- Providing the firewall to my small business office. We run it on a fanless PC and a supporting 50Mb/s VDSL connection.
- Supports 10 devices and has 40 rules.
- Using UTM and IPS extensively.
Consultant at a manufacturing company with 1,001-5,000 employees
Supports all the traditional firewall components, but the install was slow due to the GUI
Pros and Cons
- "The UTM features are reasonably strong and the patterns are updated on a regular basis"
- "The lack of import/export functions for network and service options drives me mad."
What is our primary use case?
What is most valuable?
- Using the Home version to help Sophos develop the XG. I have not used the earlier UTM, which colleagues have recommended.
- The UTM features are reasonably strong and the patterns are updated on a regular basis
- Supports all the traditional firewall components
How has it helped my organization?
Not applicable.
What needs improvement?
- The lack of import/export functions for network and service options drives me mad.
- No route to NULL
- No Dshield.org integration
Buyer's Guide
Sophos UTM
October 2024
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: October 2024.
816,406 professionals have used our research since 2012.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
Not applicable.
How are customer service and support?
Not applicable.
Which solution did I use previously and why did I switch?
Originally Cisco 871 IOS IP Advanced Security, then Juniper SSG20, which was getting old and service contracts were too expensive.
How was the initial setup?
Slow because of GUI and lack of .csv style object import.
What about the implementation team?
In-house
What was our ROI?
Not applicable.
What's my experience with pricing, setup cost, and licensing?
If you can afford it, go for a small Check Point, as it is easier to manage.
Which other solutions did I evaluate?
Linux ipchains and modern equivalents.
What other advice do I have?
Takes awhile to build a comprehensive rule set because of the relatively slow Web GUI.
If you build, backup, restore and reconfig between the boxes.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Quality Officer at a tech services company with 10,001+ employees
I know I am secure against threats from the internet
What is most valuable?
The IPS and endpoint protection function.
A standard Firewall of an access router, monitoring up to OSI level 4, is unacceptable anymore these days. The endpoint protection solution is integrated, thus running along with the notification function.
How has it helped my organization?
All the necessary functions being incorporated into one solution with notifications configured, I know I am secure against threats from the internet. (Up to the limits of the solution in the constantly evolving and dangerous Internet).
What needs improvement?
- A cleaning up function to remove unused references.
- A dashboard to show that the various parts of the solution really do their tasks and not only have been activated or configured (e.g., From the live log of the IPS function it is difficult to understand if the solution (snort) is running or experiences a problem and has stopped working.
- The possibility to add the sandbox (and possible future) function, paid for, to the free Home version.
For how long have I used the solution?
I've used this solution for three years.
What do I think about the stability of the solution?
Some with the IPS function (snort).
In my case, when restarting the system (because of an update), I doubt that snort starts correctly and do a manual restart of the IPS function (see my answer for 'Room for Improvement').
What do I think about the scalability of the solution?
How are customer service and technical support?
As a free home user, I have not used the support services up until now.
Once, I did upload an Office document that appeared to give a false positive, but never got a notification. I understand this because of the priorities that have to be given, but I would have liked to receive a (even small) reaction.
Which solution did I use previously and why did I switch?
I did take a look at other open source solutions, but found the Sophos UTM, being the best professional free for Home UTM solutions, full blown, and updated daily, to be the best solution.
How was the initial setup?
The setup wizard provided me with just enough insight into the basics of the solution -- to be able to start using the solution fully after some self-study and exploration of the various knowledge bases and forums.
What's my experience with pricing, setup cost, and licensing?
I looked at some open source variants but being able to use the best professional (free for the home version) product with regular updates -- convinced me to use the Sophos UTM solution at Home.
Which other solutions did I evaluate?
The instability and best effort service of a community of the open source solution did not give the right trust to depend on in the battle against the negative sides of the worldwide internet
What other advice do I have?
Start simple and step-by-step, and start using the product fully.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Sophos UTM
October 2024
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: October 2024.
816,406 professionals have used our research since 2012.
General Manager of Technical Division at VTI
Good visibility and protection against ransomware attacks
Pros and Cons
- "Sophos UTM's best feature is SIM in the cloud, which combines the gateway solution and endpoint solution to send telemetry data to the cloud and provides full contact visibility regarding security."
- "Sophos UTM's firewall is a bit weak, and some of its features lack depth compared to other products like F5."
How has it helped my organization?
Sophos UTM gives good visibility and prevention against ransomware attacks because they focus on unknown threats, so it's successful in protecting customers.
What is most valuable?
