0% found this document useful (0 votes)
57 views8 pages

Sophos Firewall Features

Uploaded by

Hung Tran Quoc
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
57 views8 pages

Sophos Firewall Features

Uploaded by

Hung Tran Quoc
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Sophos Firewall Highlights
  • Base Firewall
  • Secure Wireless
  • Web Protection
  • Network Protection
  • Central Orchestration
  • Reporting
  • Subscription Summary

Sophos Firewall Features

Sophos Firewall customization for common deployment scenarios


(e.g. CIPA, typical workplace policies, and more)
Highlights
Ì Xstream Architecture provides extreme levels Ì IPS, Web, App, and Traffic Shaping (QoS) policies
of visibility, protection, and performance snap into firewall rules and can be edited in-
through stream-based packet processing place providing a powerful yet intuitive model for
configuring and managing security and control
Ì Xstream TLS inspection offers high performance,
support for TLS 1.3 with no downgrading, Ì Sophos Security HeartbeatTM connects Sophos
port agnostic, enterprise-grade policies with endpoints with the firewall to share health status
pre-packaged exceptions, unique dashboard and telemetry enabling instant identification
visibility, and compatibility troubleshooting of unhealthy or compromised endpoints

Ì Xstream DPI Engine provides stream scanning Ì Dynamic firewall rule support for endpoint health
protection for IPS, AV, Web, App Control, and TLS (Sophos Security Heartbeat) automatically isolates and
Inspection in a single-high performance engine limits network access to compromised endpoints

Ì Xstream Network Flow FastPath delivers policy-driven Ì Synchronized Application Control automatically,
and intelligent acceleration of trusted traffic automatically identifies, classifies, and controls all unknown
Mac/Windows applications on the network
Ì Purpose-built user interface with interactive control
center utilizes traffic-light indicators (red, yellow, green) Ì Cloud Application Visibility enables Shadow IT discovery
to instantly identify what needs attention at a glance instantly and offers one-click traffic shaping

Ì Control Center offers instant insights into endpoint Ì Policy test simulator tool enables firewall rule and web
health, unidentified Mac and Windows applications, policy simulation and testing by user, IP, and time of day
cloud applications and Shadow IT, suspicious
Ì User Threat Quotient identifies risky users based
payloads, risky users, advanced threats, network
on recent browsing behavior and ATP triggers
attacks, objectionable websites, and much more
Ì Configuration API for all features for RMM/PSA integration
Ì Optimized two-clicks-to-anywhere navigation
Ì Discover Mode (TAP mode) for seamless integration in
Ì Policy Control Center widget monitors policy activity
trials and PoCs with support for Synchronized Security
for business, user and network policies and tracks
unused, disabled, changed, and new policies Ì SD-WAN connects remote/branch sites across
a geographically-distributed network
Ì Unified policy model combines all business, user,
and network firewall rules onto a single screen Ì Remote Access VPN with a free and
with grouping, filtering, and search options easy client for Windows/Macs

Ì Streamlined firewall rule management for large rule Ì Sophos Central cloud-based management and reporting
sets with custom auto and manual grouping plus at-a- for multiple firewalls provides group policy management
glance mouse-over feature and enforcement indicators and one console for all your Sophos IT security products

Ì All firewall rules provide an at-a-glance summary of Ì Easy streamlined setup wizard enables fast out-
the applied security and control for AV, sandboxing, of-the box deployment in just a few minutes
IPS, Web, App, Traffic Shapping (QoS), and Heartbeat
Ì Zero-touch deployment and configuration
Ì Pre-defined IPS, Web, App, and Traffic Shaping in Sophos Central for new firewalls
(QoS) policies enable quick setup and easy
Sophos Firewall Features

