Description
Sophos Webserver Protection for XGS 3100
Webserver Protection adds a reverse-proxy web application firewall to a Sophos XGS 3100. It protects the web servers you host, rather than filtering the traffic your staff send out. This subscription is licensed to the XGS 3100 specifically.
This SKU is for the XGS 3100 only. Webserver Protection is licensed per appliance model, and the five listings differ only by the model they cover. Check your appliance before ordering, because the SKUs are not interchangeable.
How it works
The firewall sits in front of your web server as a reverse proxy. External clients connect to the firewall, which terminates the connection, inspects the HTTP or HTTPS request, and forwards only clean traffic to a back-end server that is never directly exposed. Compared with plain port forwarding, the attack surface drops sharply because the traffic can be inspected, restricted and logged in detail.
What it inspects
- OWASP signature filtering for SQL injection, cross-site scripting and directory traversal.
- URL, form and cookie hardening, including cryptographic cookie signing to detect tampering.
- Antivirus scanning of uploads, and slow HTTP attack protection.
- Authentication offload, putting basic or form-based authentication in front of an application that lacks it.
Where it fits, and where it does not
It suits internally hosted applications published to the internet: Exchange OWA, intranet portals, line-of-business web apps. It is not a substitute for patching, secure development or server hardening, and for a high-volume public website a dedicated cloud WAF is usually the better answer. For everything else running behind an XGS, it adds application-layer protection without introducing another product to manage.
Frequently asked questions
Which XGS model is this for?
Each Webserver Protection SKU is tied to one appliance model. This listing is for the XGS model named in the title. Ordering the wrong model's SKU is the usual mistake, so check your appliance before you buy.
What does Webserver Protection actually do?
It turns the firewall into a reverse proxy in front of the web servers you host. Traffic hits the firewall, gets inspected, and only clean requests reach the server behind it. The server is never exposed directly.
What does it protect against?
OWASP signature filtering for SQL injection and cross-site scripting, URL hardening, form hardening, cookie signing, antivirus scanning of uploads, and slow HTTP protection. It also does authentication offload, so you can put a login in front of an application that has none.
Is this the same as web filtering?
No, and the direction matters. Web filtering protects your users browsing out. Webserver Protection protects the servers you host from traffic coming in. They are opposite jobs.
Does it replace a cloud WAF?
For internal applications, Exchange OWA, intranet portals and line-of-business apps published through the firewall, it does the job well. For a high-traffic public web property, a dedicated cloud-native WAF is still the better fit. Tell us what you are publishing and we will say which applies.
Get this quoted by Nuformat
Nuformat is a Sophos partner serving Canada and the United States. Confirm your appliance model and what you are publishing, and we will quote the right subscription, usually in two to three business days.
Request a quoteCapabilities as published by Sophos. Pricing confirmed by Nuformat at the time of quotation.

