Sophos XGS 3100 vs Fortinet, Meraki, Palo Alto
Posted by Saif Khan on 2026 Sep 13th
Sophos XGS 3100 vs Fortinet, Meraki and Palo Alto
A like-for-like look at the Sophos XGS 3100 against the FortiGate 200F, Cisco Meraki MX105 and Palo Alto PA-1410. The XGS 3100 publishes 47 Gbps firewall throughput, 7.4 Gbps threat protection and 2.47 Gbps of TLS inspection. Where a competitor leads, the table below says so.
One caveat before the numbers: vendors measure throughput differently, so these figures are not laboratory-equivalent. Use them to narrow the shortlist, then test on your own traffic.
Move into the Sophos XGS 3-series and one number jumps out: TLS inspection climbs to 2.47 Gbps on the 3100, more than double the entry 1U. For an office where most traffic is encrypted and you actually want to look inside it, that headroom is the whole reason to size up. Below, the XGS 3100 with Xstream Protection meets the nearest Fortinet, Cisco Meraki, and Palo Alto rackmounts, priced in USD.
A reminder that carries through every row: these are vendor-published figures on different tests, so read them as directional and match them to your traffic, not against each other.
Sophos XGS 3100 and its rivals
| Model | Firewall throughput | Threat / security throughput | TLS inspection | Managed by | Price (USD) |
|---|---|---|---|---|---|
| Sophos XGS 3100 (Xstream) | 47 Gbps | 7.4 Gbps Threat Protection | 2.47 Gbps, native | Sophos cloud console | See current price |
| Fortinet FortiGate 200F | 27 Gbps (UDP) | 3.0 Gbps Threat Protection | 4.0 Gbps SSL inspection | FortiCloud / FortiManager | Quote (Nuformat) |
| Cisco Meraki MX105 | 5 Gbps (stateful) | 2.5 Gbps Advanced Security (detection) | Not native (add-on) | Meraki Dashboard (cloud) | Hardware + license (quote) |
| Palo Alto PA-1410 | 8.5-8.9 Gbps (appmix) | 3.2-4.2 Gbps Threat Prevention | Yes (licensed) | Panorama | Quote |
All figures vendor-published (sophos.com, fortinet.com, documentation.meraki.com, paloaltonetworks.com), measured by differing methods. USD, checked September 7, 2026. Where a competitor figure is not confirmed in the current datasheet, it is marked as such rather than estimated.
The honest read
The 3100’s standout is that 2.47 Gbps of native TLS inspection, which is higher than the Fortinet SSL figure and does not require the extension that Cisco Meraki needs to inspect HTTPS at all. On raw threat protection the FortiGate 200F and Palo Alto still list more, so if a single number is your yardstick, note that. If encrypted-traffic inspection built into the box is what you are buying, the 3100 makes a strong case.
Why the 3-series exists
The jump from the 2-series to the 3100 is mostly about inspecting encrypted traffic at higher rates. If HTTPS makes up most of your traffic and you want the firewall to actually decrypt and inspect it, the 3100’s 2.47 Gbps of native TLS inspection is the reason to be here rather than a tier down. The Fortinet and Palo Alto alternatives inspect encrypted traffic too; Cisco Meraki, at this tier, still does not do it natively.
Questions buyers ask
Why does the XGS 3100 cost more than the 2-series?
Chiefly for higher inspected throughput, including 2.47 Gbps of TLS inspection. You are paying for decryption headroom, not a different feature set.
Can Cisco Meraki MX105 inspect HTTPS?
Not natively. It relies on the Umbrella SD-WAN extension or a third party, where the 3100 inspects TLS on the appliance.
Do the throughput numbers compare directly across vendors?
No. Sophos and Fortinet use large UDP packets, Palo Alto uses an application mix, and Cisco Meraki quotes stateful-firewall figures for a cloud appliance. Compare the security-enabled row and your traffic.
Which of these can Nuformat sell me?
Sophos and Fortinet. Cisco Meraki and Palo Alto are here for comparison only.
Three ways to buy a Sophos XGS firewall
Sophos now sells the XGS and its Xstream Protection in more than one way, which is worth weighing before you commit:
- Buy outright, term license. Purchase the appliance with a 1, 3, or 5-year Xstream Protection subscription paid upfront, and own the hardware. The 12-month Xstream figure quoted here is this option.
- Own the hardware, license monthly (MSP Flex). Buy the appliance outright, then pay for the Xstream Protection license monthly through a Sophos MSP partner’s MSP Flex billing instead of a multi-year term upfront. Billing is monthly, in arrears based on usage.
- Hardware as a Service (HWaaS). Launched July 1, 2026 for MSPs in the US and Canada, HWaaS combines the appliance, standard shipping, and Xstream Protection into a single monthly price billed through MSP Flex. It carries a mandatory 12-month initial term, then continues month to month, on select XGS models.
MSP Flex and HWaaS are delivered through a Sophos MSP partner. Ask Nuformat which fits your budgeting.
Get a quote
Ask Nuformat to quote the Sophos XGS 3100 with Xstream Protection, appliance and subscription together, sized for your throughput and users. Serving Canada and the USA. Contact us.
Sources
- Sophos XGS Series datasheet (XGS 3100): sophos.com
- Fortinet FortiGate datasheets: fortinet.com
- Cisco Meraki MX datasheets: documentation.meraki.com
- Palo Alto datasheets: paloaltonetworks.com
- Sophos firewalls at Nuformat