Base Firewall Ì Backup firmware management in Sophos Central


stores the last five configuration backup files
General Management
for each firewall with one that can be pinned
Ì Purpose-built, streamlined user interface and firewall
for permanent storage and easy access
rule management for large rule sets with grouping with
at-a-glance rule feature and enforcement indicators Ì Firmware updates from Sophos Central offer one-
click firmware updates to be applied to any device
Ì Two-factor authentication (One-time-password) support
for administrator access, user portal, IPSec and SSL VPN Ì Zero-touch deployment enables the initial
configuration to be performed in Sophos Central
Ì Advanced troubleshooting tools in
and then exported for loading onto the device
GUI (e.g., Packet Capture)
from a flash drive at startup, automatically
Ì High Availability (HA) support clustering two connecting the device back to Sophos Central
devices in active-active or active-passive
Firewall, Networking, and Routing
mode with plug-and-play Quick HA setup
Ì Stateful deep packet inspection firewall
Ì Full command line interface (CLI) accessible from GUI
Ì Xstream packet processing architecture provides
Ì Role-based administration extreme levels of visibility, protection, and performance
through stream-based packet processing
Ì Automated firmware update notification with easy
automated update process and roll-back features Ì Xstream TLS inspection with high performance,
support for TLS 1.3 with no downgrading, port
Ì Reusable system object definitions for networks, services,
agnostic, enterprise-grade polices, unique dashboard
hosts, time periods, users and groups, clients, and servers
visibility, and compatibility troubleshooting
Ì Self-service user portal
Ì Xstream DPI Engine provides stream scanning
Ì Configuration change tracking protection for IPS, AV, Web, App Control, and TLS
Inspection in a single high-performance engine
Ì Flexible device access control for services by zones
Ì Xstream Network Flow FastPath delivers policy-driven
Ì Email or SNMP trap notification options
and intelligent acceleration of trusted traffic automatically
Ì SNMP v3 and Netflow support
Ì User, group, time, or network-based policies
Ì Central management support via Sophos Central
Ì Access time polices per user/group
Ì Backup and restore configurations: locally, via FTP
Ì Enforce policy across zones, networks, or by service type
or email; on-demand, daily, weekly or monthly
Ì Zone isolation and zone-based policy support.
Ì API for third-party integration
Ì Default zones for LAN, WAN, DMZ, LOCAL, VPN, and Wi-Fi
Ì Interface renaming
Ì Custom zones on LAN or DMZ
Ì Remote access option for Sophos Support
Ì Customizable NAT policies with IP masquerading and full
Ì Cloud-based license management via MySophos
object support to redirect or forward multiple services in
Sophos Central Management a single rule with a convenient NAT rule wizard to quickly
Ì Sophos Central cloud-based management and easily create complex NAT rules in just a few clicks
and reporting for multiple firewalls provides
Ì Flood protection: DoS, DDoS, and portscan blocking
group policy management and a single console
for all your Sophos IT security products Ì Country blocking by geo-IP

Ì Group policy management allows objects, settings, Ì Routing: static, multicast (PIM-SM),
and policies to be modified once and automatically and dynamic (RIP, BGP, OSPF)
synchronized to all firewalls in the group
Ì Upstream proxy support
Ì Task Manager provides a full historical audit trail
Ì Protocol-independent multicast
and status monitoring of group policy changes
routing with IGMP snooping

2
Sophos Firewall Features

Ì Bridging with STP support and ARP broadcast forwarding Secure Wireless
Ì Simple plug-and-play deployment of Sophos
Ì VLAN DHCP support and tagging
wireless access points (APs) — automatically
Ì VLAN bridge support appear on the firewall control center

Ì Jumbo frame support Ì Central monitoring and management of APs and


wireless clients through the built-in wireless controller
Ì WAN link balancing: multiple Internet connections,
auto-link health check, automatic failover, automatic Ì Bridge APs to LAN, VLAN, or a separate
and weighted balancing, and granular multipath rules zone with client isolation options

Ì Wireless WAN support (n/a in virtual deployments) Ì Multiple SSID support per radio including hidden SSIDs

