Gbps |
117 Gbps |
70 Gbps |
19.5 Gbps |
8 × GbE, 12 × 10GbE SFP+ and 2 × QSFP28 up to 40Gbps; redundant NVMe storage |
|
XGS 8500 |
2U |
22 / 4 (70) |
190 Gbps |
141 Gbps |
92.5 Gbps |
24 Gbps |
8 × GbE, 12 × 10GbE SFP+ and 2 × QSFP28 up to 100Gbps; highest-capacity XGS model |
The XGS 88, 108, 118 and 128 are also available as “w” models with integrated dual-band Wi-Fi 6. The wired and wireless versions otherwise provide the same core firewall performance. The XGS 138 does not have an integrated wireless variant.
The XGS 88 does not support certain advanced functions, including on-box reporting, dual antivirus scanning, WAF antivirus scanning and email MTA functionality. Where these features are required, the XGS 108 or higher is recommended.
Choosing the Right Sophos XGS Firewall
Firewall sizing should be based on inspected traffic rather than internet connection speed alone. Important factors include:
- Number of users and devices
- Internet and inter-site connection speeds
- Volume of encrypted TLS traffic
- Required threat-protection throughput
- Number of VPN users and site-to-site tunnels
- Application and web-control requirements
- Need for copper, fibre, multi-gigabit or PoE interfaces
- High-availability and redundant-power requirements
- Expected business and network growth
- Required log retention and reporting capacity
For most deployments, threat-protection and TLS-inspection throughput provide a more realistic sizing reference than headline firewall throughput. Allowing capacity for traffic peaks, security inspection and future growth can also help maintain performance throughout the firewall’s service life.