Sophos XGS takes an integrated approach to next-generation firewall (NGFW) security.
Rather than operating primarily as a standalone network appliance, XGS is designed to work closely with the broader Sophos security ecosystem. Organizations using Sophos Endpoint, XDR, or MDR can share security context between products and coordinate responses to threats, making XGS particularly relevant for businesses already invested in Sophos.
After reviewing the current XGS Series, I found that integration and automated threat response are among its biggest strengths. The platform combines traditional NGFW capabilities with SD-WAN, VPN, NDR, and centralized management. Active Threat Response and Synchronized Security further connect network activity with intelligence from other Sophos security products.
Sophos has also upgraded the hardware. The current Gen.2 desktop models improve performance and connectivity over the previous generation, with 2.5 GbE standard across the lineup. Selected models also support 10 GbE, Wi-Fi 6, or optional 5G.
That combination of security integration and updated hardware makes Sophos XGS a compelling option, but its value depends on your network requirements and the extent to which your organization uses the Sophos ecosystem.
Sophos XGS
Best for Sophos-centric organizations seeking integrated network and endpoint security

Overall score: 4.6/5
- Security and threat protection: 4.8/5
- Performance and hardware: 4.7/5
- Networking and connectivity: 4.6/5
- Management and usability: 4.5/5
- Integrations and automation: 4.8/5
- Pricing and licensing: 4.1/5
Sophos XGS combines next-generation firewall protection with networking and threat-response capabilities in a single platform. The current portfolio includes desktop and rackmount appliances designed for environments ranging from small businesses and branch offices to larger enterprise networks.
The Gen.2 desktop appliances deliver improved performance and connectivity over the previous generation, while the broader XGS platform supports organizations seeking to consolidate network security and management.
Overall, XGS is well-suited to SMBs and distributed organizations seeking a scalable firewall platform that integrates with their existing Sophos security environment.
Pros
- Strong integration with Sophos Endpoint, XDR, and MDR
- Improved Gen.2 desktop hardware with multi-gigabit connectivity
- Broad NGFW and threat-protection capabilities
- Automated response through Active Threat Response
- Integrated SD-WAN, VPN, and centralized management
- Hardware options for SMBs and enterprise deployments
Cons
- Advanced security features require additional subscriptions
- Some capabilities vary by XGS model
- XGS 88 has fewer features than larger models
- Sophos ecosystem integrations provide the most value when using other Sophos products
Pricing
Sophos does not publish standard pricing on their website, so buyers must request a quote.
XGS hardware includes a Base Firewall license. Additional security capabilities are available through subscriptions and bundles such as Xstream Protection. Sophos also offers Enhanced and Enhanced Plus support options.
When evaluating costs, consider the appliance price as well as any additional security subscriptions and service levels you need.
Pro tip
When sizing an XGS appliance, focus on its threat protection and TLS inspection performance rather than on maximum firewall throughput. These figures more accurately reflect the expected performance when advanced security services are enabled.
Sophos XGS hardware and performance
Sophos' current XGS portfolio includes desktop appliances for small businesses and branch offices, as well as rack-mount models for larger enterprise environments.
The Gen.2 desktop lineup spans the XGS 88 through XGS 138. Maximum firewall throughput ranges from 9.9 Gbps on the XGS 88 to 19.1 Gbps on the XGS 128 and XGS 138. Threat-protection throughput ranges from 2 Gbps to 4.7 Gbps, while larger rackmount models provide considerably more capacity.
All Gen.2 desktop models include 2.5 GbE connectivity. The XGS 138 also includes two 10 GbE SFP+ interfaces. Wi-Fi models support Wi-Fi 6, while the XGS 118, XGS 128, and XGS 138 families support an optional 5G module.
The entry-level XGS 88 lacks some capabilities found on larger models, including on-box reporting, dual AV scanning, WAF AV scanning, and email MTA functionality. Organizations that require these capabilities should consider the XGS 108 or higher.
Sophos XGS key features
Xstream architecture and threat protection
Sophos' Xstream architecture uses FastPath acceleration to offload trusted traffic and selected networking workloads, preserving resources for deeper inspection. Sophos Firewall also supports TLS 1.3 inspection and streaming deep packet inspection.
Threat protection includes IPS and malware prevention, as well as web and application controls. Cloud sandboxing and zero-day protection extend those defenses to unknown threats. NDR Essentials uses cloud-based machine learning to analyze network metadata and identify suspicious activity without requiring full decryption of every payload.
Active Threat Response and Synchronized Security
Active Threat Response uses intelligence from Sophos MDR, NDR Essentials, X-Ops, and supported third-party feeds to monitor or block traffic associated with known threats.