Ì 802.3ad interface link aggregation Ì Support for diverse security and encryption standards
including WPA2 Personal and Enterprise
Ì Full configuration of DNS, DHCP, and NTP
Ì Channel width selection option
Ì Dynamic DNS (DDNS)
Ì Support for IEEE 802.1X (RADIUS authentication)
Ì IPv6 Ready Logo Program Approval Certification
with primary and secondary server support
Ì IPv6 tunnelling support including 6in4, 6to4, 4in6,
Ì Support for 802.11r (fast transition)
and IPv6 rapid deployment (6rd) through IPSec
Ì Hotspot support for (custom) vouchers,
SD-WAN
password of the day, or T&C acceptance
Ì Support for multiple WAN link options including
VDSL, DSL, cable, and 3G/4G/LTE cellular with Ì Wireless guest Internet access with walled garden options
essential monitoring, balancing, and failover
Ì Time-based wireless network access
Ì Application path selection and routing, which is
Ì Wireless repeating and bridging meshed
used to ensure quality and minimize latency for
network mode with supported APs
mission-critical applications such as VoIP
Ì Automatic channel selection background optimization
Ì Synchronized SD-WAN, a Synchronized Security
feature, leverages the added clarity and reliability of Ì Support for HTTPS login
application identification that comes with the sharing of
Authentication
Synchronized Application Control information between
Ì Synchronized User ID utilizes Synchronized Security
Sophos-managed endpoints and Sophos Firewall
to share currently logged in Active Directory user
Ì Application routing over preferred links via ID between Sophos endpoints and the firewall
firewall rules or policy-based routing without an agent on the AD server or client

Ì Affordable, flexible, and zero-touch Ì Authentication via: Active Directory,


or low-touch deployment eDirectory, RADIUS, LDAP and TACACS+

Ì Robust VPN support including IPSec and SSL VPN Ì Server authentication agents for Active
Directory SSO, STAS, SATC
Ì Centralized VPN orchestration
Ì Single sign-on: Active directory,
Ì Unique RED Layer 2 tunnel with routing
eDirectory, RADIUS Accounting
Base Traffic Shaping and Quotas
Ì Client authentication agents for
Ì Flexible network or user based traffic shaping (QoS)
Windows, Mac OS X, Linux 32/64
(enhanced Web and App traffic shaping options
included with the Web Protection subscription) Ì Browser SSO authentication: Transparent,
proxy authentication (NTLM) and Kerberos
Ì Set user-based traffic quotas on upload/download
or total traffic and cyclical or non-cyclical Ì Browser Captive Portal

Ì Real-time VoIP optimization Ì Authentication certificates for iOS and Android

Ì DSCP marking Ì Authentication services for IPSec, SSL, L2TP, PPTP

3
Sophos Firewall Features

Ì Google Chromebook authentication support for Ì Granular category selection


environments with Active Directory and Google G Suite
Ì Support for custom IPS signatures
Ì API-based authentication
Ì IPS Policy Smart Filters enable dynamic policies that
User Self-Serve Portal automatically update as new patterns are added
Ì Download the Sophos Authentication Client
ATP and Security Heartbeat
Ì Download SSL remote access client (Windows) Ì Advanced Threat Protection (detect and block network
and configuration files (other OS) traffic attempting to contact command and control
servers using multi-layered DNS, AFC, and firewall)
Ì Hotspot access information
Ì Sophos Security Heartbeat instantly identifies
Ì Change user name and password
compromised endpoints including the host, user,
Ì View personal Internet usage process, incident count, and time of compromise

