This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Newbie - Is SG115W the right choice?

Hello all,

After talking to sales I was directed towards SG115W unit but I was hoping to hear from the users/admins in the real world. I come from years of SonicWall and most of SW units have been notorious for overstating their speeds and processing, especially when web filtering and AV are turned on. Looking to switch from SonicWall client has TZ1xx that has to go either way so rather than getting yet another bigger SonicWall we want to try Sophos. So, no disrespect to sales I am hoping community can chime in.

Site A (HQ)

  • 10/10Mbps WAN with a AD/File/Print Server. Looking at the specs, 120Mbps even with AV on so that checks out.
  • 15 users (growth plan to 25)
  • web/SasS heavy users so web filtering/reporting  (iView or at least a syslog server) is a must along with AV so we are going with Total Protection.
  • VoIP so QoS is a must, seems like Sophos uses concept of 'Bandwidth Pools' to accomplish this. Right?
  • DHCP over VLANs to separate the traffic, single physical port preferred
  • Plan on using builtin WiFi 'just to start' but would most likely add Ubiquity = because we have used them with success but open to try Sophos APs.
  • Potentially adding a 2-3 RED boxes for few VIPs home offices

So far I think that SG115w will work and fits all the requirements. Next phase is where I am not sure it will become absolute quick and if it can keep up.


Site B (future growth within a year) = get another SG115W

Same size office that will be treated as a 'branch', build SiteToSite VPN towards Site A for access to AD/File, Print resources with the split tunnel for web/VoIP.

It would be nice if could push all the web browsing towards Site A to benefit from 'central reporting' and save some $ on Total Protection for 1 device rather than 2 but I am not sure of the performance of 'Site A' SG115W processing and running Total Protection for both sites (now double the amount of users behind it)

Is SG115w best choice for the setup and if not what model do you recommend at each site? I have not worked with Sophos before (other than some playtime with virtual XG) so I would appreciate the feedback and advice.

Thank you for your time.



This thread was automatically locked due to age.
  • Hi,

    I think sales will be the best place to contact for these queries. Please find the best contact here: www.sophos.com/.../contact.aspx

    Thanks

  • Hi, and welcome to the UTM Community!

    It sounds like you would do well to ask Sophos for a recommendation of an experienced installing reseller in your area.  I've seen UTMs set up by talented CCIEs without UTM experience, and the results aren't pretty.  WebAdmin can create very elegant configurations that are easy to administer, but a first-timer can't know how to do that.  The other benefit of finding your reseller now is that they will do the sizing and have skin in the game.

    If you are, or are planning, on becoming a reseller, look for experienced Sophos Certified Architects in your country, and hire one to help you with your first sizing and installation.  WebAdmin is a GUI that manipulates databases of objects and settings.  A single change there can cause the Configuration Daemon to rewrite hundreds of lines of the code used to run the UTM.

    To answer your question: maybe[:^)]

    Cheers - Bob

  • Thanks!

    I did start with the sales but I was bit surprised that the moment I mentioned user count they were quick to suggest the unit without addressing growth and hearing the rest of the plans. "Yes, it should work" is not the level of reassurance that makes me confident in proposed solution. Reminded me a bit of other vendors and honestly sales vs. admins always have different perspective, which is why I posted here :)

  • Hi Bob and thanks for the reply.

    Might become a reseller if the product stands up to our expectations and, naturally, the first few units we would acquire through a reseller.

    I get the whole WebAdmin vs. console and ramifications of wrong rules applied, unnecessary code generated, CPU spikes etc. but the same goes for just about any vendor even on a L2/3 switch. One of the many attractions to Sophos was the ease of admin and performance, we have the concepts down with SonicWalls and can deploy them pretty quick - we just need to replicate them into Sophos world.

    Again, just looking for feedback from the users to see if specs really match the real world use and avoid regretting not getting a next model up [:D]