Connecting to Sophos PoV Cloud…

📂 My PoC Sessions

Select a session or create a new one.

Connecting to Sophos PoV Cloud…

Sophos Firewall PoV Guide
SOPHOS

Proof of Value Guide

Sophos Firewall v22.0

PoC Progress Overview

Click any card to jump to that section.

SFOS 22.0

What's New in Sophos Firewall v22.0

Sophos Firewall OS v22.0 is the current major release, introducing significant new capabilities across threat detection, identity management, and network operations. 📖 Full v22.0 docs →

🛡️ NDR Active Threat Intelligence

Integration with Taegis NDR iSensor and NDR Essentials — delivers network detection and response with AI-powered behavioral analysis. Sophos Firewall acts as a sensor feeding telemetry to Taegis for correlation across the entire estate.

🌐 Third-Party Threat Feeds (Active Threat Response)

Ingest external IOC threat feeds directly into policy. The Active Threat Response with MDR Threat Feeds lets Sophos MDR automatically push threat intel to block malicious IPs and domains in real time.

🔑 Microsoft Entra ID SSO

Microsoft Entra ID (Azure AD) integration with Captive Portal SSO — users authenticate via their Entra credentials. Eliminates duplicate user directories and reduces friction for cloud-first organizations.

🔒 Let's Encrypt Certificates

Native Let's Encrypt ACME certificate provisioning and auto-renewal for WAF and SSL VPN. Removes the need for manual certificate management.

🌍 DHCP Prefix Delegation (IPv6)

Full IPv6 DHCPv6-PD support — automatically delegates IPv6 prefixes to downstream routers, enabling enterprise-grade IPv6 deployments without manual subnetting.

💾 Backup & VPN Enhancements

Selective backup restore of config sections. SD-WAN policy routing improvements, BGP enhancements, and IPsec IKEv2 improvements for site-to-site tunnels.

XGS Series Hardware (Current Generation):
Desktop: XGS 88/88w · 108/108w · 118/118w · 128/128w · 138
Rack/Mid-range: XGS 2100/2300/3100/3300/4300/4500  |  Enterprise: XGS 5500/6500/7500/8500
All XGS appliances include the Xstream Flow Processor for hardware-accelerated TLS inspection and FastPath traffic offloading.

📺 TechVids — v22.0 Feature Walkthroughs

🎬
Let's Encrypt™ Certificates

Auto-renewal for WAF & SSL VPN

🎬
Third-Party Threat Feeds

IOC ingestion & policy blocking

🎬
Active Threat Response with MDR

MDR threat feed auto-blocking

🎬
Microsoft Entra ID + Captive Portal SSO

Azure AD authentication walkthrough

🎬
DHCP Prefix Delegation (IPv6)

DHCPv6-PD enterprise setup

🎬
Static Route & VPN Enhancements

SD-WAN & IPsec improvements

🎬
Backup Restore Enhancements

Selective config section restore

🎬
Basic Setup & Registration

First-time firewall setup walkthrough

📋 Full v22.0 Release Notes  ·  Community Blog Post

Introduction

Introduction

This guide is designed for Sophos system engineers to get the best results from a Sophos Firewall deployment during a proof of concept (PoC) exercise. It covers how to approach different PoC scenarios and concludes with success criteria checklists to eliminate security gaps.

The guide includes suggested questionnaires covering pain points with existing solutions, the recommended workflow, and how to present findings with recommendations to improve security posture in a customer's environment. Content is based on Sophos Firewall v22.0. For questions, contact the Sophos GSE team at gse@sophos.com.

Overview

Overview

Sophos Firewall provides unrivaled visibility into risky users, unwanted applications, suspicious payloads, and persistent threats. It integrates a full suite of modern threat protection technologies that are easy to set up and maintain. Unlike legacy firewalls, Sophos Firewall communicates with other security systems on the network, enabling it to act as a trusted enforcement point — automatically containing threats and blocking malware from spreading or exfiltrating data in real time.

Sophos Firewall has three key advantages over other network firewalls:

Visibility

Expose Hidden Risks

Superior visibility into risky activity, suspicious traffic, and advanced threats through a visual dashboard, cloud and on-box reporting, and unique risk insights.