Ì Access quarantined messages and manage user-based Ì Sophos Security Heartbeat policies can limit
block/allow sender lists (requires Email Protection) access to network resources or completely isolate
compromised systems until they are cleaned
Base VPN Options
Ì Site-to-site VPN: SSL, IPSec, 256- bit AES/3DES, Ì Lateral Movement Protection further isolates
PFS, RSA, X.509 certificates, pre-shared key compromised systems by having healthy Sophos
-managed endpoints reject all traffic from
Ì Sophos RED site-to-site VPN tunnel
unhealthy endpoints preventing the movement of
(robust and light-weight)
threats even on the same broadcast domain
Ì L2TP and PPTP
SD-RED Device Management
Ì Route-based VPN Ì Central management of all SD-RED devices

Ì Remote access: SSL, IPSec, iPhone/iPad/ Ì No configuration: Automatically connects


Cisco/Android VPN client support through a cloud-based provisioning service

Ì IKEv2 Support Ì Secure encrypted tunnel using digital X.509


certificates and AES 256-bit encryption
Ì SSL client for Windows and configuration
download via user portal Ì Virtual Ethernet for reliable transfer of
all traffic between locations
Sophos Connect Client
Ì Authentication: Pre-Shared Key (PSK), Ì IP address management with centrally defined
PKI (X.509), Token and XAUTH DHCP and DNS Server configuration

Ì Enables Synchronized Security and Security Ì Remotely de-authorize SD-RED devices


Heartbeat for remote connected users after a select period of inactivity

Ì Intelligent split-tunneling for optimum traffic routing Ì Compression of tunnel traffic

Ì NAT-traversal support Ì VLAN port configuration options

Ì Client-monitor for graphical overview of connection status Clientless VPN


Ì Sophos unique encrypted HTML5 self-service portal with
Ì Mac and Windows Support
support for RDP, HTTP, HTTPS, SSH, Telnet, and VNC

Network Protection Web Protection


Intrusion Prevention (IPS)
Web Protection and Control
Ì High-performance, next-gen IPS deep packet
Ì Fully transparent proxy for anti-malware and web filtering
inspection engine with selective IPS patterns
that can be applied on a firewall rule basis for Ì Enhanced Advanced Threat Protection
maximum performance and protection
Ì URL Filter database with millions of sites across
Ì Thousands of signatures 92 categories, backed by SophosLabs

4
Sophos Firewall Features

Ì Surfing quota time policies per user/group Ì Filter cloud application usage by category or volume

Ì Access time polices per user/group Ì Detailed customizable cloud application


usage report for full historical reporting
Ì Malware scanning: block all forms of viruses,
web malware, trojans, and spyware on Application Protection and Control
HTTP/S, FTP and web-based email Ì Synchronized App Control to automatically, identify,
classify, and control all unknown Windows and Mac
Ì Advanced web malware protection
applications on the network by sharing information
with JavaScript emulation
between Sophos-managed endpoints and the firewall
Ì Live Protection real-time, in-the-cloud
Ì Signature-based application control with
lookups for the latest threat intelligence
patterns for thousands of applications
Ì Second independent malware detection
Ì Cloud Application Visibility and Control
engine (Avira) for dual-scanning
to discover Shadow IT
Ì Real-time or batch mode scanning
Ì App Control Smart Filters that enable dynamic policies
Ì Pharming protection which automatically update as new patterns are added

Ì HTTP and HTTPS scanning and enforcement Ì Micro app discovery and control
on any network and user policy with fully
Ì Application control based on category, characteristics
customizable rules and exceptions
(e.g., bandwidth and productivity consuming),
Ì SSL protocol tunnelling detection and enforcment technology (e.g. P2P), and risk level

Ì Certificate validation Ì Per-user or network rule application


control policy enforcement
Ì High performance web content caching
Web and App Traffic Shaping
Ì Forced caching for Sophos Endpoint updates
Ì Enhanced traffic shaping (QoS) options by web category
Ì File type filtering by mime-type, extension, and active or application to limit or guarantee upload/download or
content types (e.g. Activex, applets, cookies, etc.) total traffic priority and bitrate individually or shared

