SOPHOS XG3CTCHAU XGS 3300 Security Appliance

Please feel free to contact us about this item, and we will recommend an IT Sales and Service Provider in your area.


Resellers: for pricing and to place orders.

This item is not normally held in stock. We’ll order it in on request. Please contact us for estimated delivery time
In stock email will be sent.
Instock notification already exists.
Order SKU: Supplier Code:

Sophos XGS Firewall Range – Next-Generation Network Security

Sophos XGS Firewalls combine high-performance networking, SD-WAN, VPN and advanced threat protection in a single security platform. Designed for organisations ranging from small offices and branch locations to distributed enterprises and large campuses, the Sophos XGS Series provides comprehensive visibility and control over users, applications, encrypted traffic and emerging cyber threats.

Every Sophos XGS appliance runs Sophos Firewall OS and incorporates the Sophos Xstream architecture, helping accelerate trusted traffic while reserving processing resources for encrypted traffic inspection and deep packet inspection. The range includes compact desktop firewalls, versatile 1U rackmount appliances and high-capacity 2U enterprise models, making it easier to select a firewall suited to the organisation’s connectivity, performance and resilience requirements.

High-Performance Sophos Next-Generation Firewalls

Sophos XGS Series firewalls are purpose-built to protect modern networks in which cloud applications, encrypted traffic, remote users and distributed locations have become commonplace.

Key capabilities across the Sophos XGS Firewall range include:

  • Zone-based stateful firewalling, NAT, VLANs and advanced routing
  • Integrated SD-WAN with performance-based link selection
  • Site-to-site and remote-access IPsec and SSL VPN
  • Xstream FastPath traffic acceleration
  • TLS 1.3 inspection and streaming deep packet inspection when licensed
  • Application identification and control
  • Intrusion prevention and advanced threat intelligence
  • Cloud-based management and reporting through Sophos Central
  • High-availability options for improved business continuity
  • Flexible copper, fibre, multi-gigabit and modular connectivity
  • Optional Wi-Fi 6 on selected XGS desktop “w” models
  • Optional 5G connectivity on selected second-generation desktop models

The current range extends from the fanless XGS 88 for small offices through to the XGS 8500 for demanding enterprise and campus-edge deployments.

Sophos Firewall Base Licence – What Is Included?

A Base Firewall Licence is included with every Sophos XGS hardware appliance. It provides the essential networking and firewall capabilities required to deploy the appliance as a router, firewall, VPN gateway and SD-WAN device.

The Sophos Firewall Base Licence includes:

  • Zone-based stateful firewall
  • Network routing and switching features
  • Network Address Translation
  • VLAN support
  • Traffic shaping and Quality of Service
  • Integrated SD-WAN capabilities
  • Performance-based WAN link monitoring and selection
  • WAN load balancing and failover
  • Site-to-site IPsec and SSL VPN
  • Remote-access VPN up to the appliance’s supported capacity
  • Sophos Connect VPN client support
  • SD-RED Layer 2 site-to-site tunnels
  • Xstream architecture and Network Flow FastPath
  • Built-in wireless functionality and legacy Sophos APX management where supported
  • Local firewall configuration and core reporting capabilities
  • High-availability functionality
  • Firewall RED functionality

The Base Licence provides networking, VPN and stateful firewall functionality, but it should not be mistaken for a complete next-generation security subscription. Services such as intrusion prevention, web filtering, application control, malware scanning, zero-day sandboxing and cloud DNS protection require the appropriate security subscriptions.

A support subscription or another eligible firewall subscription is also required for firmware and feature updates, full Sophos technical support, Sophos Central firewall management and the standard allocation of Central Firewall Reporting.

Sophos Xstream Protection – Comprehensive Firewall Security

Sophos recommends adding the Xstream Protection bundle to obtain the broadest level of protection from an XGS Firewall. Xstream Protection combines the principal Sophos Firewall security subscriptions, centralised management features and Enhanced Support into one licence.

Network Protection

Network Protection adds:

  • Next-generation intrusion prevention system
  • Xstream TLS 1.3 inspection
  • Streaming deep packet inspection
  • Sophos X-Ops threat intelligence feeds
  • Active Threat Response
  • Sophos Security Heartbeat
  • SD-RED device management
  • Clientless HTML5 VPN
  • Detailed network and threat reporting

The intrusion prevention system analyses traffic for exploits, attacks and suspicious activity, while Active Threat Response can block known indicators of compromise without requiring administrators to create conventional firewall rules.

Web and Application Protection

Web Protection provides:

  • Web security and malware protection
  • Category, URL and keyword-based web policies
  • User- and group-based internet controls
  • Application identification and control
  • Synchronized Application Control
  • Synchronized SD-WAN application identification
  • Web and application activity reporting
  • Xstream TLS and deep packet inspection

This allows administrators to control how users access websites, cloud services and network applications, including applications that would otherwise be difficult for a conventional firewall to identify.

