Upgrade a Legacy Firewall to Sophos XGS

Upgrade a Legacy Firewall to Sophos XGS

Posted by Saif Khan on 2023 Jan 2nd

Upgrade a legacy firewall to Sophos XGS

A legacy firewall passes traffic but cannot inspect most of it. Almost all web traffic is now encrypted, and a firewall without TLS inspection sees only that encrypted data moved, not what was inside it. That is the single biggest gap between an older appliance and a current next-generation firewall.

Five signs it is time

  • It is past end of life. The Sophos XG series reached end of life on 31 March 2025. An appliance without firmware and threat intelligence updates degrades every week.
  • TLS inspection is off. Many older firewalls technically support it but were never configured for it, or cannot handle the throughput. Check whether yours is actually inspecting encrypted traffic or just passing it.
  • Your internet connection outgrew it. A firewall sized for 100 Mbps becomes the bottleneck when you move to gigabit fibre.
  • You cannot run all the services you pay for. If enabling IPS or sandboxing slows the network, the appliance is undersized rather than misconfigured.
  • Cyber insurance is asking questions. Insurers increasingly ask about firewall age, supported status and whether TLS inspection is enabled.

What a next-generation firewall adds

Capability Legacy firewall Sophos XGS
Port and protocol filtering Yes Yes
TLS 1.3 inspection Often absent or disabled Xstream engine, hardware accelerated
Application control Limited Identifies applications regardless of port
Cloud sandboxing No Unknown files detonated before delivery
Intrusion prevention Signature-based if present Advanced IPS with current threat intelligence
Endpoint coordination No Synchronized Security isolates a compromised device automatically
SD-WAN and ZTNA No Included in both bundles

Size on TLS inspection, not firewall throughput. A datasheet showing 30 Gbps firewall throughput may only inspect 1.1 Gbps of encrypted traffic. Since most of your traffic is encrypted, the second number is the one that limits real-world performance. This is the most common sizing mistake we see.

Which Sophos XGS model replaces yours

Published Sophos figures. Match on TLS inspection throughput against your internet speed and user count.

Model Firewall TLS inspection Typical fit
XGS 88 9,900 Mbps 600 Mbps Smallest office or branch
XGS 108 12,500 Mbps 800 Mbps Small office
XGS 118 15,500 Mbps 1,100 Mbps Growing small business
XGS 128 19,100 Mbps 1,450 Mbps Busy small office
XGS 138 18,100 Mbps 1,700 Mbps Small site needing 10GbE uplinks
XGS 2100 30,000 Mbps 1,100 Mbps Mid-sized single site
XGS 2300 39,000 Mbps 1,450 Mbps Mid-market office
XGS 3100 47,000 Mbps 2470 Mbps Large site or campus
XGS 4300 75,000 Mbps 8,000 Mbps Data-centre edge
XGS 4500 80,000 Mbps 10,600 Mbps Top of the 1U range

Larger sites are covered by the 2U range, the XGS 5500 through 8500, up to 190 Gbps firewall throughput.

How the migration actually goes

  1. Export the current configuration. Sophos provides a migration tool for XG to XGS that carries rules, objects and policies across.
  2. Review the rules before importing. Most firewalls accumulate rules nobody remembers adding. A migration is the natural point to remove them rather than carrying them forward.
  3. Stage the new appliance alongside the old one and test with a small group first.
  4. Cut over out of hours. The switch itself takes minutes. The planning is what takes time.
  5. Enable TLS inspection deliberately. Start with a pilot group, add exclusions for applications that use certificate pinning, then widen.

That last step is where most upgrades stall. Businesses buy the capability and never switch it on, which leaves them with a modern appliance doing a legacy job.

Three ways to pay for it

  • Term subscription. Appliance and license bought together for 1, 3 or 5 years. Only this fixes your price for the period.
  • Own the hardware, license monthly. Buy the appliance, pay the subscription month to month through an MSP.
  • Hardware as a Service. Appliance and subscription on one monthly bill with nothing upfront. The MSP owns the hardware.

Frequently asked questions

When should I replace my firewall?

Replace it when it is past end of life, when it cannot inspect TLS traffic at your internet speed, or when enabling the security services you pay for slows the network. The Sophos XG series reached end of life on 31 March 2025, so any XG appliance still in service is running without updates.

What is the difference between a legacy firewall and a next-generation firewall?

A legacy firewall filters by port and protocol. A next-generation firewall adds TLS inspection, application awareness regardless of port, intrusion prevention with current threat intelligence, and cloud sandboxing. The practical difference is that a legacy firewall cannot see inside encrypted traffic, which is now the majority of what crosses it.

Can I keep my existing firewall rules when I upgrade?

Yes. Sophos provides a migration tool that carries rules, objects and policies from XG to XGS. It is worth reviewing the rule set before importing rather than after, because most firewalls accumulate rules nobody remembers adding.

How do I know which model to buy?

Size on TLS inspection throughput rather than raw firewall throughput, because almost all web traffic is encrypted. Match that figure against your internet speed and the services you intend to run. Sophos does not publish user counts per model, so any vendor quoting a simple user number is estimating.

How long does a firewall migration take?

The cutover itself takes minutes. Planning, rule review and staging usually take a few days depending on how complex the existing configuration is. Cutovers are normally scheduled out of hours.

What happens if I do nothing?

The firewall keeps passing traffic, so nothing appears broken. Threat intelligence, IPS signatures and sandboxing stop updating, which means it stops recognizing anything new. That gap widens every week and is invisible until something gets through.

Get your replacement sized and quoted

Nuformat is a Sophos partner serving Canada and the United States. Tell us your current model, internet speed and user count, and we will confirm which XGS replaces it, price the term against monthly billing, and reply in two to three business days. Request a quote.

Sophos XG end of life · Compare XGS models · All Sophos firewalls

Specifications as published by Sophos. Pricing and availability confirmed by Nuformat at the time of quotation.