The words on datasheets, quotes and insurance forms, explained without jargon. Each entry says what the term means and why it matters when you buy, with diagrams for the ideas that are easier to see than to read. Firewalls are sized by how much traffic they can check, not by headcount. These are the figures on every datasheet and in our sizer. Also called: megabits and gigabits per second Mbps measures how much data moves each second. 1 Gbps is 1,000 Mbps. Internet plans and firewall datasheets both use these units. Why it matters when you buy: Megabits are not megabytes: a 1,000 Mbps line moves about 125 megabytes a second, because a byte is 8 bits. Also called: stateful firewall throughput The most traffic a firewall can pass when it only checks its rules (which device may talk to which, on which port), with no deeper inspection. Why it matters when you buy: It is the biggest number on a datasheet and the least useful for sizing, because almost nobody runs a firewall with only its rules switched on. One firewall, four very different speed figures. These are Sophos's published numbers for the desktop XGS 128. Also called: IPS throughput Intrusion prevention compares traffic with thousands of known attack patterns and blocks the matches. IPS throughput is how much traffic the firewall can scan this way. Why it matters when you buy: Turning IPS on lowers the speed the firewall can sustain. On a Sophos XGS 128 it drops from 19,100 Mbps to 4,650 Mbps. Also called: threat protection throughput Threat protection is the firewall running all its checks together: rules, intrusion prevention, malware scanning, web filtering and application control. Its throughput is the speed with all of those on. Why it matters when you buy: This is the realistic everyday figure for unencrypted traffic. Size so your internet speed plus growth stays under it. Also called: SSL inspection, HTTPS inspection, Xstream TLS inspection Most web traffic is encrypted. TLS inspection lets the firewall open that traffic, check it, and seal it again before it reaches the device, so malware cannot hide inside encryption. Why it matters when you buy: Opening and resealing is the heaviest job a firewall does, so TLS inspection throughput is usually the figure that decides the model. A desktop XGS 128 inspects 1,450 Mbps; the larger rackmount XGS 2100 inspects 1,100 Mbps. Also called: TLS, SSL Traffic scrambled so only the sender and receiver can read it. The padlock in a browser address bar means the page arrived over HTTPS, which is encrypted with TLS. Why it matters when you buy: Encryption protects your data in transit, and attackers use it too. Without TLS inspection a firewall sees that a connection exists but not what is inside it. Also called: sessions Every app on every device keeps several conversations open with servers at once. Concurrent connections is how many of those conversations the firewall can track at the same moment. Why it matters when you buy: Current models track millions, so this limit matters for large sites, busy servers and guest Wi-Fi rather than for a typical office. Our sizer checks it from your device count. Also called: sizing margin Spare capacity left on purpose: a firewall sized to run at 100 percent on day one is undersized on day two. Our sizer adds 15, 30 or 50 percent for growth over three years. Why it matters when you buy: Internet plans tend to get faster over a firewall's life. Room to grow costs less than replacing the box mid-term. One person can bring a laptop, a phone and a tablet, each holding many open connections at once. Devices × connections each is what the firewall has to track, so our sizer asks for devices and leaves people out of the firewall decision. Also called: vendor-published maximums The throughput numbers vendors publish are measured in a lab with ideal traffic. Real networks with mixed traffic and more features switched on run slower. Why it matters when you buy: Compare models with the same figure from the same vendor, and keep headroom. A specialist check before you buy costs nothing at Nuformat. How remote staff and branch offices reach your network safely. Also called: IPsec VPN, SSL VPN A VPN builds an encrypted tunnel across the internet, so traffic between two points cannot be read on the way. IPsec VPN throughput is how much tunnel traffic the firewall can carry. Why it matters when you buy: Every Sophos XGS includes unlimited remote-access and site-to-site VPN in its Base License. What changes between models is how much VPN traffic each can carry. Also called: client VPN One person connects a laptop or phone to the office network through an encrypted tunnel, from home or the road. Why it matters when you buy: Count the people connected at the same time, not everyone on staff, when you size for it. Also called: branch VPN Two offices join their networks through a permanent encrypted tunnel between their firewalls, so staff at either site reach shared systems as if they were in one building. Why it matters when you buy: Each office needs its own firewall. The one at head office carries every branch tunnel, so it is usually the larger unit. Instead of putting a remote user on the whole network, ZTNA connects them to one application at a time, and only after checking who they are and whether their device is healthy. Why it matters when you buy: It shrinks what an attacker can reach with a stolen password. Sophos ZTNA is sold per user alongside the firewall. Size for how many people