Sophos Firewall Feature List
Sophos Firewall Feature List
Sophos Firewall Feature List
Ì Purpose-built user interface with interactive control Ì Policy test simulator tool enables firewall rule and web
center utilizes traffic-light indicators (red, yellow, green) policy simulation and testing by user, IP, and time of day
to instantly identify what needs attention at a glance
Ì User Threat Quotient identifies risky users based
Ì Control Center offers instant insights into endpoint on recent browsing behavior and ATP triggers
health, unidentified Mac and Windows applications,
Ì Configuration API for all features for RMM/PSA integration
cloud applications and Shadow IT, suspicious
payloads, risky users, advanced threats, network Ì Discover Mode (TAP mode) for seamless integration in
attacks, objectionable websites, and much more trials and PoCs with support for Synchronized Security
Ì Policy Control Center widget monitors policy activity Ì Sophos Central cloud-based management and reporting
for business, user, and network policies and tracks for multiple firewalls provides group policy management
unused, disabled, changed, and new policies and one console for all your Sophos IT security products
Ì Unified policy model combines all firewall, NAT, Ì Easy streamlined setup wizard enables fast out-
and TLS inspection rules onto a single screen of-the box deployment in just a few minutes
with grouping, filtering, and search options
Ì Zero-touch deployment and configuration
Ì Streamlined firewall rule management for large rule in Sophos Central for new firewalls
sets with custom auto and manual grouping plus at-a-
Ì Seamless integration with Sophos MDR
glance mouse-over feature and enforcement indicators
Sophos Firewall Features
Ì Email or SNMP trap notification options Ì User, group, time, or network-based policies
Ì Central management support via Sophos Central Ì Enforce policy across zones, networks, or by service type
Ì Backup and restore configurations: locally, via FTP Ì Zone isolation and zone-based policy support.
or email; on-demand, daily, weekly, or monthly
Ì Default zones for LAN, WAN, DMZ, LOCAL, VPN, and Wi-Fi
Ì API for third-party integration
Ì Custom zones on LAN or DMZ
Ì Interface renaming
Ì Customizable NAT policies with IP masquerading and full
Ì Remote access option for Sophos Support object support to redirect or forward multiple services in
a single rule with a convenient NAT rule wizard to quickly
Ì Cloud-based license management via MySophos
and easily create complex NAT rules in just a few clicks
Sophos Central Management
Ì Re-usable network object definitions for all rules
Ì Sophos Central cloud-based management
with global intelligent free-text search
and reporting for multiple firewalls provides
group policy management and a single console Ì Flood protection: DoS, DDoS, and portscan blocking
for all your Sophos IT security products
Ì Country blocking by geo-IP
Ì Group policy management allows objects, settings,
Ì Routing: static, multicast (PIM-SM), and
and policies to be modified once and automatically
dynamic: RIP, BGP, OSPFv3 (IPv6)
synchronized to all firewalls in the group
Ì Upstream proxy support
Ì Task Manager provides a full historical audit trail
and status monitoring of group policy changes
2
Sophos Firewall Features
Ì Bridging with STP support and ARP broadcast forwarding Ì Real-time VoIP optimization
Ì 802.3ad interface link aggregation Ì Central monitoring and management of APs and
wireless clients through the built-in wireless controller
Ì Full configuration of DNS, DHCP, and NTP
Ì Bridge APs to LAN, VLAN, or a separate
Ì Dynamic DNS (DDNS)
zone with client isolation options
Ì IPv6 Ready Logo Program Approval Certification
Ì Multiple SSID support per radio including hidden SSIDs
Ì IPv6 tunnelling support including 6in4, 6to4, 4in6,
Ì Support for diverse security and encryption standards
and IPv6 rapid deployment (6rd) through IPsec
including WPA2 Personal and Enterprise
Xstream SD-WAN
Ì Channel width selection option
Ì Xstream SD-WAN profiles support multiple
WAN link options including VDSL, DSL, Ì Support for IEEE 802.1X (RADIUS authentication)
cable, LTE/cellular, and MPLS with primary and secondary server support
Ì Performance-based SLAs automatically select the Ì Support for 802.11r (fast transition)
best WAN link based on jitter, latency, or packet-loss
Ì Hotspot support for (custom) vouchers,
Ì SD-WAN load balancing across multiple password of the day, or T&C acceptance
SD-WAN links with round-robin weighting
Ì Wireless guest internet access with walled garden options
or session persistence strategies
Ì Time-based wireless network access
Ì Zero-impact re-routing maintains application sessions
when link performance falls below thresholds and a Ì Wireless repeating and bridging meshed
transition is made to a better performing WAN link network mode with supported APs
Ì SD-WAN monitoring graphs provide real-time insights Ì Automatic channel selection background optimization
