Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Some advise for private usage of Sophos products

Hello community,

I am currently very unhappy with Sophos and the usage for private networks.

My current issues are:

  • Several technical issues: SFP-VDSL2 not working, joining the Sophos Central not possible
  • Licensing: The entire license structure is quite unclear to me, especially at reasonable costs
  • Ending on-premise endpoints in summer 2023

So going back to the planing, here is what I want:

  • Securing my private network including two Laptops of the company, I am working for (Home Office)
  • Securing my private devices including MacBook, Windows Laptop, tablets (Apple, Huawei) and Smartphones (Apple, Samsung) - 2 persons using this
  • Securing my private NAS
  • Securing some IoT/SmartHome devices, like Neato Vacuum cleaner, Logitech Harmony Hubs, Sonos speaker, SmartTV, …
  • Secure connection to one VPS Server and my parents place

By securing I mean especially:

  • Avoid threats for the devices like Maleware, Ransomware and so on.
  • Avoid this marketing/advertising tracking, which is so much on the internet, at least on a certain level

What I already do have as hardware:

  • Sophos XG106, including to not properly working VDSL2-SFP-modems
  • Ruckus r510 Access Point
  • TPLink managed Switch with PoE
  • FritzBox 7530

Reasonable costs besides buying the hardware are annual fees up to 40€. I know, it‘s not much, but much more usually private persons spend for security subscriptions.

At the moment, I am quite unsure what‘s happening with Sophos aggressive Cloud strategy and which licenses in which size I do need and which costs a have calculate. From a technical point of view, running a FritzBox with PiHole as local DNS worked better for me, although I know, that none of these components deliver more than basic network security.

Thanks for your advise.



This thread was automatically locked due to age.
Parents
  • I am using an XGS for work-from-home and it is quite reasonable. If you want a cheaper option, there are many choices ranging from ISP-provided devices to Ubiquiti, Mikrotik, and PFSense. (I forgot to add the Firewall Home Edition on your own hardware, with limitations, for free. I think this is SFOS, not UTM.)  Sophos is commercial-grade and has a great price point at the low end.

    The fee structure has been simplified, and provides a lot of value. Less-expensive consumer-grade devices do not provide the ongoing updates that Sophos does. At least I'm not aware of any inexpensive devices that automatically update various components on a two-hour schedule. if you get a cheaper device that includes Snort and then pay for daily Snort updates (or is it weekly?) you'll be paying way more than what you mention. You can use the less-expensive or free Snort updates if you're willing to be a month or more behind, but that's your choice.

    I'll admit that I still haven't figured what advantage there is to a 3-year subscription. There doesn't appear to be a major price break. And having to buy through reseller channels is... painful. But that's the way commercial vendors work and this is a commercial device.

    If I were complaining, I'd complain that they require stepping up to a more expensive and over-spec'd device to get an SSD. I should be able to plug in a USB SSD and have on-device logging. Also, the whole Sophos Licensing (MySophos) website thing is crazy confusing. But trying to get Sophos to offer a consumer-grade/consumer-priced device doesn't make sense to me.

  • Hi,

    I don't understand your requirement for an SSD on the XG, the higher performance disks do not make and difference to performance? Eventually Sophos will have to replace all small spinning disks with SSDs as the small disks become scarce.

    Ian

  • No SSD, no on-device reporting. Which makes me sad with my XGS 87. Sophos Central reporting is very granular. Maybe once I get 200 Mbps upload it will be less so?

  • Not only that, unless you have a paid subscription you cannot download the data.

    my internet is a 50/20, where 20 upload seems to be the magical number even on the higher down load plans. Quite painfully slow, but cm does give more details than the onboard reports at this stage.

    I would thought allowing a device to be connected via USB wiuld be a security risk?

    ian



    fixed keyboard errors. Definitely need a new keyboard.
    [edited by: rfcat_vk at 1:14 AM (GMT -7) on 23 Jun 2021]
  • We were stuck on Verizon's "FIOS" which is really fiber-to-our-floor, but the last few yards were VDSL. Not VDSL2, not VDSL2+, but old-school VDSL, so a max of 35/5. Meanwhile, Starry came into the building maybe a year ago and we finally switched today and I'm getting 215/110 as I write this for $50/month.

    I think USB could be a security risk, but you can plug a USB stick in already, so why not store to it? I can imagine that's a slippery slope and soon you'd have people demanding to use the USB port to hook up a USB drive that turns the XGS into a NAS, consumer-style. But I just want on-device reporting which I think will always show more detail and will also show me nice graphs from a single pane of glass. (I only have one XGS, so there's really no reason for me to want to use Sophos Central -- except that Intercept X is controlled through it, I guess.)

  • Hi Wayne,

    the free CM gives you better granularity than the onsite XG reports.

    Ian

  • Ouch! If Sophos Central's report graphs are the best, I guess their graphs aren't too useful to me. The nice thing is that they are retrospective -- I can look at what's happened in the previous hour. But if I want to look at what's happening over a time period I'm here, I'll ship iftop/bwmon/tcpdump/other data from the XGS and analyze/graph it myself, I guess.

Reply
  • Ouch! If Sophos Central's report graphs are the best, I guess their graphs aren't too useful to me. The nice thing is that they are retrospective -- I can look at what's happened in the previous hour. But if I want to look at what's happening over a time period I'm here, I'll ship iftop/bwmon/tcpdump/other data from the XGS and analyze/graph it myself, I guess.

Children
No Data