connect at the same time. Always on. Each office has its own firewall at its end. Also called: software-defined wide area network Software that spreads traffic across two or more internet connections and moves it to the healthy line automatically if one fails or slows down. Why it matters when you buy: Two internet lines on one firewall, with SD-WAN, keeps an office online through a carrier outage. It is built into every Sophos XGS. Also called: VLANs, zones Splitting one network into separate zones, such as staff, guests, cameras and servers, with the firewall controlling what may cross between them. Why it matters when you buy: Segmentation stops a compromised camera or guest laptop from reaching your file server. Traffic crossing zones also uses firewall capacity, which is why the sizer asks about it. What the physical box looks like and what plugs into it. Also called: form factor Desktop firewalls sit on a shelf. Rackmount firewalls bolt into a standard equipment rack; 1U is one rack unit tall (1.75 inches) and 2U is two. Why it matters when you buy: No rack in the office means a desktop model. Rackmount models add a FleXi Port bay for more or faster ports, and reach far higher inspection speeds. Also called: Ethernet ports, GbE The familiar square sockets for network cables. GbE means 1 Gbps per port; 2.5GbE and 10GbE copper ports run faster over the same style of cable. Why it matters when you buy: Most offices plug the firewall into a switch, so the switch supplies the ports and the firewall needs only a few. Sits on a desk or shelf in the office or comms cupboard. Up to 1,700 Mbps of TLS inspection. Bolts into a standard rack. 1U is 1.75 inches tall, 2U is twice that. Adds a FleXi Port bay for more or faster ports. Also called: transceiver slots, 10GbE Small slots that take a plug-in transceiver for fiber or copper cable. SFP runs at 1 Gbps; SFP+ runs at 10 Gbps. Why it matters when you buy: Needed for 10 Gbps internet or 10 Gbps links to servers and switches. Among Sophos desktops only the XGS 138 has SFP+ built in; rackmount models add it with a FleXi Port module. Also called: expansion module A plug-in card for Sophos XGS rackmount firewalls that adds ports: 10GbE fiber, PoE, more copper, or bypass ports that keep traffic flowing if the firewall loses power. Why it matters when you buy: You buy the firewall for its inspection capacity and add ports later as the network changes. Power delivered down the same network cable as the data, so a Wi-Fi access point, camera or desk phone needs no separate power plug. Why it matters when you buy: Usually a switch provides PoE. The XGS 138 powers devices on two ports, and the 2xxx to 4xxx rackmount models can add a PoE FleXi Port module. The Sophos XGS 88w, 108w, 118w and 128w have a Wi-Fi radio inside the firewall, which suits a small office or shop. Why it matters when you buy: For more than one room or floor, separate access points give better coverage and are managed from the same console. Also called: HA pair, active-passive, failover Two identical firewalls work as a pair. One carries the traffic while the other watches it; if the first fails, the second takes over automatically. Why it matters when you buy: It doubles the hardware but not the sizing, because one unit carries the load at a time. Worth it where an hour offline costs more than a second appliance. What you pay for after the hardware. Comes with every Sophos XGS: the firewall itself, networking, SD-WAN, wireless management, unlimited remote-access and site-to-site VPN, and reporting. Why it matters when you buy: It keeps the box running as a router and VPN gateway, but it does not include the threat checks most businesses buy the firewall for. Base License plus Network Protection (intrusion prevention, advanced threat protection and Security Heartbeat) and Web Protection (web filtering and application control), with Enhanced Support. Why it matters when you buy: The minimum we would run on an internet-facing firewall. Everything in Standard, plus Zero-Day Protection (machine learning and sandboxing), Central Orchestration (SD-WAN orchestration, cloud reporting and the XDR and MDR connector) and DNS Protection. Why it matters when you buy: The bundle most businesses choose, and the one our sizer and builds assume. A term subscription is paid up front for 1, 2 or 3 years. A monthly subscription is billed each month with no long commitment. Why it matters when you buy: Term fixes the price for the period; monthly keeps cash free and adjusts as you grow. Ask us to price both. The services that watch for attacks the firewall cannot stop on its own. Also called: antivirus, next-gen antivirus Security software on each laptop, desktop and server that blocks malware and ransomware where it runs. Why it matters when you buy: The firewall guards the door; endpoint protection guards each device, including laptops that leave the office. Endpoint protection that also records what happens on each device, so an analyst can see how an attack started and isolate the device. Why it matters when you buy: Many cyber insurance applications ask whether you run EDR, not just antivirus. EDR extended across more sources: firewall, email, identity, cloud and network data are correlated in one place, so a single attack across several of them shows up as one incident. Why it matters when you buy: Fewer alerts to chase, and the story of an attack in one view. Also called: MDR Plus A team of security analysts watches your