XG To XGS
XG To XGS
Defence: Upgrade to
Sophos XGS Hardware
Now!
Sherif Saleh
Sophos System Engineer – Egypt & Levant
June 2024
Agenda
• Sophos Firewalls
• XGS Firewall High Performance
• Xstream Architecture Powerful Protection and Performance
• Enhanced Visibility and Control
• Sophos SD-WAN
• Sophos Firewall Add-on
• Sophos SD-RED
• Zero Trust Network Access Integration
• DNS Protection
• Sync-Security
• Active Threat Response
• Xstream License
• XG End-Of-Sale Announcement
• Migration Considerations
Sophos Firewall
Further XGS Series
2016: SFOS v16 2017: SFOS v17 2018: SFOS v17+ New licensing scheme
NGFW Architecture
Central Orchestration
Security Heartbeat
Sophos Firewall
Much more than a firewall
Services | Solutions | SASE
Powered by Xstream
Every model includes dedicated Xstream Flow
Processors
The flow processors accelerate trusted traffic
24/7 threat monitoring, flows
investigation, and response
They are programable so new features and
performance can be added over time
They deliver powerful protection at every price
point
Flexible Connectivity
Desktop models offer excellent value with all-
Full-scale incident response
performed in minutes in-one connectivity and options for wireless,
cellular and VDSL
Rackmount models offer extensive connectivity
options with modular bays for future expansion
10 High-end models offer redundancy of key
Dual Processor Architecture
SMB AND BRANCH OFFICE DISTRIBUTED EDGE ENTERPRISE and CAMPUS EDGE
DYNAMIC
THREAT FEEDS x86
CPU
API DPI ENGINE
ZTNA FIREWALL STACK ACTIVE THREAT RESPONSE DEEP PACKET INSPECTION
FASTPATH
DECRYPT/ENCRYPT ENGINE TRAFFIC ACCELERATION
TLS 1.3
All Ports/Applications
IPsec VPN Acceleration
ZTNA SD-WAN LOCAL APPS SAAS APPS
Sophos Firewall
Enhanced Visibility and Control
The Sophos Firewall Management Experience
22
Sophos Central Cloud Management For All Sophos Products
DSL
Firewall
MPLS Leased Line
Internet
Cable
Unlimited Applications
RETAIL BIOGAS CONSTRUCTION TURBINES EMERGENCY
REMOTE WORKERS
Sophos ZTNAaaS
SaaS APPS
Sophos Firewall Add-on
DNS Protection
Sophos DNS Protection
2 Minutes To Deploy
Be up and running in under two
minutes.
Threat Identified
1 XG Firewall identifies the presence of a threat or a
change in the health via Security Heartbeat
Security Heartbeat™
Security Heartbeat™
Endpoint Shares Application Information
2 Sophos Endpoint passes app name, path and even
category to XG Firewall for classification
Synchronized Security
Licensing
Protection Subscriptions Xstream Standard Available
Protection Protection Separately
Network Protection (Xstream TLS, DPI, IPS, X-Ops Feeds, Security Heartbeat, SD-RED Mgmt)
Web Protection (Xstream TLS, DPI, Web security and Control, Application Control)
Zero-Day Protection (Static ML-based and dynamic (sandboxing) file analysis, reporting)
Enhanced support (24x7 phone/email support, Advance RMA, required for firmware updates)
Sophos Central Email Advanced (Sophos Central antispam, AV, DLP, encryption)
Enhanced Plus Support Upgrade (VIP support, warranty for add-ons, TAM option)
SG is XG is
here here
End of
EOS EOS EOS
Sale
+1Y +2Y +3Y
EOS
Important Note:
Last order
The above timeline is not Product
date
sales end
applicable to XGS which will accessories
Single CPU Xstream Flow Processors High Performance TLS Inspection Added Built-in Interfaces
Single CPU on XG Series needs to Network co-processors augment Offloads crypto operations from the Provides optimal value and future
perform all crypto and DPI functions multi-core CPUs for max performance CPU for added performance scalability
Virtual FastPath Upgradable Performance Xstream FastPath Additional Flexi Port Modules
All traffic is processed by the CPU which Programmable flow processors enable Xstream hardware accelerated Easily upgrade your connectivity as
creates a performance bottleneck new features and better performance FastPath for offloading trusted traffic your network grows
49
Migration Considerations
XG to XGS Migration considerations
1. AP / RED Devices are not used in XGS
2. Flexiport are different
3. You can't migrate the license from XG to
XGS
4. You can migrate the configurations from
XG to XGS
Third Party Endorsements
The Top-Rated
Firewall
Network Firewall
Endpoint Protection
53
Contenders Leaders
The Top-Rated
MARKET PRESENCE
Firewall
Fortinet
Hillstone
Sophos named a 2023 Networks
MARKET AVERAGE
Huawei
Gartner Customers’ Choice
GajShield Infotech
Sophos
OVERALL EXPERIENCE
WatchGuard
Aspiring Established
55
Sophos Rated 4.7/5
in Network Firewalls
As mentioned in Gartner® Peer Insights™ Based on reviews in the last 12 months as of October 5, 2023
The GARTNER PEER INSIGHTS CUSTOMERS’ CHOICE badge is a trademark and service mark of Gartner, Inc. and/or
its affiliates and is used herein with permission. All rights reserved. Gartner Peer Insights content consists of the
opinions of individual end users based on their own experiences with the vendors listed on the platform, should not
be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not
endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied,