Sophos Firewall XGS Features

Much more than a firewall.

Sophos XGS runs one firewall software across every model. It inspects encrypted traffic at speed, catches threats other firewalls miss, links to your Sophos devices to shut attacks down, and connects your sites. Here is what it actually does, in plain terms.

Want to see it sized for you? Get a quote or call 1-833-283-7373.

One engineInspect once, everywhere
TLS 1.3Encrypted traffic inspected
Built-in NDRCatches hidden attacks
ProgrammableImproves over time

Performance — the Xstream architecture

Fast, even with full inspection on.

Sophos calls it Xstream. It is the design that lets the firewall inspect deeply without the slowdown that forces other firewalls to choose between speed and security.

Inspect once, apply everywhere

A single streaming engine runs antivirus, intrusion prevention, web and application control, and TLS inspection in one pass, instead of handing traffic between separate engines.

Trusted traffic gets out of the way

The Xstream FastPath offloads traffic you have chosen to trust at wire speed, so processing power is saved for the traffic that actually needs inspecting.

See inside encrypted traffic

Most traffic is encrypted, and threats hide there. Xstream TLS 1.3 inspection decrypts and checks it at speed, with ready-made exceptions so it does not break the apps you rely on.

Gets better without new hardware

The architecture is programmable, so new protection and performance arrive with firmware updates over the life of the appliance, not only when you buy a new box.

Threat protection

Catches what other firewalls miss.

Layered detection stops known attacks, unknown files, and threats hiding inside encrypted traffic.

Intrusion prevention

An intrusion prevention system spots exploit patterns and suspicious activity, and you can tune policies by workload and exposure to cut noise and false positives.

Stops unknown and zero-day files

Sophos calls it Zero-Day Protection: machine learning and cloud sandboxing analyse suspicious files away from your network before the firewall lets them through, catching new ransomware and targeted attacks.

Finds attacks hidden in encrypted traffic

Sophos Firewall is the only firewall with AI-powered Network Detection and Response built in. NDR spots active and encrypted threats other firewalls miss, without your team having to decrypt the traffic first.

Blocks bad sites and downloads

Web protection and a cloud DNS filtering service, both backed by SophosLabs intelligence, block malicious and unwanted URLs across every port, protocol, and application.

Works with your other Sophos products

The firewall does not work alone.

Sophos calls it Synchronized Security. The firewall shares information with your Sophos devices and services to identify threats and shut them down automatically.

Firewall and devices share a heartbeat

Security Heartbeat is a live signal between the firewall and Sophos Endpoint. When one detects a problem, the other knows immediately.

Infected devices isolated automatically

If a computer is compromised, the firewall can cut it off from the rest of the network on its own, stopping the threat from spreading while you deal with it.

Turns threat intelligence into blocks

Sophos calls it Active Threat Response: threat feeds from Sophos MDR and XDR become firewall enforcement automatically, so containment does not wait on someone writing a rule by hand.

Identifies the apps other firewalls cannot

Synchronized Application Control uses information from Sophos Endpoint to name custom, obscure, and evasive apps that signature-only firewalls leave as "unknown", so you can actually control them.

Connectivity

Connects your sites and your people.

The same appliance links your offices, remote workers, and the cloud, with control over every path.

SD-WAN with point-and-click control

Xstream SD-WAN routes each application over the best link with performance-based, zero-impact failover, and it uses app visibility from Synchronized Security to make smarter routing decisions.

Unlimited VPN

IPsec and SSL VPN for site-to-site and remote access are included with no user limits, so connecting an extra office or remote worker does not add a licence cost.

Zero-touch branch offices with SD-RED

SD-RED remote ethernet devices extend your secure network to a branch or site with almost no setup on site, the box connects back to the firewall on its own.

Zero-trust access for remote staff

An integrated ZTNA gateway lets remote and hybrid workers reach only the specific apps they need, not the whole network, with nothing extra to deploy.

Managed from one place.

Everything above is run and reported from a single cloud console, at no extra management cost.

Sophos Central, at no extra cost

Manage every firewall, and your Sophos switches and access points, from one cloud console with templates and scheduled backups.

Reporting on the box and in the cloud

Historical on-box logging plus cloud reporting show your network, web, and app activity over time.

One licence bundle to enable it all

Most of these features come with the Xstream Protection bundle. We help you match the bundle to what you need.

1

appliance, all of this

Tell us your user count and internet speed and we will size the right XGS model, match the licensing to the features you need, quote it, and reply in two to three business days.

Feature questions.

Does Sophos XGS inspect encrypted (TLS) traffic?

Yes. Xstream TLS 1.3 inspection decrypts and checks encrypted traffic at speed, with policy-based control and prepackaged exceptions so common apps keep working. It is worth testing performance and exceptions before enabling it broadly.

What makes Sophos Firewall different from other firewalls?

Two things stand out: it is the only firewall with AI-powered Network Detection and Response built in, catching threats hidden in encrypted traffic, and it links to Sophos Endpoint with Synchronized Security to isolate compromised devices automatically.

Is SD-WAN included?

Yes. Xstream SD-WAN is built in, with application-aware routing, link monitoring, load balancing, SLA-based path selection, and zero-impact failover, plus SD-RED for easy branch connectivity.

Which features need the Xstream bundle?

Networking, the Xstream architecture, unlimited VPN, and reporting come with the appliance. Threat protection features like Zero-Day Protection, DNS Protection, and the full NDR and threat-response capabilities come with the Xstream Protection bundle. We help you match the bundle to your needs.

See these features sized for your network.

Tell us your user count and internet speed and we will size the right Sophos XGS model, match the licensing, quote it, and reply in two to three business days.