Sophos XG Firewall (SFOS) boots into Failsafe Mode when one or more of its system components encounter an error. While in Failsafe Mode the below statements are true: The appliance is not in operable condition. The Web Admin Console of the appliance cannot be accessed. This Help provides information about Sophos XG Firewall (SFOS) software and virtual appliances and the step-by-step procedures for configuration. Can't find what you need? Try the following: Use the Search bar above. Go to the Support section for knowledge base articles and Sophos Community posts. Configure Sophos XG Firewall as DHCP Server. Configure Site-to-Site IPsec VPN between XG and UTM. Connect XG Firewall to Parent Proxy deployed in the Internal Network. Connect XG Firewall to Parent Proxy deployed on Internet. Establish IPSec Connection between XG Firewall and Checkpoint.
Sophos, a global leader in next-generation cybersecurity, today unveiled new XGS Series firewall appliances with unrivaled performance and advanced protection against cyberattacks. The new appliances feature industry-best Transport Layer Security (TLS) inspection, including native support for TLS 1.3, that is up to five times faster than other models available on the market today.
Dan Schiappa, chief product officer at Sophos, said, “Sophos Firewall XGS Series appliances represent the most significant hardware upgrade that we have ever released and introduce unmatched detection, protection and speed.
Sophos XG 135 rev.3 Next-Gen virtual private network firewall appliance bundle with a Rackmount kit (XG1DT3HEK+RM-SR-T6) SG 135 UTM hardware appliances are purpose-built devices with the latest technology to provide the ultimate in performance; Ideal for small business or branch offices to protect and are working on a tight budget. Anyone with an eligible Cyberoam or Sophos appliance can convert that appliance to run Sophos Firewall OS (SF-OS). The license migration is available for paid-for licenses only (i.e. Paid for appliances or subscriptions) – if you have free licenses such as UTM Home or partner licenses, you need to apply for a.
“Security teams can no longer afford to overlook encrypted traffic for fear of breaking something or hurting performance – there’s too much at risk.
“We’ve completely redesigned the Sophos Firewall hardware to handle the modern encrypted internet.
“Security teams now have the ability to easily inspect encrypted traffic and shine light on what was once a black hole, and they can confidently do so without compromising on performance.”
Cybercriminals Increasingly Using TLS to Avoid Detection
Sophos today also published new research, “Nearly Half of Malware Now Use TLS to Conceal Communications,” identifying a surge in cybercriminals using TLS in their attacks. The increasingly popular tactic is used by adversaries to encrypt and encapsulate the content of malicious communications to avoid detection as they carry out attacks.
In fact, 45% of malware detected by Sophos from January through March 2021 used TLS to conceal malicious communications. That’s a staggering rise from the 23% Sophos reported in early 2020.
Sophos Firewall Software
Sophos has also seen an increase in the use of TLS to carry out ransomware attacks in the past year, particularly with manually-deployed ransomware. The majority of malicious TLS traffic that Sophos has detected includes initial-compromise malware, such as loaders, droppers and document-based installers like BazarLoader, GoDrop and ZLoader.
“TLS has undoubtably changed the privacy of internet communications for the better, but for all the good it’s done, it’s also made it much easier for attackers to download and install malicious modules and exfiltrate stolen data – right under the noses of IT security teams and most security technologies,” said Schiappa.
“Attackers are taking advantage of TLS-protected web and cloud services for malware delivery and for command and control. Their initial compromise malware is simply the advance guard for major attacks, as they’re setting up camp for the heavy artillery that follows, like ransomware.”
Accelerating Threat Protection
Powered by Sophos Firewall’s Xstream architecture, XGS Series appliances deliver the industry’s best zero-day threat protection, identifying and stopping the most advanced known and potential threats – including ransomware.
Protection is fueled by powerful threat intelligence, available only through SophosLabs Intelix and based on petabytes of SophosLabs threat data. Suspicious files are safely detonated in SophosLabs Intelix virtual environments as well as subjected to in-depth static analysis for additional detection coverage and intelligence gathering.
New Xstream flow processors within the appliances automatically accelerate trusted traffic, such as software as a service (SaaS), software-defined wide-area network (SD-WAN) and cloud applications, providing maximum headroom for traffic requiring TLS and deep packet inspection.
This greatly reduces latency and improves overall performance for important business applications, particularly those using real-time data.
The Xstream flow processors are software programmable, allowing Sophos to offload additional traffic in the future. The flexibility to enhance and adapt connectivity on the hardware itself further protects customers’ hardware investment.
Sophos Free Firewall
Sophos provides unique and intuitive dashboard visibility of TLS traffic and inspection issues, and security administrators can add exceptions for problematic streams with one click. Performance is also optimized out of the box with an extensive set of rules that are updated and maintained by SophosLabs to exclude safe traffic from inspection.
Sophos Firewall XGS Series appliances and firmware are easily managed on the cloud-based Sophos Central platform alongside Sophos’ entire portfolio of next-generation cybersecurity solutions. Solutions share threat intelligence and automatically respond to security incidents through Sophos’ unique synchronized security approach. Integration with Sophos Managed Threat Response (MTR) further boosts protection with human analysis for 24/7 fully managed threat detection and response.
