This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

My 3 Months with Sophos

I just had to vent with my feedback for what I had anticipated was going to be a good experience. For well over a year I researched new firewalls to replace our aging Juniper Networks appliance. After much deliberation I went with the Sophos XG210 in Oct 2017. Everything went very well with the product some minor issues but really a pretty good experience overall, it met our needs. Since I was new with Sophos and really with this style of firewall, I decided I should also have one at home, so I can practice making rules, changing settings and seeing the impact before rolling out on our company network, mind you all on my dime, not the company. Just before Christmas I ordered a XG85W, too say the least a terrible product, cost aside. Within 3 weeks I had gone thru 2 appliances was doing nothing but troubleshooting, simply wasting a lot of time. The solution, I had to spend an additional couple of hundred of dollars to upgrade to the XG105W, not I'm pretty close to being 1K out of pocket for a test unit. Its been running for 2 days now and seems stable.

All during this time some of our staff went to our China facility, low and behold SSL-VPN would not work at that location, ok with the issues China has and banning VPN's I needed to come up with a solution hopefully, setup IPSec VPN remote access. Since our previous Juniper ran this setup and it worked in China hope fully it will continue working. One thing with Sophos is their lack detailed configurations but its slowly coming, there is absolutely zero on setting up a working IPSec remote client other than the guide that simply explains the fields. Anyway I config the XG and purchase the Sophos IPSec software and license for one user. After days of screwing around, I am told IPSec and SSL-VPN cannot work together thru support, but then I am told it will so we have been working on why I cannot get this system to work due to a Sophos licensing error. Come to find out the Sophos IPSec client software doesn't work, I install Greenbow VPN and within 5 minutes I establish a remote connection thru IPSec. Now I can't access any of the network resources but those are my next steps.

Here is my problem, initially I thought I was buying into more of an Enterprise level products but I'm starting to feel like I'm back to consumer grade quality products that work but with no real reliability or level of confidence that I am using a quality product. To say the least I'm frustrated, and probably more at myself because I have always thought I do my due diligence and whats the best solution but now I'm so deflated with my decision to go with Sophos I'm not sure if I want to continue with the next steps of integrating more of their products. I definitely wouldn't recommend the product to any of my colleagues but the only saving grace has been I have had zero issues with the XG210 and its configuration. This is just my personal experience and my frustration talking.



This thread was automatically locked due to age.
Parents
  • Welcome to the club... 


    My predecessor had replaced our company's old Cisco ASA with XG135s. 
    For my 4 months with Sophos, I can say far this is crappiest POS I've ever seen what comes to firewalls.

     

    I mean it's was virtually impossible to have an idea what's going on in firewall, if you had more than four rules. After the latest updates, it's just f*n hard.

    I've been trying to figure out how to get IPSEC site-to-site vpn working for couple of days now. Sometimes it works, some times it does not. Even if I don't touch any settings on either end.

    Funny thing, the VPN usually starts to work when I try to deactivate the VPN to start all over again.

     

    This firewall is sub-consumer level, I'd rather had anything else.

     

    E: Just noticed that these firewalls was bought exactly a year a go and we have a 3 year support contract. We paid $7500 for these, and I'm seriously thinking of trashing these and getting something that works.

Reply
  • Welcome to the club... 


    My predecessor had replaced our company's old Cisco ASA with XG135s. 
    For my 4 months with Sophos, I can say far this is crappiest POS I've ever seen what comes to firewalls.

     

    I mean it's was virtually impossible to have an idea what's going on in firewall, if you had more than four rules. After the latest updates, it's just f*n hard.

    I've been trying to figure out how to get IPSEC site-to-site vpn working for couple of days now. Sometimes it works, some times it does not. Even if I don't touch any settings on either end.

    Funny thing, the VPN usually starts to work when I try to deactivate the VPN to start all over again.

     

    This firewall is sub-consumer level, I'd rather had anything else.

     

    E: Just noticed that these firewalls was bought exactly a year a go and we have a 3 year support contract. We paid $7500 for these, and I'm seriously thinking of trashing these and getting something that works.

Children
  • Hi,

    please do a search of the forum for more discussion about the VPNs and IPsec issues, I am not saying there are fixes, but maybe some work arounds that might help in the short term. Next log a fault/support request with either your reseller or directly on the Sophos support portal. This approach  might help your company get some return on its investment.

    A further suggestion is to see if you can change to the UTM where these features do work last time I checked.

    Ian

  • Switched from Sonicwall NSA 2400 to XG210-HA a week ago.

    From the Sonicwall point of view I like what I'm seeing. But on the other hand there are a lot of questions and currently few issues. Especially site to site VPN to a UTM which is not coming up and Greylisting not working properly. Also SSL VPN is a bit weird and was way more easy to setup with Sonicwall than with XG.

    Maybe I lack experience with the real cool firewalls which would maybe raise my concerns about XG but I keep my fingers crossed that the showstoppers are going to be fixed soon.