Upgrade a Legacy Firewall to Sophos XGS
Posted by Saif Khan on 2023 Jan 2nd
Upgrade a legacy firewall to Sophos XGS
A legacy firewall passes traffic but cannot inspect most of it. Almost all web traffic is now encrypted, and a firewall without TLS inspection sees only that encrypted data moved, not what was inside it. That is the single biggest gap between an older appliance and a current next-generation firewall.
Five signs it is time
- It is past end of life. The Sophos XG series reached end of life on 31 March 2025. An appliance without firmware and threat intelligence updates degrades every week.
- TLS inspection is off. Many older firewalls technically support it but were never configured for it, or cannot handle the throughput. Check whether yours is actually inspecting encrypted traffic or just passing it.
- Your internet connection outgrew it. A firewall sized for 100 Mbps becomes the bottleneck when you move to gigabit fibre.
- You cannot run all the services you pay for. If enabling IPS or sandboxing slows the network, the appliance is undersized rather than misconfigured.
- Cyber insurance is asking questions. Insurers increasingly ask about firewall age, supported status and whether TLS inspection is enabled.
What a next-generation firewall adds
| Capability | Legacy firewall | Sophos XGS |
|---|---|---|
| Port and protocol filtering | Yes | Yes |
| TLS 1.3 inspection | Often absent or disabled | Xstream engine, hardware accelerated |
| Application control | Limited | Identifies applications regardless of port |
| Cloud sandboxing | No | Unknown files detonated before delivery |
| Intrusion prevention | Signature-based if present | Advanced IPS with current threat intelligence |
| Endpoint coordination | No | Synchronized Security isolates a compromised device automatically |
| SD-WAN and ZTNA | No | Included in both bundles |
Size on TLS inspection, not firewall throughput. A datasheet showing 30 Gbps firewall throughput may only inspect 1.1 Gbps of encrypted traffic. Since most of your traffic is encrypted, the second number is the one that limits real-world performance. This is the most common sizing mistake we see.
Which Sophos XGS model replaces yours
Published Sophos figures. Match on TLS inspection throughput against your internet speed and user count.
| Model | Firewall | TLS inspection | Typical fit |
|---|---|---|---|
| XGS 88 | 9,900 Mbps | 600 Mbps | Smallest office or branch |
| XGS 108 | 12,500 Mbps | 800 Mbps | Small office |
| XGS 118 | 15,500 Mbps | 1,100 Mbps | Growing small business |
| XGS 128 | 19,100 Mbps | 1,450 Mbps | Busy small office |
| XGS 138 | 18,100 Mbps | 1,700 Mbps | Small site needing 10GbE uplinks |
| XGS 2100 | 30,000 Mbps | 1,100 Mbps | Mid-sized single site |
| XGS 2300 | 39,000 Mbps | 1,450 Mbps | Mid-market office |
| XGS 3100 | 47,000 Mbps | 2470 Mbps | Large site or campus |
| XGS 4300 | 75,000 Mbps | 8,000 Mbps | Data-centre edge |
| XGS 4500 | 80,000 Mbps | 10,600 Mbps | Top of the 1U range |
Larger sites are covered by the 2U range, the XGS 5500 through 8500, up to 190 Gbps firewall throughput.
How the migration actually goes
- Export the current configuration. Sophos provides a migration tool for XG to XGS that carries rules, objects and policies across.
- Review the rules before importing. Most firewalls accumulate rules nobody remembers adding. A migration is the natural point to remove them rather than carrying them forward.
- Stage the new appliance alongside the old one and test with a small group first.
- Cut over out of hours. The switch itself takes minutes. The planning is what takes time.
- Enable TLS inspection deliberately. Start with a pilot group, add exclusions for applications that use certificate pinning, then widen.
That last step is where most upgrades stall. Businesses buy the capability and never switch it on, which leaves them with a modern appliance doing a legacy job.
Three ways to pay for it
- Term subscription. Appliance and license bought together for 1, 3 or 5 years. Only this fixes your price for the period.
- Own the hardware, license monthly. Buy the appliance, pay the subscription month to month through an MSP.
- Hardware as a Service. Appliance and subscription on one monthly bill with nothing upfront. The MSP owns the hardware.
Frequently asked questions
When should I replace my firewall?
Replace it when it is past end of life, when it cannot inspect TLS traffic at your internet speed, or when enabling the security services you pay for slows the network. The Sophos XG series reached end of life on 31 March 2025, so any XG appliance still in service is running without updates.
What is the difference between a legacy firewall and a next-generation firewall?
A legacy firewall filters by port and protocol. A next-generation firewall adds TLS inspection, application awareness regardless of port, intrusion prevention with current threat intelligence, and cloud sandboxing. The practical difference is that a legacy firewall cannot see inside encrypted traffic, which is now the majority of what crosses it.
Can I keep my existing firewall rules when I upgrade?
Yes. Sophos provides a migration tool that carries rules, objects and policies from XG to XGS. It is worth reviewing the rule set before importing rather than after, because most firewalls accumulate rules nobody remembers adding.
How do I know which model to buy?
Size on TLS inspection throughput rather than raw firewall throughput, because almost all web traffic is encrypted. Match that figure against your internet speed and the services you intend to run. Sophos does not publish user counts per model, so any vendor quoting a simple user number is estimating.
How long does a firewall migration take?
The cutover itself takes minutes. Planning, rule review and staging usually take a few days depending on how complex the existing configuration is. Cutovers are normally scheduled out of hours.
What happens if I do nothing?
The firewall keeps passing traffic, so nothing appears broken. Threat intelligence, IPS signatures and sandboxing stop updating, which means it stops recognizing anything new. That gap widens every week and is invisible until something gets through.
Get your replacement sized and quoted
Nuformat is a Sophos partner serving Canada and the United States. Tell us your current model, internet speed and user count, and we will confirm which XGS replaces it, price the term against monthly billing, and reply in two to three business days. Request a quote.
Sophos XG end of life · Compare XGS models · All Sophos firewalls
Specifications as published by Sophos. Pricing and availability confirmed by Nuformat at the time of quotation.

