10 Gigabit Networks for Business (2026 Guide)
Posted by Saif Khan on 2026 Sep 10th
How a business moves large files at 10 Gbps
A single 4K video project, a large CAD assembly, or a nightly server backup can run into hundreds of gigabytes. When that traffic crawls, people sit waiting and billable work stalls. The answer is not a bigger firewall. It is putting that traffic on a 10 Gigabit switch layer where it never touches the firewall at all. A Sophos CS1010-8FP switch gives you eight 10GbE ports for the heavy workloads, a CS210-48FP gives you 48 access ports with PoE for everything else, an AP6 840E covers Wi-Fi 6E, and a Sophos XGS 128 secures the perimeter and segments the network. All four are managed from one console.
The mistake people make: sizing the firewall for internal traffic
The instinct is understandable. You have big files, so you look for a bigger firewall. But a firewall protects the boundary between your network and the internet. Traffic between two devices on your own LAN, an editing workstation and a NAS for example, does not pass through it at all if the network is designed properly.
So the question is not "how fast is my firewall". It is "how fast is the path between the machine that creates the file and the machine that stores it". That path runs through your switch.
This matters for cost. A firewall sized for internal throughput you never actually push through it is money spent in the wrong place. Put the speed where the traffic is.
What each device actually does
| Device | Role | Key interfaces |
|---|---|---|
| Sophos CS1010-8FP | The 10GbE core. Servers, NAS, and the workstations that move large files connect here. | 8 x 1/2.5/5/10 GE multi-gig copper, 4 x 1/10G SFP+, 120 Gbps switching capacity, 410W PoE++ |
| Sophos CS210-48FP | The access layer. Desks, phones, printers, cameras, and access points. | 32 x 1GbE, 16 x 2.5GbE, 4 x 10G SFP+ uplinks, 740W PoE |
| Sophos AP6 840E | Wi-Fi 6E for laptops, tablets, and mobile devices. | Tri-radio 2.4/5/6 GHz, 4x4:4 MIMO, 1 x 2.5 GE PoE++ uplink |
| Sophos XGS 128 | Perimeter security and segmentation. Inspects internet traffic, not internal file transfers. | 9 x 2.5GbE copper, 1 x SFP, 1.45 Gbps TLS inspection |
How the traffic actually flows
Three distinct paths, each sized for what it carries:
- Heavy internal traffic (the big one). Workstation to server to NAS, all connected to the CS1010-8FP. This runs at up to 10 Gbps per port, switch-local. It never reaches the firewall, so the firewall is never the bottleneck.
- General office traffic. Workstations, phones, and printers on the CS210-48FP, which uplinks to the CS1010 over a 10G SFP+ link. Plenty of headroom for everyday work.
- Internet traffic. Everything bound for the internet passes through the XGS 128, which inspects it, including encrypted traffic at up to 1.45 Gbps of TLS inspection. That is well beyond what a typical business internet connection delivers.
The design principle: heavy internal traffic stays on the switch fabric, and only internet traffic goes through the firewall.
Why the AP6 840E needs the right switch
The AP6 840E is the flagship Sophos access point, with tri-radio Wi-Fi 6/6E and 4x4:4 MIMO. It is also the only AP6 model that requires 802.3bt PoE++, drawing up to 45W to run all three radios at once. A standard PoE switch will not power it properly.
Both switches here handle it. The CS1010-8FP has a 410W budget across eight PoE++ ports and can power up to eight AP6 840E units. The CS210-48FP carries a 740W budget across 48 ports for the wider office.
One point worth being precise about: the AP6 840E uplink is a 2.5 GE port, not 10 GE. That is the right size for a Wi-Fi 6E access point, since no wireless client is going to saturate more. The 10GbE ports are for wired imaging gear.
