Glossary · 41 terms

Firewall and cybersecurity terms in plain English

The words on datasheets, quotes and insurance forms, explained without jargon. Each entry says what the term means and why it matters when you buy, with diagrams for the ideas that are easier to see than to read.

How a firewall is sized

Firewalls are sized by how much traffic they can check, not by headcount. These are the figures on every datasheet and in our sizer.

Mbps and Gbps

Also called: megabits and gigabits per second

Mbps measures how much data moves each second. 1 Gbps is 1,000 Mbps. Internet plans and firewall datasheets both use these units.

Why it matters when you buy: Megabits are not megabytes: a 1,000 Mbps line moves about 125 megabytes a second, because a byte is 8 bits.

Firewall throughput

Also called: stateful firewall throughput

The most traffic a firewall can pass when it only checks its rules (which device may talk to which, on which port), with no deeper inspection.

Why it matters when you buy: It is the biggest number on a datasheet and the least useful for sizing, because almost nobody runs a firewall with only its rules switched on.

See the products →

Every extra check costs speed

One firewall, four very different speed figures. These are Sophos's published numbers for the desktop XGS 128.

  • Firewall rules onlyChecks who may talk to whom19,100 Mbps
  • Intrusion prevention (IPS)Also scans for known attack patterns4,650 Mbps
  • Threat protectionAlso blocks malware and risky websites4,000 Mbps
  • TLS inspectionAlso opens encrypted traffic to check it1,450 Mbps
The headline figure is 13 times the number that decides sizing. That is why our sizer checks TLS inspection and threat protection, and never sizes on firewall throughput alone.

Intrusion prevention (IPS)

Also called: IPS throughput

Intrusion prevention compares traffic with thousands of known attack patterns and blocks the matches. IPS throughput is how much traffic the firewall can scan this way.

Why it matters when you buy: Turning IPS on lowers the speed the firewall can sustain. On a Sophos XGS 128 it drops from 19,100 Mbps to 4,650 Mbps.

Threat protection

Also called: threat protection throughput

Threat protection is the firewall running all its checks together: rules, intrusion prevention, malware scanning, web filtering and application control. Its throughput is the speed with all of those on.

Why it matters when you buy: This is the realistic everyday figure for unencrypted traffic. Size so your internet speed plus growth stays under it.

TLS inspection

Also called: SSL inspection, HTTPS inspection, Xstream TLS inspection

Most web traffic is encrypted. TLS inspection lets the firewall open that traffic, check it, and seal it again before it reaches the device, so malware cannot hide inside encryption.

Why it matters when you buy: Opening and resealing is the heaviest job a firewall does, so TLS inspection throughput is usually the figure that decides the model. A desktop XGS 128 inspects 1,450 Mbps; the larger rackmount XGS 2100 inspects 1,100 Mbps.

See the products →

Encrypted traffic (HTTPS)

Also called: TLS, SSL

Traffic scrambled so only the sender and receiver can read it. The padlock in a browser address bar means the page arrived over HTTPS, which is encrypted with TLS.

Why it matters when you buy: Encryption protects your data in transit, and attackers use it too. Without TLS inspection a firewall sees that a connection exists but not what is inside it.

What happens to one web page on its way in

  1. 1RulesIs this device allowed to talk to this server, on this port?
  2. 2Intrusion preventionDoes the traffic match a known attack pattern?
  3. 3Open it (TLS inspection)Decrypt the envelope so the contents can be read.
  4. 4Threat protectionScan for malware, risky sites and unwanted apps; sandbox unknown files.
  5. 5Reseal and deliverEncrypt it again and pass it on, or block it.
Each step runs for every connection, thousands of times a second. The more steps you switch on, the more processing each byte needs, which is why each step has its own throughput figure.

Concurrent connections

Also called: sessions

Every app on every device keeps several conversations open with servers at once. Concurrent connections is how many of those conversations the firewall can track at the same moment.

Why it matters when you buy: Current models track millions, so this limit matters for large sites, busy servers and guest Wi-Fi rather than for a typical office. Our sizer checks it from your device count.