XDR data around the clock and responds to threats on your behalf, at 2 a.m. on a Sunday as well as 2 p.m. on a Tuesday. Why it matters when you buy: Most small and mid-sized businesses cannot staff a 24/7 security team; MDR is that team as a subscription. Each tool sees one part of your business. XDR joins them into one picture. MDR puts a 24/7 team of analysts on top of all six, so someone acts on what they show, day or night. A sensor that watches network traffic itself, catching suspicious behavior from devices that cannot run security software, such as printers, cameras and machinery. Why it matters when you buy: Covers the blind spot endpoint software leaves. Watches your user accounts in Microsoft Entra ID and Active Directory for stolen passwords, risky settings and suspicious sign-ins. Why it matters when you buy: Many attacks now start with a stolen login rather than malware. Also called: Next-Gen SIEM Collects and keeps logs from your firewall, devices, identity and email in one searchable store, and correlates them to spot attacks and prove compliance. Why it matters when you buy: Auditors and insurers often ask how long you keep logs. A SIEM is the answer. Also called: zero-day protection Suspicious files are opened in a sealed test environment first, to see what they do before they reach a real device. Why it matters when you buy: It catches new malware that no signature list knows about yet. Included in Xstream Protection. An attack that uses a flaw the software maker has not yet fixed, so there was zero days of warning. Why it matters when you buy: Patching alone cannot stop it; layered defenses such as sandboxing, EDR and MDR are what limit the damage. Malware that locks your files or systems and demands payment to release them, often after first copying your data to threaten its release. Why it matters when you buy: A tested backup you can restore from is the last line of defense. A fake email, text or web page made to trick someone into giving up a password, paying a false invoice or opening malware. Why it matters when you buy: Email security catches most of it; awareness training helps people spot the rest. Also called: 2FA Signing in with something you know (a password) plus something you have (a phone app or security key), so a stolen password alone is not enough. Why it matters when you buy: One of the cheapest, most effective controls there is, and a common insurance requirement. The language of audits, insurers and boards. A free framework from the US National Institute of Standards and Technology that groups security work into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Why it matters when you buy: Questionnaires from insurers and customers often follow it. Our NIST CSF-aligned build maps products to each function. A part-time, outsourced security leader who sets policy, manages risk and reports to leadership, for businesses that do not need a full-time CISO. Why it matters when you buy: Gives you a named person for the Govern function without a full-time salary. The team, and the tools, that monitor an organization for attacks and respond to them. MDR is a SOC you subscribe to. Our sizer checks your connection against every capacity figure on this page and names the smallest Sophos XGS that passes. Or tell us what you have, and a specialist will size it with you in Canada or the USA.Firewall and cybersecurity terms in plain English
How a firewall is sized
Mbps and Gbps
Firewall throughput
Every extra check costs speed
Intrusion prevention (IPS)
Threat protection
TLS inspection
Encrypted traffic (HTTPS)
What happens to one web page on its way in
Concurrent connections
Headroom and growth
Why devices, not people, drive connections
Datasheet figures
Connecting people and offices
VPN (virtual private network)
Remote-access VPN
Site-to-site VPN
ZTNA (zero trust network access)
Two kinds of VPN
SD-WAN
Network segmentation
Hardware
Desktop and rackmount (1U, 2U)
Ports: copper (RJ45)
Desktop, 1U and 2U at a glance
SFP and SFP+ (fiber ports)
FleXi Port module
PoE (Power over Ethernet)
Built-in Wi-Fi (w models)
High availability (HA)
A high-availability pair
Licenses and subscriptions
Base License
Standard Protection
Xstream Protection
Term or monthly subscription
Detection and response
Endpoint protection
EDR (endpoint detection and response)
XDR (extended detection and response)
MDR (managed detection and response)
Who watches what
NDR (network detection and response)
ITDR (identity threat detection and response)
SIEM (security information and event management)
Sandboxing
Zero-day
Ransomware
Phishing
MFA (multi-factor authentication)
Frameworks and roles
NIST Cybersecurity Framework (CSF) 2.0
vCISO (virtual chief information security officer)
SOC (security operations center)
Put the terms to work
Glossary · 41 terms
Laptop
Phone
Tablet
Printer
Firewall tracks every line
Remote access: one person to the office
Laptop at homeOffice firewall
Site to site: office to office
BranchHead office
Desktop (XGS 88 to 138)
XGS desktop
Rackmount (XGS 2100 to 8500)
1U: 2100 to 4500
2U: 5500 to 8500
Firewall A: activecarries all traffic
heartbeat
Firewall B: standbytakes over if A stops
Endpoint and EDRLaptops, desktops, serversSophos Endpoint
FirewallEverything entering or leavingSophos XGS
EmailPhishing and malicious attachmentsSophos Email
Identity (ITDR)Logins and accountsSophos ITDR
Network (NDR)Printers, cameras, machinerySophos NDR
Logs (SIEM)The record of everything aboveSophos Next-Gen SIEM