Zero-Day Protection

Zero-Day Protection helps detect previously unknown or evasive threats through:

  • Machine-learning file analysis
  • Cloud-based sandboxing
  • Dynamic run-time analysis of suspicious files
  • Sophos threat intelligence
  • Detailed malware and sandbox analysis reports

Potentially dangerous files can be analysed in an isolated cloud environment before they are allowed to reach users or internal systems.

DNS Protection

Xstream Protection includes Sophos DNS Protection, a cloud-based DNS security service that can block malicious, unwanted or non-compliant websites during domain resolution.

DNS Protection provides an additional security layer that can stop users and devices from connecting to known malicious destinations before a web session is established. This feature is included in the Xstream Protection bundle and is not sold as an individual Sophos Firewall subscription.

NDR Essentials and Additional Threat Feeds

Bundle-only capabilities include:

  • Sophos NDR Essentials
  • Sophos MDR and XDR threat feeds
  • Support for third-party threat intelligence feeds
  • Active Threat Response using additional indicators of compromise

Sophos NDR Essentials uses cloud-hosted, AI-assisted network detection to identify suspicious domains, domain-generation algorithms and potentially malicious encrypted payloads without placing the full analysis workload on the firewall.

Sophos Central Orchestration and Reporting

Xstream Protection also includes:

  • Centralised firewall management
  • Group firewall policy and configuration management
  • Zero-touch firewall deployment
  • Cloud backup management
  • Firmware update scheduling
  • SD-WAN and VPN orchestration
  • MDR and XDR data-lake integration
  • Central Firewall Reporting Advanced
  • Up to 30 days of reporting data under typical traffic conditions
  • Saved, scheduled and exportable reports

Enhanced Support

Enhanced Support is included for the subscription term and provides:

  • 24/7 Sophos technical support
  • Firmware and feature updates
  • Advanced replacement warranty cover for the appliance during the licensed term

Email Protection, Web Server Protection and Enhanced Plus Support are not included in Xstream Protection and can be purchased separately where required.

Sophos Synchronized Security

Sophos Synchronized Security connects Sophos Firewall with Sophos-managed endpoints through Security Heartbeat. Instead of operating as separate security products, the firewall and endpoint agent continuously exchange information about device health, users, applications and detected threats.

When Sophos Endpoint identifies a compromised computer, Security Heartbeat can immediately notify the XGS Firewall. Firewall policies can then automatically restrict or isolate that device, helping prevent it from communicating with servers, other endpoints or external destinations while the threat is investigated and remediated.

Synchronized Security provides:

  • Real-time sharing of endpoint health information
  • Automatic isolation of compromised devices
  • Protection against lateral movement within the network
  • Active Threat Response
  • Destination Heartbeat protection
  • Synchronized Application Control
  • Synchronized User ID
  • Improved visibility across endpoint and network activity
  • Faster investigation and coordinated remediation

This automated response reduces the time between detecting a threat and containing it. It also limits reliance on an administrator noticing an alert and manually creating firewall rules.

Enhance Sophos XGS Firewall with Sophos Endpoint

Sophos Endpoint is licensed separately from the firewall and Xstream Protection bundle. However, deploying Sophos Endpoint alongside an XGS Firewall significantly strengthens the organisation’s overall security posture.

The endpoint agent can observe processes, applications, users and potentially malicious behaviour directly on protected computers and servers. The firewall provides visibility and enforcement at the network boundary and between network zones. Together, they provide complementary layers of protection.

Benefits of combining Sophos XGS Firewall and Sophos Endpoint include:

  • Endpoint and network telemetry shared through Sophos Central
  • Automatic containment of infected or compromised devices
  • Reduced opportunity for ransomware to spread
  • Greater protection against lateral movement
  • Accurate identification of applications using endpoint telemetry
  • User identity sharing without a separate identity client
  • Coordinated investigation across endpoint and firewall events
  • Consistent policy and visibility from a single cloud platform
  • Improved context for Sophos XDR or Sophos MDR investigations

Synchronized Application Control is particularly useful for encrypted, custom or previously unidentified applications. Sophos Endpoint identifies the application on the device and shares that information with the firewall, enabling more accurate application policies and reporting.

The result is an integrated cybersecurity ecosystem in which endpoint and network protection work together, providing faster threat response and greater visibility than isolated point products.

Sophos XGS Firewall Model Comparison

The following chart compares the key hardware and performance differences across the current Sophos XGS range. Performance figures are maximum laboratory results under Sophos test conditions; real-world throughput varies according to traffic profile, configuration, enabled security services and inspection policy.