Headroom and growth

Also called: sizing margin

Spare capacity left on purpose: a firewall sized to run at 100 percent on day one is undersized on day two. Our sizer adds 15, 30 or 50 percent for growth over three years.

Why it matters when you buy: Internet plans tend to get faster over a firewall's life. Room to grow costs less than replacing the box mid-term.

Why devices, not people, drive connections

One person can bring a laptop, a phone and a tablet, each holding many open connections at once. Devices × connections each is what the firewall has to track, so our sizer asks for devices and leaves people out of the firewall decision.

Datasheet figures

Also called: vendor-published maximums

The throughput numbers vendors publish are measured in a lab with ideal traffic. Real networks with mixed traffic and more features switched on run slower.

Why it matters when you buy: Compare models with the same figure from the same vendor, and keep headroom. A specialist check before you buy costs nothing at Nuformat.

Connecting people and offices

How remote staff and branch offices reach your network safely.

VPN (virtual private network)

Also called: IPsec VPN, SSL VPN

A VPN builds an encrypted tunnel across the internet, so traffic between two points cannot be read on the way. IPsec VPN throughput is how much tunnel traffic the firewall can carry.

Why it matters when you buy: Every Sophos XGS includes unlimited remote-access and site-to-site VPN in its Base License. What changes between models is how much VPN traffic each can carry.

Remote-access VPN

Also called: client VPN

One person connects a laptop or phone to the office network through an encrypted tunnel, from home or the road.

Why it matters when you buy: Count the people connected at the same time, not everyone on staff, when you size for it.

Site-to-site VPN

Also called: branch VPN

Two offices join their networks through a permanent encrypted tunnel between their firewalls, so staff at either site reach shared systems as if they were in one building.

Why it matters when you buy: Each office needs its own firewall. The one at head office carries every branch tunnel, so it is usually the larger unit.

ZTNA (zero trust network access)

 

Instead of putting a remote user on the whole network, ZTNA connects them to one application at a time, and only after checking who they are and whether their device is healthy.

Why it matters when you buy: It shrinks what an attacker can reach with a stolen password. Sophos ZTNA is sold per user alongside the firewall.

See the products →

Two kinds of VPN

Remote access: one person to the office
Laptop at homeOffice firewall

Size for how many people connect at the same time.

Site to site: office to office
BranchHead office

Always on. Each office has its own firewall at its end.

The dashed tube is the encrypted tunnel: anyone on the internet between the two ends sees scrambled data only.

SD-WAN

Also called: software-defined wide area network

Software that spreads traffic across two or more internet connections and moves it to the healthy line automatically if one fails or slows down.

Why it matters when you buy: Two internet lines on one firewall, with SD-WAN, keeps an office online through a carrier outage. It is built into every Sophos XGS.

Network segmentation

Also called: VLANs, zones

Splitting one network into separate zones, such as staff, guests, cameras and servers, with the firewall controlling what may cross between them.

Why it matters when you buy: Segmentation stops a compromised camera or guest laptop from reaching your file server. Traffic crossing zones also uses firewall capacity, which is why the sizer asks about it.

Hardware

What the physical box looks like and what plugs into it.

Desktop and rackmount (1U, 2U)

Also called: form factor

Desktop firewalls sit on a shelf. Rackmount firewalls bolt into a standard equipment rack; 1U is one rack unit tall (1.75 inches) and 2U is two.

Why it matters when you buy: No rack in the office means a desktop model. Rackmount models add a FleXi Port bay for more or faster ports, and reach far higher inspection speeds.

Ports: copper (RJ45)

Also called: Ethernet ports, GbE

The familiar square sockets for network cables. GbE means 1 Gbps per port; 2.5GbE and 10GbE copper ports run faster over the same style of cable.

Why it matters when you buy: Most offices plug the firewall into a switch, so the switch supplies the ports and the firewall needs only a few.

See the products →

Desktop, 1U and 2U at a glance

Desktop (XGS 88 to 138)
XGS desktop

Sits on a desk or shelf in the office or comms cupboard. Up to 1,700 Mbps of TLS inspection.

