Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Disapointed by XGS 116 for home

I tested a VM with XG home Edition and I was pretty happy with it that I decided to order a physical firewall to get a real protection instead of virtual.

I ordered a XGS 116 and I got really disapointed by the noize of the device. I plug the device in the ground floor and I can hear the high frequences fan noise even in my living room at the first floor. I get surprise when I upgraded to the latest firmware (19OS) that I still got 3 free update and after  that I must order support which is a good price.I also realized that I have no licenses for IPS and this costs like 600.- per year.

I feel like this firewall was way to big for home usage and I will asks for a refund.

I checked on the web and it looks like the XGS 87 also have a lot of big noise feedback regarding the size of the box. Is it the same regarding the licenses as additional?

Is there a way to have a fanless device with XG Home Edition instead of having to sell my car just to have a good performant firewall?



This thread was automatically locked due to age.
  • Hi,

    I would suggest you log a ram call about a faulty fan. The desktop device should be very quiet.

    The XGS87 had a bios update that was supposed to fix the fan noise issue.

    There is a total support package for the box which includes many updates for the life of the licence.

    You can always build your own finless system or buy a fanless system and put the free home line on it which has all the functions but support is throw these forums.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • There are fanless devices that can support XG. Mostly the Qotom ones but you will have a couple of things to keep in mind. There is an entire discussion about this topic.

    The XG has limited support for certain NICs and the ones with the older Intel i211 through i219 NICs are supported are are recommended. Running a fanless device with the newer NICs that are not supported will require you to run the XG virtualized for a few reasons:

    1. XG home does not support UEFI boot which means the newer devices cannot boot the XG natively but will work in a VM if the hypervisor supports UEFI since Intel is doing away with legacy boot support*

    *The older devices support legacy mode BIOS which means they will boot the XG natively.

    2. The newer devices have NICs that are not support by the XG so that is another reason why you would have to virtualize the firewall.

    The XG home version includes IPS for free and you should not have to pay for it. In fact the home edition support everything except for Heartbeat/application synchronization and most Sophos Central features like remote administration, besides the "free" Wireless portion of Sophos Central wireless. All these things that are evaluating are free:

  • Hi Alan,

    the Xg does not support i219 series or i225/6 series intel NICs, I think you made a typing mistake. CM does support remote administration for the home licence user, but does not support report generation and only holds data for 7 days.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Sorry if I was mistaken but I was under the impression it supported i219.

    anyways to the OP there is no official hardware compatibility list but supported NICs are based on the version of whichever linux kernel that the XG is running at the moment.

  • Hello Guys,

    Thanks for the feedback.

    I found this little guy on the web:

    Niuguy N4200 Mini PC

    • Intel Pentium N4200

    • 4xIntel i211 RJ45 LANs, 1xCOM/console.

    • 1xDDR3 ram slot, max support 8GB(Select configurations as needed).

    • 1xmSATA SSD(Select configurations as needed) up to 512Gb.

    • Support 1xHD-MI, 2XUSB3.0, 4 XUSB2.0.

    • 1x4G/WIFI slot.

    • All aluminum alloy high-quality solid shell, excellent cooling performance, and beautifully designed external production process.

    • Fanless system without cooling fan, noiselessness and durability fit for industrial grade field, work as long as 7x24 hours.

    • Low consumption TDP only 25W & can be mounted back of monitor by VESA bracket(optional).

    • X86 architecture, multi port design, suitable for professional network engineers to carry out OSI reference model testing and development, and convenient for installing firewall software such as pfsense, m0n0wall, OPNsense, Untangle NG Fierwall, Router OS x86, hi spider, Wayos, etc.

    • It can be used to load RedHat, Linux, Ubuntu Linux, CentOS7, windows xp, windows 7 & other systems for use as mini pc.

    Do you think it would be totaly compatible with Sophos Home?

    Do you think Intel Pentium N4200 is strong enough for all base home firewall, IPS and some SSL VPN connection sometime ?

  • Hi,

    lit is compatible, but performance will depend on your link speed and number of active devices you have connected. You will need to disable power step in bios.

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • My internet link speed is around 1Gb symetrical but I am not at high usage (max 2Mbps constant). I have around 35 device connected with 4 VM for local DNS, Plex server and some Sonos speakers. I am not hosting external services, only Web browsing and gaming.

    As a comparaison I want to replace my Ubiquiti Unifi 3P USG and today it runs okay.

  • I recommend you to upgrade to 8Gb ram if you get it. Be aware, the home version of XG can only use up to 6Gb of ram. So finetune your IPS rules and choose only the ones you need and it should be fast enough. 

  • Most likely you should look into a Hypervisor (like KVM etc.) and use there Hardware support to implement SFOS. 

    __________________________________________________________________________________________________________________

  • That way he can use any of the newer devices which have the latest i225/i226 NICs and faster CPUs?