Sophos Firewall Feature List
Sophos Firewall Feature List
Ì Purpose-built user interface with interactive control Ì Policy test simulator tool enables firewall rule and web
center utilizes traffic-light indicators (red, yellow, green) policy simulation and testing by user, IP, and time of day
to instantly identify what needs attention at a glance
Ì User Threat Quotient identifies risky users based
Ì Control Center offers instant insights into endpoint on recent browsing behavior and ATP triggers
health, unidentified Mac and Windows applications,
Ì Configuration API for all features for RMM/PSA integration
cloud applications and Shadow IT, suspicious
payloads, risky users, advanced threats, network Ì Discover Mode (TAP mode) for seamless integration in
attacks, objectionable websites, and much more trials and PoCs with support for Synchronized Security
Ì Policy Control Center widget monitors policy activity Ì Sophos Central cloud-based management and reporting
for business, user, and network policies and tracks for multiple firewalls provides group policy management
unused, disabled, changed, and new policies and one console for all your Sophos IT security products
Ì Unified policy model combines all firewall, NAT, Ì Easy streamlined setup wizard enables fast out-
and TLS inspection rules onto a single screen of-the box deployment in just a few minutes
with grouping, filtering, and search options
Ì Zero-touch deployment and configuration
Ì Streamlined firewall rule management for large rule in Sophos Central for new firewalls
sets with custom auto and manual grouping plus at-a-
glance mouse-over feature and enforcement indicators
Sophos Firewall Features
Base Firewall for each firewall with one that can be pinned
for permanent storage and easy access
General Management
Ì Purpose-built, streamlined user interface and firewall Ì Firmware update scheduling from Sophos Central enables
rule management for large rule sets with grouping with easy automated updates to be applied at any time
at-a-glance rule feature and enforcement indicators
Ì Zero-touch deployment enables the initial
Ì Two-factor authentication (One-time-password) support configuration to be performed in Sophos Central
for administrator access, user portal, IPsec and SSL VPN and then exported for loading onto the device
from a flash drive at startup, automatically
Ì Advanced troubleshooting tools in
connecting the device back to Sophos Central
GUI (e.g., Packet Capture)
Firewall, Networking, and Routing
Ì High Availability (HA) support clustering two
Ì Stateful deep packet inspection firewall
devices in active-active or active-passive
mode with plug-and-play Quick HA setup Ì Xstream packet processing architecture provides
extreme levels of visibility, protection, and performance
Ì Full command line interface (CLI) accessible from GUI
through stream-based packet processing
Ì Role-based administration
Ì Xstream TLS inspection with high performance,
Ì Automated firmware update notification with easy support for TLS 1.3 with no downgrading, port
automated update process and roll-back features agnostic, enterprise-grade polices, unique dashboard
visibility, and compatibility troubleshooting
Ì Reusable system object definitions for networks, services,
hosts, time periods, users and groups, clients, and servers Ì Xstream DPI Engine provides stream scanning
protection for IPS, AV, Web, App Control, and TLS
Ì Self-service user portal
Inspection in a single high-performance engine
Ì Configuration change tracking
Ì Xstream Network Flow FastPath delivers policy-driven
Ì Flexible device access control for services by zones and intelligent acceleration of trusted traffic automatically
Ì Email or SNMP trap notification options Ì Xstream SD-WAN profiles and performance-
based SLAs automatically select the best WAN
Ì SNMP v3 and Netflow support
link based on jitter, latency, or packet-loss
Ì Central management support via Sophos Central with zero-impact re-routing transitions
Ì Backup and restore configurations: locally, via FTP Ì WAN link balancing: multiple internet connections,
or email; on-demand, daily, weekly, or monthly auto-link health check, automatic failover, automatic
and weighted balancing, and granular multipath rules
Ì API for third-party integration
Ì User, group, time, or network-based policies
Ì Interface renaming
Ì Access time polices per user/group
Ì Remote access option for Sophos Support
Ì Enforce policy across zones, networks, or by service type
Ì Cloud-based license management via MySophos
Ì Zone isolation and zone-based policy support.