Rackmount (XGS 2100 to 8500)
1U: 2100 to 4500
2U: 5500 to 8500

Bolts into a standard rack. 1U is 1.75 inches tall, 2U is twice that. Adds a FleXi Port bay for more or faster ports.

SFP and SFP+ (fiber ports)

Also called: transceiver slots, 10GbE

Small slots that take a plug-in transceiver for fiber or copper cable. SFP runs at 1 Gbps; SFP+ runs at 10 Gbps.

Why it matters when you buy: Needed for 10 Gbps internet or 10 Gbps links to servers and switches. Among Sophos desktops only the XGS 138 has SFP+ built in; rackmount models add it with a FleXi Port module.

See the products →

FleXi Port module

Also called: expansion module

A plug-in card for Sophos XGS rackmount firewalls that adds ports: 10GbE fiber, PoE, more copper, or bypass ports that keep traffic flowing if the firewall loses power.

Why it matters when you buy: You buy the firewall for its inspection capacity and add ports later as the network changes.

See the products →

PoE (Power over Ethernet)

 

Power delivered down the same network cable as the data, so a Wi-Fi access point, camera or desk phone needs no separate power plug.

Why it matters when you buy: Usually a switch provides PoE. The XGS 138 powers devices on two ports, and the 2xxx to 4xxx rackmount models can add a PoE FleXi Port module.

See the products →

Built-in Wi-Fi (w models)

 

The Sophos XGS 88w, 108w, 118w and 128w have a Wi-Fi radio inside the firewall, which suits a small office or shop.

Why it matters when you buy: For more than one room or floor, separate access points give better coverage and are managed from the same console.

See the products →

High availability (HA)

Also called: HA pair, active-passive, failover

Two identical firewalls work as a pair. One carries the traffic while the other watches it; if the first fails, the second takes over automatically.

Why it matters when you buy: It doubles the hardware but not the sizing, because one unit carries the load at a time. Worth it where an hour offline costs more than a second appliance.

A high-availability pair

Firewall A: activecarries all traffic
heartbeat
Firewall B: standbytakes over if A stops
Both units are the same model. The standby checks the active unit constantly through a dedicated link, the heartbeat, and steps in if it goes quiet.

Licenses and subscriptions

What you pay for after the hardware.

Base License

 

Comes with every Sophos XGS: the firewall itself, networking, SD-WAN, wireless management, unlimited remote-access and site-to-site VPN, and reporting.

Why it matters when you buy: It keeps the box running as a router and VPN gateway, but it does not include the threat checks most businesses buy the firewall for.

Standard Protection

 

Base License plus Network Protection (intrusion prevention, advanced threat protection and Security Heartbeat) and Web Protection (web filtering and application control), with Enhanced Support.

Why it matters when you buy: The minimum we would run on an internet-facing firewall.

See the products →

Xstream Protection

 

Everything in Standard, plus Zero-Day Protection (machine learning and sandboxing), Central Orchestration (SD-WAN orchestration, cloud reporting and the XDR and MDR connector) and DNS Protection.

Why it matters when you buy: The bundle most businesses choose, and the one our sizer and builds assume.

See the products →

Term or monthly subscription

 

A term subscription is paid up front for 1, 2 or 3 years. A monthly subscription is billed each month with no long commitment.

Why it matters when you buy: Term fixes the price for the period; monthly keeps cash free and adjusts as you grow. Ask us to price both.

See the products →

Detection and response

The services that watch for attacks the firewall cannot stop on its own.

Endpoint protection

Also called: antivirus, next-gen antivirus

Security software on each laptop, desktop and server that blocks malware and ransomware where it runs.

Why it matters when you buy: The firewall guards the door; endpoint protection guards each device, including laptops that leave the office.

See the products →

EDR (endpoint detection and response)

 

Endpoint protection that also records what happens on each device, so an analyst can see how an attack started and isolate the device.

Why it matters when you buy: Many cyber insurance applications ask whether you run EDR, not just antivirus.

