Toll-free1-877-430-6240 / 1-780-430-6240 Authorized Sophos Partner
Next-Gen Firewall (XGS Series)

A firewall that talks to your endpoints.

Sophos Firewall (XGS series) consolidates next-gen firewall, IPS, web filtering, app control, ZTNA gateway, and SD-WAN in one appliance. Synchronized Security with Sophos endpoints means a compromised host can be automatically isolated at the firewall the moment it’s detected, before lateral movement starts.

Key Capabilities

Built for performance and modern threats

Most firewalls forced you to choose between deep inspection and line-rate throughput. Sophos’s Xstream architecture removes the compromise, then Synchronized Security adds the active response other firewalls can’t.

Xstream architecture

Custom flow processors and FastPath offload keep throughput near line rate even with deep packet inspection, application control, and TLS decryption all enabled.

TLS 1.3 inspection

Most traffic is encrypted. XGS decrypts and inspects TLS 1.3 at scale, surfacing the threats hiding in HTTPS that traditional firewalls only see as opaque blobs.

Synchronized Security

Endpoints and firewall share threat intelligence over the Security Heartbeat. The firewall sees which hosts are compromised and can isolate them automatically.

Active threat response

When a host is flagged by Intercept X, the firewall automatically blocks its lateral traffic, contains it, and notifies admins, all without manual intervention.

ZTNA gateway built-in

Replace legacy SSL VPN with identity- and posture-based access. Users connect only to the specific apps they’re authorized for, never to a flat network behind a tunnel.

SD-WAN & multi-link

Application-aware traffic steering, automatic failover, and link quality monitoring let you treat MPLS, broadband, and 5G as a single resilient WAN fabric.

Deep Dive

When the endpoint shouts, the firewall listens

Traditional firewalls and endpoint products are independent silos. An infected laptop can sit on the LAN for hours after detection while the firewall passes its traffic happily. Synchronized Security closes that gap.

  • Security Heartbeat. Sophos endpoints send a live health signal to the firewall. The firewall sees red, yellow, and green hosts at all times, in real time.
  • Automatic isolation. A red host gets cut off from internal network access until it’s remediated. The decision and action take seconds, not the hours an analyst needs to pivot consoles.
  • User and app awareness. Synchronized App Control identifies unknown applications on the network by querying their endpoint sources, so policies stay accurate as new apps appear.
  • One incident, one timeline. Firewall and endpoint events appear in the same Sophos Central case, so analysts see the full picture without correlating manually.
Sophos XGS firewall appliance
Appliance Range

Sized for every environment

From a small branch office to a large enterprise data center, the XGS series scales without changing the feature set or the management console.

S

XGS 87 / 107 / 116

Small offices and branch sites. Desktop form factor, fanless options, ideal for 5 to 100 users. Full feature set in a hardware footprint the size of a paperback.

5 to 100 users
M

XGS 126 / 136 / 2100 / 3100

Mid-sized organizations and regional offices. 1U rack form factor, expansion slots for additional interfaces, redundant power options. Ideal for 100 to 1,000 users.

100 to 1,000 users
L

XGS 4300 / 5500 / 6500 / 7500 / 8500

Enterprise and data-center deployments. Multi-Gbps inspected throughput, fibre-channel options, full chassis redundancy. Plus virtual and cloud-deployable instances for AWS, Azure, and VMware.

1,000+ users / data center
Who Deploys It

Common deployment patterns

Sophos Firewall isn’t a one-shape-fits-all box. These are the three deployments we see most often.

1

Replacing a legacy firewall

End-of-life Cisco, Fortinet, or SonicWall? We migrate rules, NAT, VPNs, and policies with parallel validation, then cut over in a planned maintenance window with rollback ready.

Planned, reversible cutovers
2

Distributed networks

Headquarters with multiple branch offices. XGS plus SD-RED branch devices give every site the same security posture with central policy, while ZTNA replaces site-to-site VPN.

Branch-friendly by design
3

Regulated environments

Healthcare, finance, government, and education estates needing segmentation, deep inspection, and audit-grade logging. XGS produces the records auditors want, in formats they recognize.

Audit-ready logging
Pairs Well With

Build the rest of the network stack

Sophos Firewall is the centerpiece. These are the network-side products our customers most often pair with it.

Sophos NDR
Detection

Sophos NDR

Catches threats the firewall can’t see by signature alone: encrypted-traffic anomalies, command-and-control, and lateral movement on internal segments.

Sophos Wireless Access Points
Wireless

Wireless Access Points

Wi-Fi 6 APs managed from the same Sophos Central as the firewall. Optional firewall-backed deep inspection for wireless traffic, on every SSID you choose.

Sophos ZTNA
Access

Sophos ZTNA

The firewall’s built-in ZTNA gateway extends to remote users without an MPLS tail-circuit. Replace your SSL VPN with identity- and posture-based access.

Ready to modernize your perimeter?

Start a free Sophos Firewall evaluation in your environment, request appliance-specific pricing for your throughput and user counts, or talk to our team about migrating off your existing firewall.