Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Am I the only person who likes this new XG product?

Wow - reading the comments here...... sounds like I'm the only one outside of Sophos Corporate who likes this product.

And no - I'm not a Sophos employee _OR_ a Sophos plant.

In fact, I came to the firewalls grudgingly through their other products.  I am (or was) a Watchguard/pfSense/Cisco/Several Others kind of guy. I started with SGN (encryption) and SMC (the server-based mobile control) and then started looking at the firewalls because of a few integrated features.  I decided to go through the engineer cert training for both UTM and XG.  In fact, I think I went through the XG training the day - or the day after - the training itself was released.

After all that - I don't see why everyone is so down on this product.

Sophos has been exceeding clear on the fact that 1) NO SG is not going away any time soon. 2) if you like your SG or CR product, you can KEEP your SG/CR product and 3) YES there are missing features, expect new ones soon.

Are there limitations and weaknesses - YES. It's a VERSION 1 product! (they can call it version 15 all they want.  It's a v1 product)

Is it still a pretty cool damned product? YES. 

Will it improve drastically? Likely, YES.

Seriously guys - give it a few months.  It is brand new, needs a few tweaks, and change always sucks - but the compelling new features they've put in - heartbeat, cloud management, etc - are, or are going to be, excellent.

As of now, our NFR of the XG230 is happily running down in our server room, humming away, and acting as our primary gateway to the internet.  Working like champ so far. 



This thread was automatically locked due to age.
Parents
  • I don't really think that it's an issue of 'not liking' the new product.

    The problems that most have an issue with, is that it was released for use with missing and/or incomplete items that we are used to having with UTM 9. The fact is, this is not a finished product and will continue to be scrutinized for being released. I know it's 'bleeding edge' - the very reason why I haven't implemented it at home yet. The other issue, is that there has been so many requests for so long put into for UTM to have, those were ignored for a stable product and placed into this 'beta/bleeder' product.

    Hardware limitations are something that greatly disturbs me personally, as I just bought my new system right before Copernicus was put out, because I needed a big upgrade from an ATOM processor to what I have now. Now, I won't even get to use some of that hardware in place of IP restrictions being removed - something of which I don't have a problem with, yet I will be punished for whenever I upgrade. That should have been an option, not a mandatory thing. Not all of us are running out of IP addresses.

    Beta testers screamed bloody murder about some item-stopping issues for them - no one came back to them with addressing their concerns, some of which I am betting had to do with the forum board being moved in a hurry, but other parts of just flat out being ignored, or 'duly noted'. There are some people in the UTM community who know exactly what will work and what has been a problem - they want to see Sophos and UTM/XG succeed but get completely frustrated when ignored, told to not post, or something else that hinders them. Nature of the beast I suppose, but there are some hurt feelings going around lately between Sophos and its community members.
  • Not to be an apologist for them, but from my discussions with their people, it sounds like they had - and continue to have - a very aggressive development timeline - and made it especially clear that in V1, it WOULD NOT have parity with UTM. Combine that with the fact that you do not have to upgrade, and seriously - I see no reason for everyone's extreme frustration.

    As for those restrictions, lets actually look at them....You'll be "penalized" by only being able to use 6 of your 8GB of RAM in something they're providing you for FREE, and removing other restrictions that are probably hitting a good number of folks. In addition, that 4-core and 6gb is enough to run a PRETTY GOOD-SIZED firewall. That is the eqiv. of their third level up in their commercial software version. To license that same "free" product for use in business, you'll pay $2300 MSRP for the BASE license, and that does not even include web protection which the free home version includes.

    So tell me why this is a raw deal? I realize you had a restriction on IP addresses previously instead of the hardware restriction, but really? I seriously just don't see the problem there.


    For those folks complaining about the move to 64bit architecture - I can understand that, but seriously - x64 the 'now' and has been for several years. Next time folks buy hardware, they will probably be getting x64 BY DEFAULT whether they try or not... so hey, then, they can upgrade to XG. There is PLENTY of time to do that. 9.x is not going anywhere for a long time, and they've ALSO made it clear that NEW RELEASES will continue for a while.

    As for Sophos "not listening" - they are trying several new things with this new software... sometimes, you have to know when to tell people "duly noted" and forge on. Now they get to refine and improve and listen and see what happens. Give them a chance to.