Ì YouTube for Schools enforcement per policy (user/group)

Ì SafeSearch enforcement (DNS-based) for major


Zero-Day Protection
search engines per policy (user/group) Dynamic Sandbox Analysis
Ì Full integration into your Sophos
Ì Web keyword monitoring and enforcement to log,
security solution dashboard
report or block web content matching keyword
lists with the option to upload customs lists Ì Inspects executables and documents containing
executable content (including .exe, .com, and .dll, .doc,
Ì Block Potentially Unwanted Applications (PUAs)
.docx, docm, and .rtf and PDF) and archives containing
Ì Web policy override option for teachers or any of the file types listed above (including ZIP, BZIP,
staff to temporarily allow access to blocked GZIP, RAR, TAR, LHA/LZH, 7Z, Microsoft Cabinet)
sites or categories that are fully customizable
Ì Aggressive behavioral, network, and memory analysis
and manageable by select users
Ì Detects sandbox evasion behavior
Ì User/Group policy enforcement on Google Chromebooks
Ì Machine Learning technology with Deep
Cloud Application Visibility
Learning scans all dropped executable files
Ì Control Center widget displays amount of data uploaded
and downloaded to cloud applications categorized Ì Includes exploit prevention and Cryptoguard
as new, sanctioned, unsanctioned or tolerated Protection technology from Sophos Intercept X

Ì Discover Shadow IT at a glance Ì In-depth malicious file reports with screen


shots and dashboard file release capability
Ì Drill down to obtain details on users, traffic, and data

Ì One-click access to traffic shaping policies

5
Sophos Firewall Features

Ì Optional data center selection and flexible Ì Reputation service with spam outbreak monitoring based
user and group policy options on file type, on patented Recurrent-Pattern-Detection technology
exclusions, and actions on analysis
Ì Block spam and malware during the SMTP transaction
Ì Supports one-time download links
Ì DKIM and BATV anti-spam protection
Static Threat Intelligence Analysis
Ì Spam greylisting and Sender Policy
Ì All files containing active code downloaded via the
Framework (SPF) protection
web or coming into the firewall as email attachments
such as executables and documents containing Ì Recipient verification for mistyped email addresses
executable content (including .exe, .com, and .dll, .doc,
Ì Second independent malware detection
.docx, docm, and .rtf and PDF) and archives containing
engine (Avira) for dual scanning
any of the file types listed above (including ZIP, BZIP,
GZIP, RAR, TAR, LHA/LZH, 7Z, Microsoft Cabinet) are Ì Live Protection real-time, in-the-cloud
automatically sent for Threat Intelligence Analysis lookups for the latest threat intelligence

Ì Files are checked against SophosLabs’ massive threat Ì Automatic signature and pattern updates
intelligence database and subjected to multiple machine
Ì Smart host support for outbound relays
learning models to identify new and unknown malware
Ì File type detection/blocking/scanning of attachments
Ì Extensive reporting includes a dashboard widget for
analyzed files, a detailed list of the files that have been Ì Accept, reject or drop over-sized messages
analyzed and the analysis results, and a detailed report
Ì Detects phishing URLs within e-mails
outlining the outcome of each machine learning model.
Ì Use pre-defined content scanning rules or create