Protection

Stop Unknown Threats

Powerful next-gen protection technologies including deep learning and intrusion prevention to keep the organization secure against known and unknown threats.

Response

Isolate Infected Systems

Automatic threat response via Synchronized Security — instantly identifies and isolates compromised systems on the network to stop threats from spreading.

~20%
of organizations that suffered a cyberattack were unaware of how the most significant attack entered their network. (Vanson Bourne survey of 2,109 respondents)
13 hrs
average time for the most significant threat to remain in the environment before being detected — giving attackers ample opportunity to deliver payloads.
Deployment

Initial Deployment & Administration

Sophos Firewall offers flexible deployment options to meet the needs of any organization. It can be deployed in four ways:

🖥️

Hardware Appliance

Sophos Firewall hardware devices come pre-loaded and ready to deploy. Delivers Visibility, Protection, and Response out of the box.

💿

Software

Install Sophos Firewall onto any Intel-compatible hardware. Ideal for organizations wanting to Consolidate, Simplify, & Save on hardware costs.

⚙️

Virtual Appliance

Runs on VMware, Citrix, Microsoft Hyper-V, Nutanix, and KVM. Suitable for Retail, Branch Office, ICS & SD-WAN environments.

☁️

Cloud (Azure / AWS)

Deploy Sophos Firewall in the cloud on Azure and AWS for Synchronized Security & Automated Response in cloud-native environments.

Deployment Modes

Deployment Modes

Gateway Mode

In Gateway Mode, Sophos Firewall acts as the primary network gateway — routing all traffic between internal segments and the outside world. This is the ideal solution for organizations replacing an existing firewall or deploying a new one. All security features are fully supported in this mode. 📖 Gateway mode setup →

Public Internet ISP Device Sophos Firewall Gateway Mode DMZ Switch LAN Switch Server Endpoints

Bridge Mode

In Bridge Mode, Sophos Firewall sits inline between an existing firewall and the internal network, adding deep packet inspection, IPS, malware scanning, and email content scanning without changing any IP schema. It augments security to an upstream firewall by detecting unknown applications and threats it may miss. Selected Sophos models support a hardware bypass module to ensure network continuity during hardware failure.

Best for: Organizations that want to add Sophos Firewall capabilities alongside an existing firewall without network reconfiguration. Supports Layer 3 bridge (mixed mode) for hybrid deployments. Selected XGS models support a hardware bypass module for uninterrupted traffic flow during hardware failure. 📖 Bridge mode setup →

Discover Mode (TAP / SPAN / Port Mirror)

Discover Mode — also known as Test Access Point (TAP), port mirroring, or SPAN mode — lets you deploy Sophos Firewall to passively monitor all network traffic without any changes to the existing network schema. A switch forwards a copy of every packet to the Sophos Firewall for analysis and reporting.

This mode is ideal for PoC demonstrations — a partner can identify threats the existing firewall is missing without disrupting the live environment. It also unlocks Synchronized Security capabilities, including endpoint health status visibility and automatic isolation of infected systems. 📖 Discover mode setup →

Visibility

Visibility

Lack of visibility into security posture highlights a significant challenge: if you don't know how a threat got in, it's difficult to prevent future attacks. The longer a threat remains in the network, the greater the risk. According to a Vanson Bourne survey of 3,100 IT managers globally, organizations took an average of 13 hours to detect threats — ample time for attackers to deliver payloads.

Control Center

Sophos Firewall's Control Center provides an unprecedented level of visibility into activity, risks, and threats on the network. It uses traffic-light indicators to focus attention on critical items: Red requires immediate attention, Yellow indicates a potential problem, and Green means no action is required.

Sophos Central Management & Reporting

Sophos Central provides a unified interface for managing multiple Sophos Firewalls and the full Sophos security portfolio. It includes alerting, backup management, one-click firmware updates, and Group Firewall Management for synchronizing policies across all firewalls with a few clicks. Central Firewall Reporting (CFR) is bundled at no extra cost — delivering rich analytics on user behavior, application usage, and security events with interactive dashboards and drill-down syslog data. The free tier retains data for 7 days; CFR Advanced extends retention up to 365 days per firewall. Sophos Firewalls can also forward logs to external syslog servers or SIEM systems for long-term storage. 📖 Central management docs →

Key question: To highlight Sophos Firewall's visibility value, ask customers where their current firewall solution may be lacking. Use the checklist below to guide the conversation.

