Sophos XGS firewalls: sized from a survey, deployed remotely, managed around the clock.
Sophos XGS firewall design, deployment and managed support for US businesses, delivered remotely by a team that has run firewalls in production since 2022. Survey before sizing, Sophos Central cloud management, Synchronized Security with Intercept X, ZTNA for remote access, and optional Sophos MDR for 24/7 vendor-side detection and response. The most common Sophos failure is a wrong-sized unit, and the survey is how we prevent it.

- XGSCurrent-generation platform
- Survey firstWritten sizing before any quote
- 5 minP1 response for managed clients
- 24/7Coverage, plus optional Sophos MDR

Nine capabilities, scaled to your business size.
Deep packet inspection with Xstream
The Sophos Xstream architecture provides TLS 1.3 decryption, deep packet inspection, full IPS and application control, with a dedicated Xstream Flow Processor offloading decryption and DPI so inspection holds up at high throughput.
ZTNA module
Sophos Zero Trust Network Access replaces legacy remote-access VPN with identity-aware, per-application access. Conditional access policies, device-health enforcement via Sophos Central, and integration with Microsoft Entra ID for SSO.
Synchronized Security with Intercept X
Sophos Firewall and Sophos Intercept X endpoint share live threat intelligence. A compromised endpoint detected by Intercept X is automatically isolated at the firewall in seconds, with no SIEM glue required.
Web filtering and application control
URL filtering across dozens of categories, SSL inspection granular by user, group or category, and application control over thousands of recognized applications. Custom user-based policies for productivity, compliance and risk management.
Intrusion prevention
Live IPS with SophosLabs threat feeds and anomaly detection aimed at command-and-control traffic, lateral movement and data-exfiltration patterns. Integrated in the firewall rather than a separate IPS appliance to license and manage.
Email protection at the edge
A built-in MTA with anti-spam, anti-phishing and malware scanning. For most US businesses on Microsoft 365 we recommend pairing the firewall with Defender for Office 365, and we will say plainly which layer should own which job.
SD-WAN and dual ISP
Native SD-WAN with multi-WAN failover, application-aware routing and quality-of-service prioritization for Teams, Zoom and VoIP. Dual ISP load balancing keeps a branch online when one carrier drops.
Sophos Central management
Cloud-managed via Sophos Central: configuration, monitoring, reports, alerts and firmware from one console covering firewall, endpoint, server and mobile. Multi-tenant view for groups with several entities or sites.
Sophos MDR (optional)
Sophos MDR, formerly Managed Threat Response, is 24/7 threat hunting and response by Sophos analysts across firewall, endpoint, email, server and cloud telemetry. We integrate it with our own managed service so detection and remediation have one accountable owner.
Four reasons to have us design and manage the firewall.
Sizing before quote, every time
We never quote a firewall without a survey. Peak throughput, concurrent connections, SSL inspection load, planned VPN tunnels, SD-WAN topology and branch count all go into a written sizing recommendation across the XGS lineup. A wrong-sized firewall is the most common Sophos failure, and the survey is a day of work that prevents it.
Synchronized Security depth
We deploy Sophos Firewall alongside Sophos Intercept X endpoint where it makes sense, so Synchronized Security actually delivers: a compromised endpoint isolated at the firewall automatically. Many Sophos installations deploy only the firewall and miss the ecosystem value; we design the integrated stack deliberately, or tell you honestly when it is not worth it.
P1 response in 5 minutes for managed clients
Firewall failure is a P1 incident. Managed clients get a 5-minute P1 response with 24/7 coverage, delivered remotely through Sophos Central, which is how modern firewall operations actually work. A monthly report tracks firewall health, blocked threats, policy hits and firmware currency, with 800+ systems already under our management group-wide.
One accountable team across the stack
We are a Microsoft Solutions Partner running Microsoft 365, Azure and endpoint estates for 68+ active clients group-wide, so the firewall is designed against the rest of your environment rather than in isolation: Entra ID integration for ZTNA, Sentinel for log forwarding, and Defender coexistence decided on purpose rather than by accident.
Six business profiles and how the XGS lineup maps to them.
Small office (10 to 50 users)
Desktop XGS models. Single site, mixed wired and WiFi, basic remote access, no SSL inspection at scale. The entry protection bundle usually fits, with endpoint integration where Intercept X is in play.
Mid-market (50 to 250 users)
Mid-range XGS models. Two ISPs, branch VPN to a handful of sites, SSL inspection for compliance-driven industries, ZTNA for remote work, and the fuller protection bundle for integrated visibility.