Availability
Sophos Firewall XGS Series desktop and most 1U rackmount appliances are available for immediate purchase exclusively through Sophos’ global channel of partners and managed service providers (MSPs). These models are ideally suited for small, medium and distributed organizations as an all-in-one network security solution with a strong price to performance ratio and diverse add-on connectivity options.
Additional models designed for enterprise edge environments requiring maximum throughput for more complex network configurations will be available in the coming weeks. Simplified licensing includes bundled protection with enhanced support.
What Analysts and Channel Partners Say
“Firewall appliances are evolving to secure newer use cases, including cloud and the sudden shift to a growing remote workforce,” said Frank Dickson, program vice president at IDC. “The elegance of Sophos Firewall’s Xstream dual processor architecture approach is its ability to accelerate trusted traffic from so-called ‘elephant flows’— large media streams, VoIP traffic and even cloud applications — to then leverage the general purpose CPU to perform appropriate resource-intensive processes, such as deep packet inspection and TLS inspection. The result is an adaptable network appliance designed to provide protection while meeting changing and accelerating business demands across a variety of use cases.”
“The new XGS Series firewall appliances are screaming fast with rock solid, unbreakable stability. We captured an immediate increase in performance that doubled our throughput, which completely blew us away. Sophos Firewall has always been industry best, but the XGS Series appliances are revolutionary and beyond compare with cutting-edge innovation that’s years ahead of other offerings,” said Sam Heard, president at Data Integrity Services.
“Sophos Firewall provides the protection our customers need as they increasingly move business critical applications to the cloud and adopt zero trust technologies. It’s a win-win for channel partners, who further benefit with tremendous growth opportunities to cross and up-sell across the entire suite of Sophos solutions and services.”
Sophos Firewall Cost
“Sophos is raising the bar and pushing the cybersecurity industry forward at warp speed with its new XGS Series appliances, which are nothing short of amazing,” said Karen Greer, CEO at Secure Content Technologies.
“Appliance installation is incredibly simple, and within minutes I could hear our technician yelling through the wall, ‘wow, this is fast!’ Sophos Firewall is effortlessly managed on Sophos Central, making it exponentially easier to secure and manage diverse and complex customer environments.
“Knowing that Sophos Firewall automatically shares threat intelligence with other solutions on the platform through Sophos’ synchronized security heartbeat feature is game changing, giving us complete confidence and peace of mind that our customers are protected – even the most evasive threats don’t stand a chance at getting by.”
Today we’re announcing a brand-new range of hardware appliances for Sophos Firewall OS, the XGS Series. This is not just a technology refresh; our firewall appliances have been completely reengineered and now come with a dual processor architecture to deliver a significant performance increase over previous models.
The new XGS Series appliances release with Sophos Firewall OS v18.5, have a new simplified licensing scheme, and as if that wasn’t enough, we’re also changing the overall product name from Sophos XG Firewall to Sophos Firewall.
Dual Processor Architecture
Every XGS Series appliance combines a multi-core x86 CPU with a dedicated Xstream Flow Processor for application acceleration. Xstream Flow Processors are Network Processing Units (NPUs) which now add a hardware layer FastPath to extend the Xstream architecture that we introduced in SFOS version 18.
Flexible to the core
One benefit of the hardware platform that we’ve chosen, is that our Xstream Flow Processors are programmable. This allows us to extend the offload capabilities in future software releases, providing additional performance improvements, even for things like crypto processes. This, combined with the ability to modify and extend connectivity on every appliance, delivers a truly future-proof solution which can adapt as the network, workforce and security infrastructure evolves.
Protection and Performance
The increase in performance varies by model and test but you’re likely to see at least a 2X performance increase over v18 running on XG Series hardware and numbers to meet or beat our key competitors on the all-important Price per Protected Mbps. The additional performance headroom allows customers to turn on essential protection, such as TLS Inspection, with the confidence that they’re removing a huge blind spot in their network visibility – which hackers are increasingly exploiting – whilst maintaining their network performance.
Sophos Firewall OS v18.5
The new appliances come with the latest v18.5 software release which not only provides support for the new hardware, but also includes all the 18.x maintenance releases since the v18 release with extensive security hardening features, VPN and SD-WAN enhancements, Central Management and Reporting capabilities, and many more improvements.
Note: 18.5 for all non-XGS Series customers is currently expected to be available in June.
Product naming and availability
The XGS Series model line-up is similar to what we offer with the XG Series:
- Desktop model numbers have been increased by ‘1’
- 1U and 2U rackmount model numbers have an added ‘0’
We’re launching all models over a period of about four to six weeks. All XGS Desktop and 1U 2xxx and 3xxx models are available from today, April 21st and the XGS 1U 4xxx and 2U models will be available from late May.
As actual availability can vary by model and region, please reach out to your local Sophos or distribution team for further details.
The XG Series models remain available for purchase.
Where to get more information
You can access all the updated resources for the Sophos Firewall and XGS Series launch, including a What’s New video, on the Partner Portal.
The web updates on sophos.com will be live in all core languages by 9am EDT/3pm CEST. The key pages for you to bookmark are sophos.com/firewall for the new main Sophos Firewall page and sophos.com/compare-xgs for the tech specs and details on the XGS Series.
A recording of the full launch SophSkills is available on the Partner Portal.
We wish you great success selling Sophos Firewall and the XGS Series and look forward to welcoming you to further webinars and events in the coming weeks.