Sophos XGS model

Form factor

Fixed ports / expansion slots (maximum ports)

Firewall throughput

IPsec VPN

Threat protection

TLS inspection

Key hardware difference

XGS 88 / 88w

Desktop

4 / 0 (4)

9.9 Gbps

6 Gbps

2 Gbps

600 Mbps

4 × 2.5GbE; fanless; 88w adds Wi-Fi 6

XGS 108 / 108w

Desktop

7 / 0 (7)

12.5 Gbps

8.25 Gbps

2.5 Gbps

800 Mbps

6 × 2.5GbE + 1 × SFP; fanless; optional second PSU; 108w adds Wi-Fi 6

XGS 118 / 118w

Desktop

10 / 1 (10)

15.5 Gbps

13 Gbps

3.25 Gbps

1.1 Gbps

9 × 2.5GbE + 1 × SFP; optional 5G and second PSU; 118w adds Wi-Fi 6

XGS 128 / 128w

Desktop

10 / 1 (10)

19.1 Gbps

15.05 Gbps

4 Gbps

1.45 Gbps

9 × 2.5GbE + 1 × SFP; optional 5G and second PSU; 128w adds Wi-Fi 6

XGS 138

Desktop

8 / 1 (8)

19.1 Gbps

6.6 Gbps

4.75 Gbps

1.7 Gbps

4 × GbE, 2 × 2.5GbE PoE and 2 × 10GbE SFP+; dedicated Xstream processor

XGS 2100

1U short-depth

10 / 1 (18)

30 Gbps

17 Gbps

5 Gbps

1.1 Gbps

8 × GbE + 2 × SFP; one Flexi Port slot

XGS 2300

1U short-depth

10 / 1 (18)

39 Gbps

20.5 Gbps

5.5 Gbps

1.45 Gbps

8 × GbE + 2 × SFP; one Flexi Port slot

XGS 3100

1U short-depth

12 / 1 (20)

47 Gbps

25 Gbps

7.4 Gbps

2.47 Gbps

8 × GbE, 2 × SFP and 2 × 10GbE SFP+

XGS 3300

1U short-depth

12 / 1 (20)

58 Gbps

31.1 Gbps

10 Gbps

3.13 Gbps

8 × GbE, 2 × SFP and 2 × 10GbE SFP+

XGS 4300

1U full-depth

12 / 2 (28)

75 Gbps

62.5 Gbps

25.2 Gbps

8 Gbps

4 × GbE, 4 × 2.5GbE and 4 × 10GbE SFP+; two Flexi Port slots

XGS 4500

1U full-depth

12 / 2 (28)

80 Gbps

75.55 Gbps

31.85 Gbps

10.6 Gbps

4 × GbE, 4 × 2.5GbE and 4 × 10GbE SFP+; optional internal second PSU

XGS 5500

2U

16 / 3 (48)

100 Gbps

92.5 Gbps

46 Gbps

13.5 Gbps

8 × GbE + 8 × 10GbE SFP+; redundant PSUs, SSDs and fans

XGS 6500

2U

20 / 4 (68)

120 Gbps

109.8 Gbps

53.5 Gbps

16 Gbps

8 × GbE + 12 × 10GbE SFP+; redundant PSUs, SSDs and fans

XGS 7500

2U

22 / 4 (70)

160 Gbps

117 Gbps

70 Gbps

19.5 Gbps

8 × GbE, 12 × 10GbE SFP+ and 2 × QSFP28 up to 40Gbps; redundant NVMe storage

XGS 8500

2U

22 / 4 (70)

190 Gbps

141 Gbps

92.5 Gbps

24 Gbps

8 × GbE, 12 × 10GbE SFP+ and 2 × QSFP28 up to 100Gbps; highest-capacity XGS model

The XGS 88, 108, 118 and 128 are also available as “w” models with integrated dual-band Wi-Fi 6. The wired and wireless versions otherwise provide the same core firewall performance. The XGS 138 does not have an integrated wireless variant.

The XGS 88 does not support certain advanced functions, including on-box reporting, dual antivirus scanning, WAF antivirus scanning and email MTA functionality. Where these features are required, the XGS 108 or higher is recommended.

Choosing the Right Sophos XGS Firewall

Firewall sizing should be based on inspected traffic rather than internet connection speed alone. Important factors include:

  • Number of users and devices
  • Internet and inter-site connection speeds
  • Volume of encrypted TLS traffic
  • Required threat-protection throughput
  • Number of VPN users and site-to-site tunnels
  • Application and web-control requirements
  • Need for copper, fibre, multi-gigabit or PoE interfaces
  • High-availability and redundant-power requirements
  • Expected business and network growth
  • Required log retention and reporting capacity

For most deployments, threat-protection and TLS-inspection throughput provide a more realistic sizing reference than headline firewall throughput. Allowing capacity for traffic peaks, security inspection and future growth can also help maintain performance throughout the firewall’s service life.