Sophos UTM's best feature is SIM in the cloud, which combines the gateway solution and endpoint solution to send telemetry data to the cloud and provides full contact visibility regarding security.
What needs improvement?
Sophos UTM's firewall is a bit weak, and some of its features lack depth compared to other products like F5.
For how long have I used the solution?
I've been using Sophos UTM for about eight years.
What do I think about the stability of the solution?
Sophos UTM is quite stable.
What do I think about the scalability of the solution?
Sophos UTM is quite simple to scale.
How are customer service and support?
Sophos' technical support is good.
How was the initial setup?
The initial setup takes around seven to nine days.
What was our ROI?
I would rate our ROI from Sophos UTM as three to four out of five.
What's my experience with pricing, setup cost, and licensing?
Sophos UTM's pricing is on the cheaper side.
What other advice do I have?
I would advise starting with the basic firewall before adding other features. I would give Sophos UTM a rating of seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partners/integrators
Senior IT Specialist at Shabana Group
Stable with good technical support, but the web filtering should be improved
Pros and Cons
- "This is a very stable product."
- "Anti-phishing functionality should be improved."
What is our primary use case?
We use Sophos UTM to protect our infrastructure.
What needs improvement?
There are things missing when it comes to policies.
The web filtering capability should be improved.
Anti-phishing functionality should be improved.
For how long have I used the solution?
We have been using Sophos Unified Threat Management (UTM) for two years.
What do I think about the stability of the solution?
This is a very stable product.
What do I think about the scalability of the solution?
Scaling this solution works fine.
How was the initial setup?
The initial setup is complex.
What's my experience with pricing, setup cost, and licensing?
Our licensing fees are paid on a monthly basis.
What other advice do I have?
Overall, this product is very good and I recommend it for other users.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT SM & Security Consultant at a tech services company with 1,001-5,000 employees
Sandstorm protects against crypto viruses in real-time
Pros and Cons
- "Advanced protection (Sophos Sandstorm) - Protects against crypto viruses in real-time."
- "There is still room for improvement in wireless protection. I don't mean their WiFi device is bad, but there are still things to improve on, such as WiFi roaming."
How has it helped my organization?
We replace customers' old and expensive devices such as firewalls, anti-spam, etc. with Sophos, as it has all these features. You don't need four boxes if you can have all these features in one box.
What is most valuable?
The most valuable features are
- Web Protection - Protects you against problems originating from the internet.
- Advanced protection (Sophos Sandstorm) - Protects against crypto viruses in real-time.
- Email Protection - Really strong anti-spam.
- REDs (Remote Ethernet Device) - Connects you from a remote workplace to your source network.
What needs improvement?
There is still room for improvement in wireless protection. I don't mean their WiFi device is bad, but there are still things to improve on, such as WiFi roaming.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
No issues with stability.
What do I think about the scalability of the solution?
No, everything works perfectly.
How is customer service and technical support?
They have consultants who can help you quickly.
How was the initial setup?
You can use the wizard which will guide you through all the initial settings.
What's my experience with pricing, setup cost, and licensing?
Sometimes more is less, meaning if you want more than three features, take the FullGuard licence.
What other advice do I have?
We do not use this on AWS.
Before implementing the SG appliance, completely prepare the rules for your network; know what and where you want to implement.
Disclosure: My company has a business relationship with this vendor other than being a customer: Gold Partner.
Global Network Security Admin at a consumer goods company with 501-1,000 employees
It can identify threats quickly, then find the affected devices and quarantine them
Pros and Cons
- "It has helped by identifying threats within the company. If there are computers or servers that are compromised, then we are able to identify them right away in the system."
- "The technical support only communicates via email. I would prefer to communicate directly with someone."
What is our primary use case?
I am using it for security, antivirus, and malware detection.
How has it helped my organization?
It has helped by identifying threats within the company. If there are computers or servers that are compromised, then we are able to identify them right away in the system.
What is most valuable?
It can identify threats quickly, then find the affected devices and quarantine them.
It ease of use: The GUI is easy to maneuver through; it is not complicated.
What needs improvement?
The support needs improvement.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It has been stable. We haven't had issues. It does what it is supposed to do.
What do I think about the scalability of the solution?
Since it is cloud-based, scalability works great. We have around 300 users in our environment.
How is customer service and technical support?
The technical support only communicates via email. I would prefer to communicate directly with someone.
Which other solutions did I evaluate?
We also considered Symantec and McAfee. We did not chose them because we had experience with both of them and were not happy with their platforms.