Central Orchestration your own custom rules based on a variety of criteria


with granular policy options and exceptions
(Expected Soon)
Ì TLS encryption support for SMTP, POP, and IMAP
SD-WAN Orchestration
Ì SD-WAN and VPN orchestration with easy and automated Ì Append signature automatically to all outbound messages
wizard-based creation of site-to-site VPN tunnels
Ì Email archiver
between network locations using an optimal architecture
(hub-and-spoke, full mesh, or some combination). Ì Individual user-based block and allow sender
Supports IPSec, SSL or RED VPN tunnels. Integrates lists maintained through the user portal
seamlessly with SD-WAN features for application
Email Quarantine Management
prioritization, routing optimization, and leveraging
Ì Spam quarantine digest and notifications options
multiple WAN links for resiliency and performance.
Ì Malware and spam quarantines with search and
Central Firewall Reporting Advanced
filter options by date, sender, recipient, subject, and
Ì 30-days of cloud data storage for historical
reason with option to release and delete messages
firewall reporting with advanced features to
save, schedule and export custom reports. Ì Self-serve user portal for viewing and
releasing quarantined messages
XDR and MTR Connector
Ì Ready to integrate with Sophos Extended Email Encryption and DLP
Threat Detection and Response (XDR) for cross- Ì Patent-pending SPX encryption for
product threat hunting and analysis one-way message encryption

Ì Support for Sophos 24/7 Managed Ì Recipient self-registration SPX password management
Threat Response (MTR) service
Ì Add attachments to SPX secure replies

Email Protection Ì Completely transparent, no additional


software or client required
Email Protection and Control
Ì DLP engine with automatic scanning of emails
Ì Email scanning with SMTP, POP3, and IMAP support
and attachments for sensitive data

6
Sophos Firewall Features

Ì Pre-packaged sensitive data type content Ì Intuitive user interface provides


control lists (CCLs) for PII, PCI, HIPAA, and graphical representation of data
more, maintained by SophosLabs
Ì Report dashboard provides an at-a-glance
view of events over the past 24 hours
Web Server Protection Ì Easily identify network activities,
Web Application Firewall Protection trends, and potential attacks
Ì Reverse proxy
Ì Easy backup of logs with quick retrieval for audit needs
Ì URL hardening engine with deep-linking
Ì Simplified deployment without the
and directory traversal prevention
need for technical expertise
Ì Form hardening engine
Central Firewall Reporting Advanced
Ì SQL injection protection Ì Multi-firewall aggregate reporting

Ì Cross-site scripting protection Ì Save custom report templates

Ì Dual-antivirus engines (Sophos and Avira) Ì Scheduled reporting

Ì HTTPS (TLS/SSL) encryption offloading Ì Export reports in PDF, CFV or HTML format

Ì Cookie signing with digital signatures Ì Up to 1 year data storage per firewall

Ì Path-based routing Ì MTR/XDR Connector

Ì Outlook anywhere protocol support On-box Reporting


NOTE: Sophos Firewall reporting is included at no extra
Ì Reverse authentication (offloading) for form-based
charge but individual log, report, and widget availability
and basic authentication for server access
may be dependent on their respective protection module
Ì Virtual server and physical server abstraction licenses.

Ì Integrated load balancer spreads Ì Hundreds of on-box reports with custom report options:
visitors across multiple servers Dashboards (Traffic, Security, and User Threat Quotient),
Applications (App Risk, Blocked Apps, Synchronized
Ì Skip individual checks in a granular fashion as required
Apps, Search Engines, Web Servers, Web Keyword
Ì Match requests from source networks Match, FTP), Network and Threats (IPS, ATP, Wireless,
or specified target URLs Security Heartbeat, Sandstorm), VPN, Email, Compliance
(HIPAA, GLBA, SOX, FISMA, PCI, NERC CIP v3, CIPA)
Ì Support for logical and/or operators
Ì Current Activity Monitoring: system health, live users,
Ì Assists compatibility with various configurations
IPSec connections, remote users, live connections,
and non-standard deployments
wireless clients, quarantine, and DoS attacks
Ì Options to change Web Application
Ì Report anonymization
Firewall performance parameters
Ì Report scheduling to multiple recipients by
Ì Scan size limit option
report group with flexible frequency options
Ì Allow/Block IP ranges
Ì Export reports as HTML, PDF, Excel (XLS)
Ì Wildcard support for server paths and domains
Ì Report bookmarks
Ì Automatically append a prefix/suffix for authentication
Ì Log retention customization by category

