Sophos Firewall Features
Sophos Firewall Features
Ì Xstream DPI Engine provides stream scanning Ì Dynamic firewall rule support for endpoint health
protection for IPS, AV, Web, App Control, and TLS (Sophos Security Heartbeat) automatically isolates and
Inspection in a single-high performance engine limits network access to compromised endpoints
Ì Xstream Network Flow FastPath delivers policy-driven Ì Synchronized Application Control automatically,
and intelligent acceleration of trusted traffic automatically identifies, classifies, and controls all unknown
Mac/Windows applications on the network
Ì Purpose-built user interface with interactive control
center utilizes traffic-light indicators (red, yellow, green) Ì Cloud Application Visibility enables Shadow IT discovery
to instantly identify what needs attention at a glance instantly and offers one-click traffic shaping
Ì Control Center offers instant insights into endpoint Ì Policy test simulator tool enables firewall rule and web
health, unidentified Mac and Windows applications, policy simulation and testing by user, IP, and time of day
cloud applications and Shadow IT, suspicious
Ì User Threat Quotient identifies risky users based
payloads, risky users, advanced threats, network
on recent browsing behavior and ATP triggers
attacks, objectionable websites, and much more
Ì Configuration API for all features for RMM/PSA integration
Ì Optimized two-clicks-to-anywhere navigation
Ì Discover Mode (TAP mode) for seamless integration in
Ì Policy Control Center widget monitors policy activity
trials and PoCs with support for Synchronized Security
for business, user and network policies and tracks
unused, disabled, changed, and new policies Ì SD-WAN connects remote/branch sites across
a geographically-distributed network
Ì Unified policy model combines all business, user,
and network firewall rules onto a single screen Ì Remote Access VPN with a free and
with grouping, filtering, and search options easy client for Windows/Macs
Ì Streamlined firewall rule management for large rule Ì Sophos Central cloud-based management and reporting
sets with custom auto and manual grouping plus at-a- for multiple firewalls provides group policy management
glance mouse-over feature and enforcement indicators and one console for all your Sophos IT security products
Ì All firewall rules provide an at-a-glance summary of Ì Easy streamlined setup wizard enables fast out-
the applied security and control for AV, sandboxing, of-the box deployment in just a few minutes
IPS, Web, App, Traffic Shapping (QoS), and Heartbeat
Ì Zero-touch deployment and configuration
Ì Pre-defined IPS, Web, App, and Traffic Shaping in Sophos Central for new firewalls
(QoS) policies enable quick setup and easy
Sophos Firewall Features
Ì Group policy management allows objects, settings, Ì Routing: static, multicast (PIM-SM),
and policies to be modified once and automatically and dynamic (RIP, BGP, OSPF)
synchronized to all firewalls in the group
Ì Upstream proxy support
Ì Task Manager provides a full historical audit trail
Ì Protocol-independent multicast
and status monitoring of group policy changes
routing with IGMP snooping
2
Sophos Firewall Features
Ì Bridging with STP support and ARP broadcast forwarding Secure Wireless
Ì Simple plug-and-play deployment of Sophos
Ì VLAN DHCP support and tagging
wireless access points (APs) — automatically
Ì VLAN bridge support appear on the firewall control center
Ì Wireless WAN support (n/a in virtual deployments) Ì Multiple SSID support per radio including hidden SSIDs
Ì 802.3ad interface link aggregation Ì Support for diverse security and encryption standards
including WPA2 Personal and Enterprise
Ì Full configuration of DNS, DHCP, and NTP
Ì Channel width selection option
Ì Dynamic DNS (DDNS)
Ì Support for IEEE 802.1X (RADIUS authentication)
Ì IPv6 Ready Logo Program Approval Certification
with primary and secondary server support
Ì IPv6 tunnelling support including 6in4, 6to4, 4in6,
Ì Support for 802.11r (fast transition)
and IPv6 rapid deployment (6rd) through IPSec
Ì Hotspot support for (custom) vouchers,
SD-WAN
password of the day, or T&C acceptance
Ì Support for multiple WAN link options including
VDSL, DSL, cable, and 3G/4G/LTE cellular with Ì Wireless guest Internet access with walled garden options
essential monitoring, balancing, and failover
Ì Time-based wireless network access
Ì Application path selection and routing, which is
Ì Wireless repeating and bridging meshed
used to ensure quality and minimize latency for
network mode with supported APs
mission-critical applications such as VoIP
Ì Automatic channel selection background optimization
Ì Synchronized SD-WAN, a Synchronized Security
feature, leverages the added clarity and reliability of Ì Support for HTTPS login
application identification that comes with the sharing of
Authentication
Synchronized Application Control information between
Ì Synchronized User ID utilizes Synchronized Security
Sophos-managed endpoints and Sophos Firewall
to share currently logged in Active Directory user
Ì Application routing over preferred links via ID between Sophos endpoints and the firewall
firewall rules or policy-based routing without an agent on the AD server or client
Ì Robust VPN support including IPSec and SSL VPN Ì Server authentication agents for Active
Directory SSO, STAS, SATC
Ì Centralized VPN orchestration
Ì Single sign-on: Active directory,
Ì Unique RED Layer 2 tunnel with routing
eDirectory, RADIUS Accounting
Base Traffic Shaping and Quotas
Ì Client authentication agents for
Ì Flexible network or user based traffic shaping (QoS)
Windows, Mac OS X, Linux 32/64
(enhanced Web and App traffic shaping options