Sophos Central Management
Ì Sophos Central cloud-based management Ì Default zones for LAN, WAN, DMZ, LOCAL, VPN, and Wi-Fi
and reporting for multiple firewalls provides
Ì Custom zones on LAN or DMZ
group policy management and a single console
for all your Sophos IT security products Ì Customizable NAT policies with IP masquerading and full
object support to redirect or forward multiple services in
Ì Group policy management allows objects, settings,
a single rule with a convenient NAT rule wizard to quickly
and policies to be modified once and automatically
and easily create complex NAT rules in just a few clicks
synchronized to all firewalls in the group
Ì Re-usable network object definitions for all rules
Ì Task Manager provides a full historical audit trail
with global intelligent free-text search
and status monitoring of group policy changes
Ì Flood protection: DoS, DDoS, and portscan blocking
Ì Backup firmware management in Sophos Central
stores the last five configuration backup files Ì Country blocking by geo-IP
2
Sophos Firewall Features
Ì Wireless WAN support (n/a in virtual deployments) Ì Bridge APs to LAN, VLAN, or a separate
zone with client isolation options
Ì 802.3ad interface link aggregation
Ì Multiple SSID support per radio including hidden SSIDs
Ì Full configuration of DNS, DHCP, and NTP
Ì Support for diverse security and encryption standards
Ì Dynamic DNS (DDNS)
including WPA2 Personal and Enterprise
Ì IPv6 Ready Logo Program Approval Certification
Ì Channel width selection option
Ì IPv6 tunnelling support including 6in4, 6to4, 4in6,
Ì Support for IEEE 802.1X (RADIUS authentication)
and IPv6 rapid deployment (6rd) through IPsec
with primary and secondary server support
Xstream SD-WAN
Ì Support for 802.11r (fast transition)
Ì Xstream SD-WAN profiles support multiple
WAN link options including VDSL, DSL, Ì Hotspot support for (custom) vouchers,
cable, LTE/cellular, and MPLS password of the day, or T&C acceptance
Ì Performance-based SLAs automatically select the Ì Wireless guest internet access with walled garden options
best WAN link based on jitter, latency, or packet-loss
Ì Time-based wireless network access
Ì Zero-impact re-routing maintains application sessions
Ì Wireless repeating and bridging meshed
when link performance falls below thresholds and a
network mode with supported APs
transition is made to a better performing WAN link
Ì Automatic channel selection background optimization
Ì SD-WAN monitoring graphs provide real-time insights
into latency, jitter and packet loss for all WAN links Ì Support for HTTPS login
Ì Application routing over preferred links via Ì Server authentication agents for Active
firewall rules or policy-based routing Directory SSO, STAS, SATC
Ì Robust VPN support including IPsec and SSL VPN Ì Single sign-on: Active directory,
eDirectory, RADIUS Accounting
Ì Unique RED Layer 2 tunnel with routing
Ì Client authentication agents for
Base Traffic Shaping and Quotas
Windows, Mac OS X, Linux 32/64
Ì Flexible network- or user-based traffic shaping (QoS)
(enhanced web and app traffic shaping options Ì Browser SSO authentication: Transparent,
included with the Web Protection subscription) proxy authentication (NTLM) and Kerberos
3
Sophos Firewall Features
4
Sophos Firewall Features
Ì URL Filter database with millions of sites across Ì Filter cloud application usage by category or volume
92 categories, backed by SophosLabs
Ì Detailed customizable cloud application
Ì Surfing quota time policies per user/group usage report for full historical reporting
5
Sophos Firewall Features
Central Firewall Reporting Advanced Ì Self-serve user portal for viewing and
Ì 30-days of cloud data storage for historical releasing quarantined messages
firewall reporting with advanced features to
Email Encryption and DLP
save, schedule and export custom reports
Ì Patent-pending SPX encryption for
XDR and MTR Connector one-way message encryption
Ì Ready to integrate with Sophos Extended
Ì Recipient self-registration SPX password management
Threat Detection and Response (XDR) for cross-
product threat hunting and analysis Ì Add attachments to SPX secure replies
Ì DLP engine with automatic scanning of emails Ì Reporting for Sophos Firewalls: hardware,
and attachments for sensitive data software, virtual, and cloud
Ì HTTPS (TLS/SSL) encryption offloading Ì Export reports in PDF, CFV or HTML format
Ì Cookie signing with digital signatures Ì Up to one year data storage per firewall
Ì Integrated load balancer spreads Ì Hundreds of on-box reports with custom report options:
visitors across multiple servers Dashboards (Traffic, Security, and User Threat Quotient),
Applications (App Risk, Blocked Apps, Synchronized
Ì Skip individual checks in a granular fashion as required
Apps, Search Engines, Web Servers, Web Keyword
Ì Match requests from source networks Match, FTP), Network and Threats (IPS, ATP, Wireless,
or specified target URLs Security Heartbeat, Sandstorm), VPN, Email, Compliance
(HIPAA, GLBA, SOX, FISMA, PCI, NERC CIP v3, CIPA)
Ì Support for logical and/or operators
Ì Current Activity Monitoring: system health, live users,
Ì Assists compatibility with various configurations
IPsec connections, remote users, live connections,
and non-standard deployments
wireless clients, quarantine, and DoS attacks
Ì Options to change web application
Ì SD-WAN Link Performance Monitoring
firewall performance parameters
for jitter, latency, and packet loss
Ì Scan size limit option
Ì Report anonymization
Ì Allow/Block IP ranges
Ì Report scheduling to multiple recipients by
Ì Wildcard support for server paths and domains report group with flexible frequency options
Ì Automatically append a prefix/suffix for authentication Ì Export reports as HTML, PDF, Excel (XLS)
Ì Report bookmarks
Reporting Ì Log retention customization by category
Central Firewall Reporting
Ì Full-featured log viewer with column view and
Ì Pre-defined reports with flexible customization options
detailed view with powerful filter and search options,
hyperlinked rule ID, and data view customization 7
Sophos Firewall Features
Base Network Web Zero-Day Central Central Firewall Email Web Server
Firewall Protection Protection Protection Orchestration Reporting Adv. Protection Protection
Please note:
Ì Some features are not supported on XGS 87 and XG 86 models (on-box reporting, dual AV scanning,
WAF AV scanning and email message transfer agent (MTA) functionality)
Ì MSP licensing options differ slightly to the above
United Kingdom and Worldwide Sales North American Sales Australia and New Zealand Sales Asia Sales
Tel: +44 (0)8447 671131 Toll Free: 1-866-866-2802 Tel: +61 2 9409 9100 Tel: +65 62244168
Email: [email protected] Email: [email protected] Email: [email protected] Email: [email protected]