Financial services under GLBA and FTC Safeguards
Rack XGS models in a high availability pair, full SSL inspection, ZTNA for remote staff, log forwarding to Microsoft Sentinel, and Sophos MDR for 24/7 monitoring that a safeguards program can point to.
Healthcare and clinics
Sized to the site, with network segmentation between clinical systems and administration, encrypted remote access for clinicians, and egress controls around PHI. Segmentation is the part a HIPAA risk analysis will ask about.
Multi-site retail and hospitality
Small XGS units per site with a larger unit at HQ. SD-WAN over dual ISP, branch tunnels back to HQ, central Sophos Central management of every site, and PCI DSS segmentation for card-handling networks.
Manufacturing and distribution
Larger XGS at HQ, smaller units at plants and warehouses. OT segmentation between IT and plant-floor systems, with the firewall sitting between IT and OT VLANs under restrictive policies. Also the segmentation story a CMMC scoping exercise wants to see.
Three firewall platforms compared on what matters.
| Feature | Sophos XGS | Fortinet FortiGate | Palo Alto NGFW |
|---|---|---|---|
Best fit | SMB to mid-enterprise | SMB to enterprise | Enterprise |
Native EDR integration | Intercept X tightly integrated | FortiEDR adjacent | Cortex XDR adjacent |
Cloud management | Sophos Central included | FortiManager / FortiCloud | Panorama |
ZTNA module | Included with Xstream | FortiClient required | Prisma Access required |
Managed detection and response | Sophos MDR available | FortiGuard MDR available | Unit 42 MDR available |
Typical deployment time | 1-2 weeks | 2-3 weeks | 3-4 weeks |
Annual licensing complexity | Two bundles | Multiple FortiGuard SKUs | Multiple subscription SKUs |
Total cost of ownership | Lowest at SMB and mid-market | Competitive at all tiers | Highest, justified at enterprise |
From sizing call to live firewall in 2-4 weeks.
- 1
Survey and sizing
2-3 days
Remote survey: throughput needs, user count, branch topology, ISP profile, VPN scenarios, SSL inspection requirement, HA needs. Output is a written sizing recommendation across the XGS lineup with the protection bundle that fits.
- 2
Quote and procurement
3-5 days
A custom quote scoped per engagement: hardware, protection bundle, optional Sophos MDR, optional HA second unit. Hardware ships direct to your site; lead time varies by model and we tell you before you commit.
- 3
Deployment and migration
3-5 days
Configuration built remotely in advance, cutover scheduled off-hours with your on-site contact handling the physical swap while we drive the change. Policies migrated or rebuilt depending on the origin firewall, VPN tunnels rebuilt, SD-WAN configured, ZTNA tested, Sophos Central provisioned, Synchronized Security activated.
- 4
Acceptance and handover
2-3 days
Acceptance tests: throughput, failover, policy enforcement, log capture, alert routing. Knowledge transfer to your team, hypercare through the first weeks, and the monthly report scheduled.
What US buyers ask before standardizing on Sophos.
Related security pages on our site.
Cybersecurity Audit and Compliance
HIPAA, SOC 2, CMMC and FTC Safeguards aligned security baseline and audit support.
Endpoint Security
Defender for Endpoint and Intercept X EDR/XDR deployment for US businesses.
SOC as a Service
24/7 security operations with Microsoft Sentinel and Sophos MDR integration.
MFA Solutions
Microsoft Entra MFA, FIDO2 and passwordless rollout across your workforce.
Managed Security Services
Outsourced security operations: SIEM, EDR, MDR and vulnerability management.
Azure Firewall
The cloud-native alternative for traffic that lives in Azure rather than at your edge.
Book a sizing call and we will return a written Sophos firewall recommendation.
A 30 to 45 minute sizing call followed by a written recommendation: which XGS model, which protection bundle, with or without HA, with or without MDR, and a custom quote scoped per engagement. No commitment.
Related Services
Explore more solutions that work great with this service
Azure Firewall Design and Deployment
Azure Firewall engagements for US businesses: capability-led SKU
Learn moreFirewall Rule Base Audit
Rule bases reviewed, tightened and documented
Learn moreEndpoint Security
Endpoint security for US businesses using Microsoft Defender for
Learn moreManaged Security Services
Managed security services (MSS) for US businesses, delivered remotely
Learn moreSOC-as-a-Service
24/7 security operations delivered as a service
Learn more