Firewall HA Cost: Sophos vs Fortinet

Firewall HA Cost: Sophos vs Fortinet

Posted by Saif Khan on 2025 Jan 31st

Most businesses that skip firewall high availability skip it for one reason. They assume a second firewall means paying twice for everything. On Sophos that assumption is wrong, and on Fortinet it is now wrong for a specific list of models. Here is what a redundant pair actually costs and how to deploy one properly.

What high availability does

A firewall in high availability is two units running as a pair. One passes traffic. The other holds a synchronized copy of the configuration and waits. If the active unit loses power, drops a disk, or fails to come back from a firmware update, the standby takes over and traffic keeps moving.

Sophos and Fortinet both support two arrangements. Active-passive is one unit working and one waiting. Active-active spreads processing across both. Active-passive is the common choice for small and mid-size deployments because it is simpler to reason about when something breaks at 2am.

What a firewall failure looks like without a pair

Network diagram showing a single firewall between the internet and the internal LAN, marked as failed, with both connections broken and all internal computers cut off
A single firewall sits between every user and everything they need. When it stops, they all stop.

The firewall is the one device every other device depends on. Email, VoIP, cloud applications, remote access, site to site VPN, card processing. All of it routes through the same box. When that box dies, the question is not whether work stops. It is how long it stops for.

Count the real timeline. You notice the outage, confirm the hardware is dead, open a support case, get the RMA approved, wait for shipping, rack the replacement, restore the configuration, then verify every VPN tunnel and rule came back. Even with next business day hardware support, two working days is a reasonable estimate. Over a holiday weekend it is longer.

What the same failure looks like with a pair

Network diagram showing two firewalls in a high availability pair, with the failed unit bypassed and the standby unit now carrying traffic between the internet and the internal LAN
The standby takes over. Users stay connected while the failed unit gets replaced on your schedule.

Failover happens in seconds. Long sessions such as a file copy or an active VoIP call may drop and reconnect, but staff generally notice a brief stutter rather than an outage. The failed unit gets replaced during a planned window instead of a panicked afternoon.

The licensing question, answered per vendor

This is the part that changes the budget, and the two vendors work differently.

Sophos XGS

On Sophos Firewall, only the active device requires a license subscription. Sophos documents that the passive device receives a copy of those subscriptions so it can take over processing if the active unit fails. The practical consequence is that a Sophos HA pair costs one extra appliance, not a second set of protection licenses.

One rule to get right: activate the subscriptions on the unit you intend to run as active, and turn HA on from that unit. Sophos is explicit that the subscriptions must live on the intended active device. Getting this backwards is the most common setup mistake we see.

For software and virtual deployments, you buy a single base license. Once that serial number is registered, Sophos Firewall handles creating the passive device.

Fortinet FortiGate

Fortinet has historically worked the opposite way. A FortiGate HA cluster requires two sets of licenses, one per unit, and every member must carry the same level of licensing. If one unit has a lower subscription than the other, the cluster drops to the lower level for everybody. Buying web filtering for only one unit means neither unit filters.

That changed for part of the range. Fortinet now offers HA-specific SKUs that let two units share a single subscription bundle, sold in pairs. The details matter, so check them against your model before assuming it applies:

Requirement Detail
Supported models FortiGate 40F, 40F-3G4G, 60F, 61F, 70F, 71F, 80F, 81F, 80F-BYPASS, 80F-DSL, 80F-POE, 81F-POE, 100F, 101F
FortiOS version 7.2.9, 7.4.6, 7.6.1 or later
Eligible bundles Enterprise Protection, UTP, ATP. No other subscriptions qualify
How it is ordered In pairs, as the HA SKU. It does not apply retroactively to units you already own
Cluster mode Active-passive

Side by side

  Sophos XGS Fortinet FortiGate
Second appliance Required Required
Second set of subscriptions Not required Required, unless you buy the HA SKU on a supported model
Applies to The XGS range Entry-level models on the list above
Mismatched licensing Passive mirrors the active unit Cluster drops to the lowest licensed member

Deployment practices worth following

  • Match the hardware. Both vendors require identical models running identical firmware. Fortinet also requires the same hardware generation, so a 90G and a 91G will not cluster together.
  • Give the heartbeat its own link. Use a dedicated port between the two units rather than sharing a link that also carries production traffic.
  • Size on TLS inspection throughput. Not firewall throughput. Once inspection is on, TLS is the number that decides whether the pair copes at peak.
  • Test the failover before you need it. Pull power from the active unit during a maintenance window and watch what actually happens. An untested pair is an assumption.
  • Do not forget the rest of the path. A firewall pair feeding a single switch moves the outage rather than removing it. Redundant uplinks and a second switch are the next question, not an afterthought.

Common questions

Does a Sophos HA pair need two sets of licenses?

No. On Sophos Firewall only the active device requires a license subscription, and the passive device holds a copy of those subscriptions so it can take over if the active unit fails. A Sophos HA pair costs one extra appliance rather than a second set of protection licenses.

Does a FortiGate HA cluster need two sets of licenses?

Usually yes. A FortiGate HA cluster requires two sets of licenses, one per unit, at the same level. The exception is Fortinet's HA-specific SKU, which lets two entry-level FortiGates share a single Enterprise, UTP or ATP bundle on FortiOS 7.2.9, 7.4.6, 7.6.1 or later.

How fast does firewall failover happen?

Seconds. Established sessions such as a large file transfer or an active VoIP call may drop and reconnect, but most users experience a brief pause rather than an outage.

Can two different firewall models run in HA together?

No. Both Sophos and Fortinet require both units to be the same model running the same firmware version. Fortinet additionally requires the same hardware generation.

Which Sophos XGS models support high availability?

All current XGS models support HA, from the desktop range of 88, 108, 118, 128 and 138 through the rackmount models up to the 8500.

Is active-active better than active-passive?

Not for most businesses. Active-active spreads processing across both units, which helps when a single unit cannot handle peak load. Active-passive is simpler to troubleshoot and is the usual choice for small and mid-size deployments.

Sizing a pair for your site

Tell us your internet speed, user count, and whether you inspect TLS. We will size the pair, quote both units, and set out exactly which subscriptions you need for Canada or the USA.

Get a sizing recommendation Compare Sophos XGS models

Licensing details reflect vendor documentation current at publication. Fortinet's HA SKU model list and FortiOS requirements change between releases, so confirm against your model before ordering.