We chose Sophos for its ease of use and it detects malware and viruses that other companies can't detect.
What other advice do I have?
The product works. It helps you identify threats within the environment.
We were able to integrate it with different devices and the installation is straightforward.
We are using the cloud-based version, but it is through Sophos directly. We are not using AWS. A lot of this stuff is also on-premise.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Officer at Grupo Vision
Has good quality and functionality
Pros and Cons
- "The most valuable feature is the price. I've been requesting prices all over these years between different solutions like Fortinet, Palo Alto, and Check Point and Sophos has been the cheapest and the best of all of them that I have tried. I have been working with Fortinet, it's a fact that the price is surprisingly better."
- "Sophos should improve its ability to check something like bandwidth consumption for users or something more real-time."
What is our primary use case?
Our primary use cases include:
- Remote SSL connection
- Web-filtering
- Web server protection
- WAF application.
- Firewall rules
How has it helped my organization?
We have securely deploy systems accesible only behind encrypted ssl vpn and all user can access without the risk of data exposure.
What is most valuable?
The most valuable feature is the price. I've been requesting prices all over these years between different solutions like Fortinet, Palo Alto, and Check Point and Sophos has been the cheapest and the best of all of them that I have tried. I have been working with Fortinet, it's a fact that the sophos price is surprisingly better.
I have also worked with Check Point and it's not far enough from what Sophos can do. In terms of quality and functionality, Sophos is very useful and better than the competition.
What needs improvement?
Sophos should improve its ability to check something like bandwidth consumption for users or something more real-time.
real time trafic graph most show specific info from user, ip and bandwith, in my personal opinion i have seen better traffic graphs in open source firewalls.
For how long have I used the solution?
I have been using Sophos UTM for six years.
What do I think about the stability of the solution?
It's very stable. In all the time I have been using it, I haven't seen it fail or gets stuck.
What do I think about the scalability of the solution?
Scalability is not a complex issue and is something you can do within 20 minutes. I've been managing three UTMs, one with 50 users, another one with around 150, and the biggest one has 3,000 users.
Which solution did I use previously and why did I switch?
i used PFSense, the capabilities of UTM sophos y very much higher and powerfull.
How was the initial setup?
The initial setup was straightforward. It depends on the rules, but a basic setup can take up to seven to 15 minutes max.
What about the implementation team?
What was our ROI?
Based on cost compare with other vendor who bill per license and OTP users, the ROI have been set as far as 6 moths.
What's my experience with pricing, setup cost, and licensing?
SOphos is the best alternative in features, specifications and lower price.
Which other solutions did I evaluate?
yes i did, Fortinet, Checkpoint, Palo Alto, Meraki.
What other advice do I have?
It's a good solution, I would say to go for it.
I would rate Sophos UTM a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
We have a better level of protection and we have the ability for our devices to be more of a self-sustained type of resource.
Pros and Cons
- "I have no problem with the cost or licensing of this solution. This is a primary reason whay I wanted this solution. It does the same thing cheaper than other name brands."
- "The memory and processing were problematic. The interface could be better."
What is our primary use case?
My primary use case is as a VPN, a firewall and a web filter.
How has it helped my organization?
We have a better level of protection and we have the ability for our devices to be more of a self-sustained type of resource.
What is most valuable?
The most valuable features are:
- Firewall protection
- Intrusion detection
What needs improvement?
The memory and processing were problematic. The interface could be better.
What's my experience with pricing, setup cost, and licensing?
I have no problem with the cost or licensing of this solution. This is a primary reason whay I wanted this solution. It does the same thing cheaper than other name brands.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2024
Product Categories
Unified Threat Management (UTM)Popular Comparisons
Meraki MX
Check Point NGFW
WatchGuard Firebox
Juniper SRX Series Firewall
Untangle NG Firewall
KerioControl
Zyxel Unified Security Gateway
Stormshield Network Security
Huawei NGFW
Check Point CloudGuard Network Security
Sophos Cyberoam UTM
LANCOM R&S Unified Firewalls
Seqrite UTM
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
- What Is The Biggest Difference Between Sophos and pfSense?
- Who provides a better antivirus solution: Bitdefender or Sophos?
- What are the biggest differences between Meraki and Sophos? Which one is good for security and SD-WAN?
- What is the biggest difference between Fortinet FortiGate and Sophos UTM?
- When evaluating Unified Threat Management (UTM), what aspect do you think is the most important to look for?
- What UTM solution do you recommend?
- Why is a UTM solution important?
- Which tool is better for internet protection: Meraki MX or Fortinet?