Reporting Ì Full-featured log viewer with column view and


detailed view with powerful filter and search options,
Central Firewall Reporting hyperlinked rule ID, and data view customization
Ì Pre-defined reports with flexible customization options

Ì Reporting for Sophos Firewalls - hardware,


software, virtual, and cloud

7
Sophos Firewall Features

Sophos Firewall Features by Subscription Summary


Xstream Protection Bundle Available Separately

Standard Protection Bundle Available Separately

Base Network Web Zero-Day Central Central Firewall Email Web Server
Firewall Protection Protection Protection Orchestration* Reporting Adv. Protection Protection

General Management (incl. HA) ●


Xstream Architecture ●
Firewall, Networking and Routing ●
Base Traffic Shaping and Quotas ●
Secure Wireless ●
Authentication ●
Self-Serve User Portal ●
Base VPN Options ●
RED Site-to-Site VPN ●
Sophos Connect VPN Client ●
Intrusion Prevention (IPS) ●
ATP and Security Heartbeat™ ●
SD-RED Device Management ●
Clientless VPN ●
Synchronized Application Control ●
Web Protection and Control ●
Application Protection and Control ●
Cloud Application Visibility ●
Web and App Traffic Shaping ●
Dynamic Sandbox Analysis ●
Threat Intelligence Analysis ●
SD-WAN Orchestration ●
Central Firewall Reporting Data 7 Days 30 Days Up to 1 Year
CFR Advanced Features ● ●
XDR and MTR Connector ● ●
Email Protection and Control ●
Email Quarantine Management ●
Email Encryption and DLP ●
Web Application Firewall Protection ●
Logging and Reporting ● ● ● ● ● ● ● ●
Sophos Central Management ● ● ● ● ● ● ● ●

* Expected soon

Please note:
Ì Some features are not supported on XGS 87 and XG 86 models (on-box reporting, dual AV scanning,
WAF AV scanning and email message transfer agent (MTA) functionality)
Ì MSP licensing options differ slightly to the above
Ì For XG Series hardware/virtual licensing, see the brochure under [Link]/compare-xg

United Kingdom and Worldwide Sales North American Sales Australia and New Zealand Sales Asia Sales
Tel: +44 (0)8447 671131 Toll Free: 1-866-866-2802 Tel: +61 2 9409 9100 Tel: +65 62244168
Email: sales@[Link] Email: nasales@[Link] Email: sales@[Link] Email: salesasia@[Link]

© Copyright 2021. Sophos Ltd. All rights reserved.


Registered in England and Wales No. 2096520, The Pentagon, Abingdon Science Park, Abingdon, OX14 3YP, UK
Sophos is the registered trademark of Sophos Ltd. All other product and company names mentioned are
trademarks or registered trademarks of their respective owners.

21-04-09 FL-EN (PC)

Sophos Firewall
Highlights
	Ì Xstream Architecture provides extreme levels 
of visibility, protection, and performance 
throu
Sophos Firewall Features
2
Base Firewall
General Management
	Ì Purpose-built, streamlined user interface and firewall 
rule m
Sophos Firewall Features
3
	Ì Bridging with STP support and ARP broadcast forwarding
	Ì VLAN DHCP support and tagging
	Ì VLAN
Sophos Firewall Features
4
	Ì Google Chromebook authentication support for 
environments with Active Directory and Google G S
Sophos Firewall Features
5
	Ì Surfing quota time policies per user/group 
	Ì Access time polices per user/group
	Ì Malware sc
Sophos Firewall Features
6
	Ì Optional data center selection and flexible 
user and group policy options on file type, 
exclu
Sophos Firewall Features
7
	Ì Pre-packaged sensitive data type content 
control lists (CCLs) for PII, PCI, HIPAA, and 
more,
Sophos Firewall Features
Sophos Firewall Features by Subscription Summary
Xstream Protection Bundle
Available Separately
Stan

You might also like