See the products →

XDR (extended detection and response)

 

EDR extended across more sources: firewall, email, identity, cloud and network data are correlated in one place, so a single attack across several of them shows up as one incident.

Why it matters when you buy: Fewer alerts to chase, and the story of an attack in one view.

See the products →

MDR (managed detection and response)

Also called: MDR Plus

A team of security analysts watches your XDR data around the clock and responds to threats on your behalf, at 2 a.m. on a Sunday as well as 2 p.m. on a Tuesday.

Why it matters when you buy: Most small and mid-sized businesses cannot staff a 24/7 security team; MDR is that team as a subscription.

See the products →

Who watches what

Each tool sees one part of your business. XDR joins them into one picture.

Endpoint and EDRLaptops, desktops, serversSophos Endpoint
FirewallEverything entering or leavingSophos XGS
EmailPhishing and malicious attachmentsSophos Email
Identity (ITDR)Logins and accountsSophos ITDR
Network (NDR)Printers, cameras, machinerySophos NDR
Logs (SIEM)The record of everything aboveSophos Next-Gen SIEM

MDR puts a 24/7 team of analysts on top of all six, so someone acts on what they show, day or night.

NDR (network detection and response)

 

A sensor that watches network traffic itself, catching suspicious behavior from devices that cannot run security software, such as printers, cameras and machinery.

Why it matters when you buy: Covers the blind spot endpoint software leaves.

See the products →

ITDR (identity threat detection and response)

 

Watches your user accounts in Microsoft Entra ID and Active Directory for stolen passwords, risky settings and suspicious sign-ins.

Why it matters when you buy: Many attacks now start with a stolen login rather than malware.

See the products →

SIEM (security information and event management)

Also called: Next-Gen SIEM

Collects and keeps logs from your firewall, devices, identity and email in one searchable store, and correlates them to spot attacks and prove compliance.

Why it matters when you buy: Auditors and insurers often ask how long you keep logs. A SIEM is the answer.

See the products →

Sandboxing

Also called: zero-day protection

Suspicious files are opened in a sealed test environment first, to see what they do before they reach a real device.

Why it matters when you buy: It catches new malware that no signature list knows about yet. Included in Xstream Protection.

Zero-day

 

An attack that uses a flaw the software maker has not yet fixed, so there was zero days of warning.

Why it matters when you buy: Patching alone cannot stop it; layered defenses such as sandboxing, EDR and MDR are what limit the damage.

Ransomware

 

Malware that locks your files or systems and demands payment to release them, often after first copying your data to threaten its release.

Why it matters when you buy: A tested backup you can restore from is the last line of defense.

See the products →

Phishing

 

A fake email, text or web page made to trick someone into giving up a password, paying a false invoice or opening malware.

Why it matters when you buy: Email security catches most of it; awareness training helps people spot the rest.

See the products →

MFA (multi-factor authentication)

Also called: 2FA

Signing in with something you know (a password) plus something you have (a phone app or security key), so a stolen password alone is not enough.

Why it matters when you buy: One of the cheapest, most effective controls there is, and a common insurance requirement.

Frameworks and roles

The language of audits, insurers and boards.

NIST Cybersecurity Framework (CSF) 2.0

 

A free framework from the US National Institute of Standards and Technology that groups security work into six functions: Govern, Identify, Protect, Detect, Respond and Recover.

Why it matters when you buy: Questionnaires from insurers and customers often follow it. Our NIST CSF-aligned build maps products to each function.

vCISO (virtual chief information security officer)

 

A part-time, outsourced security leader who sets policy, manages risk and reports to leadership, for businesses that do not need a full-time CISO.

Why it matters when you buy: Gives you a named person for the Govern function without a full-time salary.

See the products →

SOC (security operations center)

 

The team, and the tools, that monitor an organization for attacks and respond to them. MDR is a SOC you subscribe to.

See the products →

Put the terms to work

Our sizer checks your connection against every capacity figure on this page and names the smallest Sophos XGS that passes. Or tell us what you have, and a specialist will size it with you in Canada or the USA.