Sophos XGS 2100 vs Fortinet, Meraki, Palo Alto
Posted by Saif Khan on 2026 Sep 12th
Sophos XGS 2100 vs Fortinet, Meraki and Palo Alto
A like-for-like look at the Sophos XGS 2100 against the FortiGate 100F, Cisco Meraki MX95 and Palo Alto PA-1410. The XGS 2100 publishes 30 Gbps firewall throughput, 5 Gbps threat protection and 1.1 Gbps of TLS inspection. Where a competitor leads, the table below says so.
One caveat before the numbers: vendors measure throughput differently, so these figures are not laboratory-equivalent. Use them to narrow the shortlist, then test on your own traffic.
Step up from a desktop firewall to a 1U rackmount, and the spec sheets get slippery. The Sophos XGS 2100 advertises 30 Gbps of firewall throughput; the Palo Alto next to it lists 8.9 Gbps; the Cisco Meraki lists 3 Gbps. Those gaps are mostly a measurement illusion, not a real one, and this guide untangles them so a mid-market office can pick the right 1U box. The four models below are the Sophos XGS 2100 with Xstream Protection against the closest rackmount units from Fortinet, Cisco Meraki, and Palo Alto, priced in USD.
Why the illusion? Sophos and Fortinet quote raw firewall throughput with large UDP packets, which produces big headline figures. Palo Alto quotes an application mix. Cisco Meraki quotes a stateful-firewall number for a cloud appliance. The one row that comes closest to comparable is threat protection with security switched on, and even there the mixes differ. Read that row, not the headline.
Sophos XGS 2100 and its 1U rivals
| Model | Firewall throughput | Threat / security throughput | TLS inspection | IPsec VPN | Managed by | Price (USD) |
|---|---|---|---|---|---|---|
| Sophos XGS 2100 (Xstream) | 30 Gbps | 5 Gbps Threat Protection | 1.1 Gbps, native | 17 Gbps | See current price | |
| Fortinet FortiGate 100F | 20 Gbps (UDP) | 1.0 Gbps Threat Protection | ~1.0 Gbps SSL | Vendor-published | FortiCloud / FortiManager | Quote (Nuformat) |
| Cisco Meraki MX95 | 3 Gbps (stateful) | ~1 Gbps Advanced Security | Not native (add-on) | ~1 Gbps | Meraki Dashboard (cloud) | Hardware + Meraki license (quote) |
| Palo Alto PA-1410 | 8.5-8.9 Gbps (appmix) | 3.2-4.2 Gbps Threat Prevention (appmix) | Yes (licensed) | 4.6 Gbps | Panorama | Quote (hardware + subscriptions) |
All figures vendor-published (sophos.com, fortinet.com, documentation.meraki.com, paloaltonetworks.com), measured by differing methods. USD, checked September 7, 2026. Palo Alto figures vary by PAN-OS revision.
Reading the table honestly
Notice something the marketing does not lead with: on the threat-protection row, the Palo Alto PA-1410 actually lists the highest number of the four. That is worth stating plainly rather than pretending Sophos wins on every line. Where the XGS 2100 pulls ahead is elsewhere: it inspects TLS natively at 1.1 Gbps, it bundles its security services under a single license, and it needs only one license in a high-availability pair where some competitors need two. For a mid-market office, licensing simplicity and bundled inspection often matter more day to day than a throughput row measured three different ways.
The alternatives in brief
FortiGate 100F. The mid-market Fortinet that most buyers cross-shop against the 2100, and one Nuformat can quote alongside it. Its threat-protection figure sits close to the Sophos, its firewall headline is lower, and, like Sophos, it bundles security and centralizes management. If you run FortiSwitch and FortiAP, the Security Fabric is a genuine draw.
Cisco Meraki MX95. A cloud-managed 1U aimed at larger branches, up to around 500 devices. The Meraki story is operational simplicity, everything in one dashboard, and it is a good one. The trade-offs carry up from the smaller models: a recurring license is mandatory, and HTTPS inspection is not native. If the reason you are looking at the 2100 is TLS inspection, the MX95 asks you to add an extension for it.
Palo Alto PA-1410. The strongest security-throughput number in this group on paper, in a 1U with PoE and SFP+ options. It fits an organization that has committed to Palo Alto and staffs Panorama and per-service licensing. As ever, its numbers use an application mix and its price arrives by quote, so plan the budget around the full stack, not the appliance.
Which 1U firewall fits?
- Want bundled security, native TLS inspection, and simple HA licensing: the Sophos XGS 2100 The XGS 2100 with a 1-year Xstream Protection subscription is priced on its product page, and we quote the appliance and licence together.
- Cross-shopping a bundled 1U with SD-WAN and a fabric, on one quote: the FortiGate 100F.
- Prioritizing pure cloud-dashboard management for a larger branch: the Meraki MX95, license and TLS-inspection caveats included.
- Chasing the top security-throughput figure and already invested in Palo Alto: the PA-1410.
Questions buyers ask about the 2100
Is the XGS 2100 really faster than a Palo Alto PA-1410?
On the raw firewall row it lists a much bigger number, but that uses large UDP packets. On threat protection with security enabled, the PA-1410 lists more. Neither is a clean win; the methods differ, so match the numbers to your traffic.
How is the XGS 2100 priced in USD?
The XGS 2100 with a 1-year Xstream Protection subscription is priced on its product page, and we quote the appliance and licence together. Request a full quote for the hardware-plus-subscription total.
Does the XGS 2100 inspect encrypted traffic natively?
Yes, at 1.1 Gbps of TLS inspection with Xstream Protection. Cisco Meraki does not inspect HTTPS natively at this tier.
Why does Sophos say it is cheaper to run in HA?
A Sophos XGS high-availability pair uses one security license, where some competitors require a license on each unit. Confirm the current licensing for any model before you buy.
Which of these can Nuformat sell me?
Sophos and Fortinet. Cisco Meraki and Palo Alto are here for comparison only.
Three ways to buy a Sophos XGS firewall
Sophos now sells the XGS and its Xstream Protection in more than one way, which is worth weighing before you commit:
- Buy outright, term license. Purchase the appliance with a 1, 3, or 5-year Xstream Protection subscription paid upfront, and own the hardware. The 12-month Xstream figure quoted here is this option.
- Own the hardware, license monthly (MSP Flex). Buy the appliance outright, then pay for the Xstream Protection license monthly through a Sophos MSP partner’s MSP Flex billing instead of a multi-year term upfront. Billing is monthly, in arrears based on usage.
- Hardware as a Service (HWaaS). Launched July 1, 2026 for MSPs in the US and Canada, HWaaS combines the appliance, standard shipping, and Xstream Protection into a single monthly price billed through MSP Flex. It carries a mandatory 12-month initial term, then continues month to month, on select XGS models.
MSP Flex and HWaaS are delivered through a Sophos MSP partner. Ask Nuformat which fits your budgeting.
Get a quote
Ask Nuformat to quote the Sophos XGS 2100 with Xstream Protection for your site, appliance and subscription together, sized for your throughput and user count. Serving Canada and the USA. Contact us.
Sources
- Sophos XGS Series datasheet (XGS 2100): sophos.com
- Fortinet FortiGate 100F datasheet: fortinet.com
- Cisco Meraki MX95 datasheet: documentation.meraki.com
- Palo Alto PA-1400 Series datasheet: paloaltonetworks.com
- Sophos firewalls at Nuformat