Synchronized Security shares context between Sophos Firewall and endpoints, helping identify compromised systems and restrict their network access. This coordination provides additional value for organizations already using other Sophos security products.
SD-WAN and connectivity
Sophos Firewall includes integrated SD-WAN with performance-based routing and load balancing. It also provides link failover and centralized orchestration.
For secure connectivity, the platform supports IPsec and SSL VPN connections. Integration with Sophos ZTNA and SD-RED enables organizations to combine branch connectivity and network security in a single ecosystem.
Centralized management
Sophos Fusion provides cloud-based management for multiple Sophos firewalls and other security products. Administrators can deploy group configurations and schedule firmware updates. They can also manage SD-WAN networks, maintain backups, and use zero-touch deployment for remote appliances.
This centralized approach is useful for distributed organizations that manage multiple firewalls across locations.
How I evaluated Sophos XGS
I evaluated Sophos XGS across six weighted categories based on the capabilities that matter most when choosing a next-generation firewall. My evaluation relies primarily on Sophos documentation, with online user reviews providing additional insight into management and usability.
Security and threat protection (25%): I evaluated core protections, including IPS, TLS inspection, malware prevention, and sandboxing. I also considered web and application security. NDR, Active Threat Response, and threat intelligence integration also factored into the score.
Performance and hardware (20%): I evaluated Sophos' published performance for firewall traffic, threat protection, VPNs, and TLS inspection. I also considered the Gen.2 hardware architecture and energy-efficiency improvements. Scores are based on published specifications rather than independent performance testing.
Networking and connectivity (15%): I considered SD-WAN and VPN capabilities, interface speeds, and wireless connectivity. Expansion and redundancy options also factored into the score, as did the range of appliances available for different deployment sizes.
Management and usability (15%): I evaluated Sophos Firewall administration and centralized management through Sophos Fusion. I also considered deployment and reporting capabilities, supplemented by administrator feedback from online reviews.
Integrations and automation (15%): I considered Synchronized Security and integration with Sophos Endpoint, XDR, and MDR. Active Threat Response and support for third-party threat feeds also factored into the score.
Pricing and licensing (10%): I evaluated licensing flexibility and feature availability. I also considered support requirements and pricing transparency. Sophos does not publish standard pricing on its website, requiring organizations to request a custom quote.
Frequently asked questions
What is the difference between Sophos XG and XGS?
XG and XGS are different generations of Sophos firewall hardware. The Sophos XG Series reached end of life on Mar. 31, 2025, and Sophos directs customers toward XGS hardware. Current SFOS 22 releases also no longer support XG or SG Series appliances.
Organizations purchasing new Sophos firewall hardware in 2026 should therefore be evaluating XGS rather than XG.
Which Sophos XGS models are Gen.2?
Sophos' Gen.2 desktop lineup includes the XGS 88/88w, 108/108w, 118/118w, 128/128w, and XGS 138. Models with a "w" include integrated Wi-Fi 6. The XGS 138 does not have an integrated Wi-Fi version.
Sophos also offers rackmount models from the XGS 2100 through XGS 8500. These are part of the current XGS Series but not the Gen.2 desktop lineup.
Does Sophos XGS require a subscription?
XGS appliances include a Base Firewall license, but additional security features require an active subscription. These capabilities are available individually or as part of bundles such as Xstream Protection. Sophos also offers Enhanced and Enhanced Plus support options.
Is Sophos XGS worth it if I already use Sophos Endpoint?
Existing Sophos Endpoint customers are well positioned to benefit from XGS. Synchronized Security allows Sophos Firewall and Endpoint to share security context and coordinate responses to compromised systems. This integration can provide greater visibility and automation than managing firewall and endpoint security separately.
Bottom line
Sophos XGS combines next-generation firewall protection with SD-WAN, VPN, NDR, and automated threat response. The portfolio spans small branch offices through large enterprise environments.
The Gen.2 desktop models, from the XGS 88 through XGS 138, improve performance and networking over the previous generation. Selected models also offer Wi-Fi 6 and additional connectivity options.
XGS provides the greatest value when integrated with the broader Sophos ecosystem. Organizations using Sophos Endpoint, XDR, or MDR can benefit from shared security context and coordinated threat response. Organizations using products from multiple security vendors should consider how well XGS fits their existing environment and licensing requirements.
Final verdict: Sophos XGS is a strong choice for organizations seeking an NGFW with tight integration between network and endpoint security, especially those already invested in Sophos.
Because a firewall is only one layer of enterprise security, organizations should also evaluate endpoint detection and response (EDR) solutions to protect devices from threats that reach or originate inside the network.





