Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Am I the only person who likes this new XG product?

Wow - reading the comments here...... sounds like I'm the only one outside of Sophos Corporate who likes this product.

And no - I'm not a Sophos employee _OR_ a Sophos plant.

In fact, I came to the firewalls grudgingly through their other products.  I am (or was) a Watchguard/pfSense/Cisco/Several Others kind of guy. I started with SGN (encryption) and SMC (the server-based mobile control) and then started looking at the firewalls because of a few integrated features.  I decided to go through the engineer cert training for both UTM and XG.  In fact, I think I went through the XG training the day - or the day after - the training itself was released.

After all that - I don't see why everyone is so down on this product.

Sophos has been exceeding clear on the fact that 1) NO SG is not going away any time soon. 2) if you like your SG or CR product, you can KEEP your SG/CR product and 3) YES there are missing features, expect new ones soon.

Are there limitations and weaknesses - YES. It's a VERSION 1 product! (they can call it version 15 all they want.  It's a v1 product)

Is it still a pretty cool damned product? YES. 

Will it improve drastically? Likely, YES.

Seriously guys - give it a few months.  It is brand new, needs a few tweaks, and change always sucks - but the compelling new features they've put in - heartbeat, cloud management, etc - are, or are going to be, excellent.

As of now, our NFR of the XG230 is happily running down in our server room, humming away, and acting as our primary gateway to the internet.  Working like champ so far. 



This thread was automatically locked due to age.
Parents
  • I really wanted to like XG. I liked the new interface and finally started to figure out the logic of building policies. My biggest issue was that the performance was terrible using the same rules I had on UTM 9. I'm not sure if it is due to the 4-core limitation. That probably isn't a big deal on an Intel i3/5/7/Xeon but when you're running it on a server grade Atom processor it would be nice to be able to spread the load out over all 8 cores. System load was a constant 2 with no traffic running. If I started a download running then my ping to Google shot up to 1,200ms and I couldn't browse the internet. When I ran the top command my CPU usage was usually 2%-15% and I couldn't figure out where the load value of 2 was coming from. Maybe it's a bug that will be fixed in the future? My second biggest gripe with XG was that I was never able to get SMTPS filtering running for my mail server. It could be that I just don't understand the differences between when you need to use certificates and certificate authorities. I was able to get my certificate into the certificate section so I could use the WAF with my web server, but I was unable to get it working for email. In UTM 9 I just uploaded my cert in the cert section and then I could use it for the WAF and SMTPS. I'm not sure why in XG it wants me to select a cert I've uploaded to the CA section for SMTPS and select a cert I've uploaded to the cert section for WAF?
Reply
  • I really wanted to like XG. I liked the new interface and finally started to figure out the logic of building policies. My biggest issue was that the performance was terrible using the same rules I had on UTM 9. I'm not sure if it is due to the 4-core limitation. That probably isn't a big deal on an Intel i3/5/7/Xeon but when you're running it on a server grade Atom processor it would be nice to be able to spread the load out over all 8 cores. System load was a constant 2 with no traffic running. If I started a download running then my ping to Google shot up to 1,200ms and I couldn't browse the internet. When I ran the top command my CPU usage was usually 2%-15% and I couldn't figure out where the load value of 2 was coming from. Maybe it's a bug that will be fixed in the future? My second biggest gripe with XG was that I was never able to get SMTPS filtering running for my mail server. It could be that I just don't understand the differences between when you need to use certificates and certificate authorities. I was able to get my certificate into the certificate section so I could use the WAF with my web server, but I was unable to get it working for email. In UTM 9 I just uploaded my cert in the cert section and then I could use it for the WAF and SMTPS. I'm not sure why in XG it wants me to select a cert I've uploaded to the CA section for SMTPS and select a cert I've uploaded to the cert section for WAF?
Children
No Data