into latency, jitter and packet loss for all WAN links
Ì Support for HTTPS login
Ì Xstream FastPath acceleration of SD-
Authentication
WAN IPsec tunnel traffic
Ì Synchronized User ID utilizes Synchronized Security
Ì Synchronized SD-WAN, a Synchronized Security to share currently logged in Active Directory user
feature, leverages the added clarity and reliability of ID between Sophos endpoints and the firewall
application identification that comes with the sharing of without an agent on the AD server or client
Synchronized Application Control information between
Ì Authentication via: Active Directory,
Sophos-managed endpoints and Sophos Firewall
eDirectory, RADIUS, LDAP and TACACS+
Ì Application routing over preferred links via
Ì Server authentication agents for Active
firewall rules or policy-based routing
Directory SSO, STAS, SATC
Ì Robust VPN support including IPsec and SSL VPN
Ì Single sign-on: Active directory,
Ì Unique RED Layer 2 tunnel with routing eDirectory, RADIUS Accounting
Base Traffic Shaping and Quotas Ì Azure AD single sign-on for administrator
Ì Flexible network- or user-based traffic shaping (QoS) access to the Webadmin console
(enhanced web and app traffic shaping options
Ì Client authentication agents for
included with the Web Protection subscription)
Windows, Mac OS X, Linux 32/64
3
Sophos Firewall Features
Ì Remote access: SSL, IPsec, iPhone/iPad/ Ì Secure encrypted tunnel using digital X.509
Cisco/Android VPN client support certificates and AES 256-bit encryption
Ì URL Filter database with millions of sites across Ì Filter cloud application usage by category or volume
92 categories, backed by SophosLabs
Ì Detailed customizable cloud application
Ì Surfing quota time policies per user/group usage report for full historical reporting
5
Sophos Firewall Features
Central Firewall Reporting Advanced Ì Self-serve user portal for viewing and
Ì 30-days of cloud data storage for historical releasing quarantined messages
firewall reporting with advanced features to
Email Encryption and DLP
save, schedule and export custom reports
Ì Patent-pending SPX encryption for
XDR and MDR Connector one-way message encryption
Ì Ready to integrate with Sophos Extended
Ì Recipient self-registration SPX password management
Threat Detection and Response (XDR) for cross-
product threat hunting and analysis Ì Add attachments to SPX secure replies
Ì DLP engine with automatic scanning of emails Ì Reporting for Sophos Firewalls: hardware,
and attachments for sensitive data software, virtual, and cloud
Ì HTTPS (TLS/SSL) encryption offloading Ì Export reports in PDF, CFV or HTML format
Ì Cookie signing with digital signatures Ì Up to one year data storage per firewall
Ì Integrated load balancer spreads Ì Hundreds of on-box reports with custom report options:
visitors across multiple servers Dashboards (Traffic, Security, and User Threat Quotient),
Applications (App Risk, Blocked Apps, Synchronized
Ì Skip individual checks in a granular fashion as required
Apps, Search Engines, Web Servers, Web Keyword
Ì Match requests from source networks Match, FTP), Network and Threats (IPS, ATP, Wireless,
or specified target URLs Security Heartbeat, Sandstorm), VPN, Email, Compliance
(HIPAA, GLBA, SOX, FISMA, PCI, NERC CIP v3, CIPA)
Ì Support for logical and/or operators
Ì Current Activity Monitoring: system health, live users,
Ì Assists compatibility with various configurations
IPsec connections, remote users, live connections,
and non-standard deployments
wireless clients, quarantine, and DoS attacks
Ì Options to change web application
Ì SD-WAN Link Performance Monitoring
firewall performance parameters
for jitter, latency, and packet loss
Ì Scan size limit option
Ì Report anonymization
Ì Allow/Block IP ranges
Ì Report scheduling to multiple recipients by
Ì Wildcard support for server paths and domains report group with flexible frequency options
Ì Automatically append a prefix/suffix for authentication Ì Export reports as HTML, PDF, Excel (XLS)
Ì Report bookmarks
Reporting and Logging Ì Log retention customization by category
Central Firewall Reporting
Ì Full-featured log viewer with column view and
Ì Pre-defined reports with flexible customization options
detailed view with powerful filter and search options,
hyperlinked rule ID, and data view customization 7
Sophos Firewall Features
Base Network Web Zero-Day Central Central Firewall Email Web Server
Firewall Protection Protection Protection Orchestration Reporting Adv. Protection Protection
Please note:
Ì Some features are not supported on XGS 87 and XG 86 models (on-box reporting, dual AV scanning,
WAF AV scanning and email message transfer agent (MTA) functionality)
Ì MSP licensing options differ slightly to the above
United Kingdom and Worldwide Sales North American Sales Australia and New Zealand Sales Asia Sales
Tel: +44 (0)8447 671131 Toll Free: 1-866-866-2802 Tel: +61 2 9409 9100 Tel: +65 62244168
Email: sales@sophos.com Email: nasales@sophos.com Email: sales@sophos.com.au Email: salesasia@sophos.com