    I've seen people call this release "stillborn" and "not viable." I've seen people hollering about how they've been loyal (free edition) customers for years and will be leaving now. Wow. Come on, guys.
  • ChavousCamp,

    the XG Firewall is a new product and if you did not see any Enterprise Firewall before, for anyone it is beatiful.
    As BillyBob said, we came from Astaro point of view and thinking and Sophos should remember that they won so many awards on Network Security thanks to UTM9.
    I personally manage other Sophos Products on big company, like SEC and Email Appliances and they are doing they job without pains.
    From UTM side, I work and know even other vendors and to be honest UTM9 has the best UI and all the feaures built-in that are competitor do not have.
    So know Sophos released XG (Copernicus line). How can you imagine to manage 1000 users with Copernicus at the moment?
    Many base feature are missing, such as Live Log, Renema Objects, MTA (BillYBob they planned to bring MTA back, please vote on feature.astaro.com/.../10614999-mta-bring-it-back), UI object placement (you need to remember where the things are), TABS, cloning, better Policy UI (ID does not match the order).

    I think that Sophos want to redisegn UI and Firewall to better compete with other vendors in order to get more business in this area but they need to eat a lot of dust before they can fight for a better placement.
    For me this product is still in beta and until version 2 or 3, I will not move any of my customers to XG (Sophos said to keep our Customers on UTM9).

    The other thinkg really strange is feedback from them. "Lack of information".
    Sometimes they publish some news and only few Sophos moderator reply to this forum. No one know how updates pattern works and what firmware fixes or what bugs exist at the moment (a pdf saying really few bugs).
    No roadmap. What do they will add into next release? Maybe they do not even know, but what we would like to know is HONESTY.

    In the meanwhile, we can pray and feedbacking until XG is ready and UTM9 will be end-of-support.
    If the XG will not be ready and nice as UTM9 we will think about. Future is a mistery!

    Luk
Reply
  • ChavousCamp,

    the XG Firewall is a new product and if you did not see any Enterprise Firewall before, for anyone it is beatiful.
    As BillyBob said, we came from Astaro point of view and thinking and Sophos should remember that they won so many awards on Network Security thanks to UTM9.
    I personally manage other Sophos Products on big company, like SEC and Email Appliances and they are doing they job without pains.
    From UTM side, I work and know even other vendors and to be honest UTM9 has the best UI and all the feaures built-in that are competitor do not have.
    So know Sophos released XG (Copernicus line). How can you imagine to manage 1000 users with Copernicus at the moment?
    Many base feature are missing, such as Live Log, Renema Objects, MTA (BillYBob they planned to bring MTA back, please vote on feature.astaro.com/.../10614999-mta-bring-it-back), UI object placement (you need to remember where the things are), TABS, cloning, better Policy UI (ID does not match the order).

    I think that Sophos want to redisegn UI and Firewall to better compete with other vendors in order to get more business in this area but they need to eat a lot of dust before they can fight for a better placement.
    For me this product is still in beta and until version 2 or 3, I will not move any of my customers to XG (Sophos said to keep our Customers on UTM9).

    The other thinkg really strange is feedback from them. "Lack of information".
    Sometimes they publish some news and only few Sophos moderator reply to this forum. No one know how updates pattern works and what firmware fixes or what bugs exist at the moment (a pdf saying really few bugs).
    No roadmap. What do they will add into next release? Maybe they do not even know, but what we would like to know is HONESTY.

    In the meanwhile, we can pray and feedbacking until XG is ready and UTM9 will be end-of-support.
    If the XG will not be ready and nice as UTM9 we will think about. Future is a mistery!

    Luk
Children
  • Hi Luk, thanks for pointing out the MTA feature request as accepted, I had already noticed it ;) I see you have a lot of other feature requests trying to improve everything. Thanks for not giving up and actively pressuring sophos into making SFOS better. Maybe they will listen to a few feature requests this time.
    Regards
    Bill
  • BillyBob,

    we will continue to support Sophos and customers if Sophos is going in the direction we are hoping to.

    We only have 2 ways to let them hear from us:

    1. this community

    2. feature requests.

    At the moment I have XG at home and I am trying to push what is really missing before to move some small customer to XG.

    So add feature request and vote the one that are already there.

    It is a great news that MTA will be back! At least, something is moving! [:D]

    Now we need live log, better UI navigation and dashboard too.

    Luk