included with the Web Protection subscription) Ì Browser SSO authentication: Transparent,
proxy authentication (NTLM) and Kerberos
Ì Set user-based traffic quotas on upload/download
or total traffic and cyclical or non-cyclical Ì Browser Captive Portal
3
Sophos Firewall Features
Ì Access quarantined messages and manage user-based Ì Sophos Security Heartbeat policies can limit
block/allow sender lists (requires Email Protection) access to network resources or completely isolate
compromised systems until they are cleaned
Base VPN Options
Ì Site-to-site VPN: SSL, IPSec, 256- bit AES/3DES, Ì Lateral Movement Protection further isolates
PFS, RSA, X.509 certificates, pre-shared key compromised systems by having healthy Sophos
-managed endpoints reject all traffic from
Ì Sophos RED site-to-site VPN tunnel
unhealthy endpoints preventing the movement of
(robust and light-weight)
threats even on the same broadcast domain
Ì L2TP and PPTP
SD-RED Device Management
Ì Route-based VPN Ì Central management of all SD-RED devices
4
Sophos Firewall Features
Ì Surfing quota time policies per user/group Ì Filter cloud application usage by category or volume
Ì HTTP and HTTPS scanning and enforcement Ì Micro app discovery and control
on any network and user policy with fully
Ì Application control based on category, characteristics
customizable rules and exceptions
(e.g., bandwidth and productivity consuming),
Ì SSL protocol tunnelling detection and enforcment technology (e.g. P2P), and risk level
5
Sophos Firewall Features
Ì Optional data center selection and flexible Ì Reputation service with spam outbreak monitoring based
user and group policy options on file type, on patented Recurrent-Pattern-Detection technology
exclusions, and actions on analysis
Ì Block spam and malware during the SMTP transaction
Ì Supports one-time download links
Ì DKIM and BATV anti-spam protection
Static Threat Intelligence Analysis
Ì Spam greylisting and Sender Policy
Ì All files containing active code downloaded via the
Framework (SPF) protection
web or coming into the firewall as email attachments
such as executables and documents containing Ì Recipient verification for mistyped email addresses
executable content (including .exe, .com, and .dll, .doc,
Ì Second independent malware detection
.docx, docm, and .rtf and PDF) and archives containing
engine (Avira) for dual scanning
any of the file types listed above (including ZIP, BZIP,
GZIP, RAR, TAR, LHA/LZH, 7Z, Microsoft Cabinet) are Ì Live Protection real-time, in-the-cloud
automatically sent for Threat Intelligence Analysis lookups for the latest threat intelligence
Ì Files are checked against SophosLabs’ massive threat Ì Automatic signature and pattern updates
intelligence database and subjected to multiple machine
Ì Smart host support for outbound relays
learning models to identify new and unknown malware
Ì File type detection/blocking/scanning of attachments
Ì Extensive reporting includes a dashboard widget for
analyzed files, a detailed list of the files that have been Ì Accept, reject or drop over-sized messages
analyzed and the analysis results, and a detailed report
Ì Detects phishing URLs within e-mails
outlining the outcome of each machine learning model.
Ì Use pre-defined content scanning rules or create
Ì Support for Sophos 24/7 Managed Ì Recipient self-registration SPX password management
Threat Response (MTR) service
Ì Add attachments to SPX secure replies
6
Sophos Firewall Features
Ì HTTPS (TLS/SSL) encryption offloading Ì Export reports in PDF, CFV or HTML format
Ì Cookie signing with digital signatures Ì Up to 1 year data storage per firewall
Ì Integrated load balancer spreads Ì Hundreds of on-box reports with custom report options:
visitors across multiple servers Dashboards (Traffic, Security, and User Threat Quotient),
Applications (App Risk, Blocked Apps, Synchronized
Ì Skip individual checks in a granular fashion as required
Apps, Search Engines, Web Servers, Web Keyword
Ì Match requests from source networks Match, FTP), Network and Threats (IPS, ATP, Wireless,
or specified target URLs Security Heartbeat, Sandstorm), VPN, Email, Compliance
(HIPAA, GLBA, SOX, FISMA, PCI, NERC CIP v3, CIPA)
Ì Support for logical and/or operators
Ì Current Activity Monitoring: system health, live users,
Ì Assists compatibility with various configurations
IPSec connections, remote users, live connections,
and non-standard deployments
wireless clients, quarantine, and DoS attacks
Ì Options to change Web Application
Ì Report anonymization
Firewall performance parameters
Ì Report scheduling to multiple recipients by
Ì Scan size limit option
report group with flexible frequency options
Ì Allow/Block IP ranges
Ì Export reports as HTML, PDF, Excel (XLS)
Ì Wildcard support for server paths and domains
Ì Report bookmarks
Ì Automatically append a prefix/suffix for authentication
Ì Log retention customization by category
7
Sophos Firewall Features
Base Network Web Zero-Day Central Central Firewall Email Web Server
Firewall Protection Protection Protection Orchestration* Reporting Adv. Protection Protection
* Expected soon
Please note:
Ì Some features are not supported on XGS 87 and XG 86 models (on-box reporting, dual AV scanning,
WAF AV scanning and email message transfer agent (MTA) functionality)
Ì MSP licensing options differ slightly to the above
Ì For XG Series hardware/virtual licensing, see the brochure under [Link]/compare-xg
United Kingdom and Worldwide Sales North American Sales Australia and New Zealand Sales Asia Sales
Tel: +44 (0)8447 671131 Toll Free: 1-866-866-2802 Tel: +61 2 9409 9100 Tel: +65 62244168
Email: sales@[Link] Email: nasales@[Link] Email: sales@[Link] Email: salesasia@[Link]