When you do want 10 Gigabit at the firewall
Everything above assumes the heavy traffic stays on the LAN, which is the right design for most sites. But there are cases where you genuinely want 10 Gigabit through the firewall: a second site connected over a fast link, a DMZ holding a customer-facing application or file server, or a fibre internet service faster than 2.5 Gbps. For those, the XGS 128 is not the right model, and two upgrades give you real 10G interfaces.
| Model | 10 Gigabit capability | Price with 1-yr Xstream |
|---|---|---|
| XGS 128 | None. 9 x 2.5GbE copper, 1 x SFP (1G). | $3,027 |
| XGS 138 | 2 x SFP+ fibre (10G), plus 2 x 2.5GbE PoE copper. The affordable way to get 10G on a desktop firewall. | $4,187 |
| XGS 2100 | A FlexiPort slot that accepts a 4-port or 6-port 10G SFP+ module, so you choose how much 10G you need. | $7,685 |
The XGS 138 is the practical step up. For about $1,160 more than the 128, you get two SFP+ ports that run at 10 Gigabit, and it keeps the desktop form factor. Pair those SFP+ ports with the CS1010-8FP’s SFP+ uplinks and the firewall sits on the 10G fabric rather than beside it.
The XGS 2100 is the rackmount option, and it earns its price when you need more than two 10G ports or want bypass pairs for high availability. Its 4-port 10GbE SFP+ FlexiPort module is $1,777 on top of the appliance. Note that SFP+ ports need transceivers: 10GbE short range is $1,078, long range $1,407.
Which should you actually buy?
- Heavy traffic stays internal, internet under 2.5 Gbps: XGS 128 plus the CS1010. The firewall never sees the file transfers, so there is nothing to gain from paying more.
- You need 10G through the firewall, for a DMZ, a second site, or very fast fibre: XGS 138. Two SFP+ ports, desktop form factor, modest price step.
- Multi-site, high availability, or more than two 10G ports: XGS 2100 with a 10G FlexiPort module.
Where segmentation comes in
Speed is only half of it. Medical imaging systems and connected devices often run software that cannot be patched on a normal cycle, which makes network segmentation a practical necessity rather than a nice to have.
Because all four devices are managed from the same Sophos console, you can put production systems, staff workstations, and guest Wi-Fi on separate VLANs and enforce what may talk to what. If an endpoint is compromised, Active Threat Response lets the switch isolate that device automatically when it is paired with the Sophos Firewall, rather than waiting for someone to notice.
For any business handling sensitive or regulated data, that combination, fast internal transfer plus enforced separation, is the thing to aim for.
Keeping it running: on-site spares
A 10 Gigabit core is only useful while it is powered on. If the switch carrying your file transfers fails on a Tuesday morning, a standard advance-replacement process that ships a unit in a few business days is not much comfort, because the work stops in the meantime.
For sites where downtime is expensive, we recommend keeping a spare unit on site. It is a simple idea that removes the shipping window entirely:
- Swap in minutes, not days. A cold spare on the shelf means someone racks it, restores the configuration, and you are back, without waiting on a courier.
- Configuration is already in the cloud. Because Sophos switches, access points, and firewalls are managed centrally, a replacement can pull its configuration rather than being rebuilt by hand.
- The RMA runs in the background. You still claim the faulty unit under warranty, but that process no longer sits on the critical path.
- Spare the single points of failure first. Usually the core switch and the firewall. Access-layer switches and access points matter less if a failure only affects part of the floor.
Sophos switches include a limited lifetime warranty with the hardware purchase, and support subscriptions cover hardware replacement for the supported term. A spare sits on top of that, buying you time rather than replacing the warranty. Ask us to price spares alongside the main build and to advise which units are worth duplicating for your site.
What it costs
USD pricing from Nuformat, current at time of writing. A working build for a small business site:
| Component | Purpose | Price |
|---|---|---|
| Sophos CS1010-8FP, 1-yr support | 10GbE core for servers and workstations | $2,646 |
| Sophos CS210-48FP, 1-yr support | 48-port access layer, 740W PoE | $5,187 |
| Sophos AP6 840E, 1-yr support | Wi-Fi 6E, tri-radio | $1,490 |
| Sophos XGS 128 with Xstream, 1-yr | Perimeter security and segmentation | $3,027 |
Longer support and subscription terms lower the effective annual cost, and monthly licensing is available. Ask us to size it for your actual port count and device list rather than working from this example.
