This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Pros/Cons of XG Firewall? - looking for some real world experience

I am considering the XG Firewall (210 model) and would plan to implement it with high availability.  I personally come from a Cisco background and have experience with the ASA line, but I wanted to see how these models compare and what others experiences are.

Please let me know any pros/cons you have encountered and if there are any gotcha moments to be aware of.

Thanks much.

KM



This thread was automatically locked due to age.
Parents
  • KM,

    I have used Sophos SG UTM since version the end of version 1 and the release of version 2.  Over a year ago, I switched to XG Firewall and never looked back.  The SG Firewall is simple, straight forward, and capable of handling everything I have ever thrown at it - from large enterprises  and small businesses to large estates and small homes.  As CMR stated, updates come often, and they are quick and painless to deploy.  My favorite features are the integrated secure wireless and RED add-ons.

    I have only one con: The Firewall is defaulted to Deny All while each Firewall Rule you create is based on Allow All - Drop and Reject seem to be cleanup rules.  For every User/Network Firewall Rule, You must select Allow All and then re-identify what you want to restrict/block through policies.  This is fine as long as you understand this is how the rules work in the XG Firewall.  I say this coming from using multiple SG UTM rules set in Deny ALL, in which, I turn on only what you want to allow and where I want it to go.

Reply
  • KM,

    I have used Sophos SG UTM since version the end of version 1 and the release of version 2.  Over a year ago, I switched to XG Firewall and never looked back.  The SG Firewall is simple, straight forward, and capable of handling everything I have ever thrown at it - from large enterprises  and small businesses to large estates and small homes.  As CMR stated, updates come often, and they are quick and painless to deploy.  My favorite features are the integrated secure wireless and RED add-ons.

    I have only one con: The Firewall is defaulted to Deny All while each Firewall Rule you create is based on Allow All - Drop and Reject seem to be cleanup rules.  For every User/Network Firewall Rule, You must select Allow All and then re-identify what you want to restrict/block through policies.  This is fine as long as you understand this is how the rules work in the XG Firewall.  I say this coming from using multiple SG UTM rules set in Deny ALL, in which, I turn on only what you want to allow and where I want it to go.

Children
No Data