Who this is for
Any business where the bottleneck is machine-to-machine transfer rather than internet speed. Sophos lists the CS1010-8FP use cases as high-definition media streaming, large file and CAD transfer, video editing, server-to-server and server-to-NAS backup, and communication with 10-gigabit servers. In practice that means video and post-production houses, architecture and engineering firms, design and print studios, software teams with large build artefacts, imaging-heavy medical and dental practices, and any office running nightly backups that currently overrun their window.
Frequently asked questions
Does the Sophos XGS 128 have a 10GbE port?
No. The XGS 128 has nine 2.5GbE copper ports and one SFP port. It is not designed to be the 10 Gigabit path. In this architecture the 10GbE runs on the CS1010-8FP switch, and internal file transfers never pass through the firewall.
Can a small business really get 10 Gbps?
Yes, between devices on the switch. The Sophos CS1010-8FP provides eight 10GbE multi-gigabit copper ports and 120 Gbps of switching capacity. Connect your servers, NAS, and the workstations that move large files to it, and those transfers run at 10 Gbps, independent of your internet speed or firewall.
Can I get 10 Gigabit on the firewall itself?
Not on the XGS 128, which tops out at 2.5GbE. The XGS 138 has two SFP+ fibre ports that run at 10 Gigabit, and the rackmount XGS 2100 takes a FlexiPort module with four or six 10G SFP+ ports. Choose those if you need 10G for a DMZ, a second site, or internet faster than 2.5 Gbps.
Why not just buy a bigger firewall?
Because internal traffic between two devices on your LAN does not pass through the firewall, so paying for throughput you never use is money in the wrong place. Size the firewall for your internet connection and inspection needs, and the switch for internal transfer. If you do need 10G at the firewall, for a DMZ or a second site, step up to the XGS 138 or XGS 2100 rather than oversizing on throughput alone.
What switch does the AP6 840E need?
The AP6 840E requires 802.3bt PoE++ and draws up to 45W. Sophos specifies the CS210-8FP or CS1010-8FP switch, or a Sophos PoE++ 60W injector. The CS210-48FP, with its 740W budget, also supports PoE++ devices.
How many AP6 840E units can the CS1010-8FP power?
Up to eight. Its 410W PoE budget supports up to six 60W devices, or eight PoE++ devices with slightly lower draw, which is the case for the AP6 840E.
Should I keep a spare switch on site?
If downtime stops billable work, yes, particularly for the core switch and the firewall. A cold spare turns a multi-day shipping wait into a swap that takes minutes, and because the configuration lives in the Sophos cloud console the replacement can pull its settings rather than being rebuilt by hand. Ask Nuformat to quote spares with the main build.
Do I need Cat6 cabling for 10GbE?
Yes. Sophos notes that 10 GE is backward compatible with earlier Ethernet standards, provided the required Cat6 cabling is in place. Check your existing runs before assuming a switch upgrade alone will deliver 10 Gbps.
Can all of this be managed together?
Yes. The firewall, both switches, and the access point are managed from the same Sophos cloud console, and Active Threat Response can isolate a compromised device automatically when the switch is paired with the Sophos Firewall.
Get it sized for your site
Nuformat is a Sophos partner serving Canada and the United States. Tell us your device count, whether your cabling is Cat6, and what your heaviest internal transfers look like, and we will size the switch and firewall properly rather than overselling either. Contact Nuformat, or browse Sophos switches and Sophos XGS firewalls.
Sources
- Sophos Switch Series operating instructions, interface and PoE tables (docs.sophos.com)
- Sophos news: Turbocharge your network with our new 10-gigabit switch (news.sophos.com)
- Sophos AP6 840E technical specifications, PoE++ requirement
- Sophos XGS Series datasheet, XGS 128 interfaces
- Topology diagram - for reference