Visibility Assessment Checklist

Visibility Assessment Progress
0 / 0
Visibility Assessment
0 / 6
Connectivity

Connectivity

When evaluating connectivity requirements, consider not only the current topology but also future growth. Select a firewall that offers flexible deployment options — both on-premises and cloud — with appropriate management tools. For organizations with small remote locations, consider SD-WAN to securely and affordably connect those sites.

SD-WAN (Software-defined Wide Area Network) is a virtual WAN architecture that allows enterprises to leverage any combination of transport services — MPLS, LTE, and broadband — to securely connect users to applications. Sophos Firewall v19+ provides granular routing decisions via SD-WAN profiles that route traffic based on application, network, user, or service, using SLA parameters (jitter, latency, packet loss) with active-backup and load-balancing support.

Sophos Firewall delivers zero-impact failover — automatically rerouting connections to the next available gateway when an active gateway goes down or fails its SLA, with no user-visible disconnection.

SD-WAN VPN Orchestration 📖 docs →

Sophos Central provides a dedicated SD-WAN Connection Group to manage connectivity between multiple Sophos Firewalls from a single interface. Select head office and branch firewalls, and Sophos Central automatically establishes IPsec route-based VPN tunnels between them in minutes — with no manual tunnel configuration required.

Topology Options
  • Full-mesh — every site connected to every other site
  • Hub-and-spoke — branches connect to a central hub
  • Mix of both in a single SD-WAN group
Zero-Touch Provisioning
  • Zero-touch via Sophos Central — new XGS hardware auto-registers and pulls config
  • Light-touch via USB stick — pre-stage config for remote deployments
  • World map view of all connected sites with IPsec tunnel status

Connectivity Requirements Checklist

Connectivity Requirements Progress
0 / 0
Connectivity Requirements
0 / 9
Protection

Protection

Network security has evolved as threats have shifted from direct network attacks to infecting systems and spreading laterally. Best practice is to segment the LAN into smaller subnets using zones or VLANs, then connect them through the firewall — enabling anti-malware and IPS protection between segments to identify and block lateral movement.

Next-gen Intrusion Prevention System (IPS)

Next-generation IPS provides advanced protection from modern threats, going beyond traditional server and network resources to protect users and applications on the network.

Security Heartbeat™

Security Heartbeat provides constant communication between Sophos-protected endpoints and Sophos Firewall, enabling administrators to visualize endpoint health status in real time. Green = healthy; Amber/Yellow = attention needed; Red = immediate action required.

Lateral Movement Protection

When a computer is infected or nefarious activity is detected by either Sophos Firewall or an endpoint, it automatically isolates the infected device. Other machines in the same broadcast domain stop communicating with it until it is cleaned.

Synchronized Application Control

One of the key capabilities of an NGFW is detecting Layer-7 applications regardless of port or protocol. Every 30 seconds, Sophos-protected endpoints send health status and application information. Sophos Firewall categorizes traffic down to the application path on the endpoint — giving administrators full control over the network.

TLS 1.3 Scanning

Encrypted TLS/SSL traffic accounts for ~80% of internet traffic. Sophos Firewall can scan TLS 1.3 natively without downgrading to TLS 1.2. The Xstream architecture with Fastpath decrypts and scans traffic with minimal performance trade-off.

Active Threat Response — Components Overview

Sophos Firewall v22.0 unifies multiple threat intelligence and detection layers under the Active Threat Response framework. These components work together to detect, feed, and automatically act on threat intelligence — from zero-day files to live MDR-sourced IOCs.

🔬 Sophos X-Ops (Sandstorm)

Sophos X-Ops is the cross-functional threat intelligence team behind Sophos Firewall's advanced detection. When the firewall encounters a file with no prior conviction, it submits it to the cloud-based Sandstorm sandbox — using deep learning and Intercept X to emulate and analyse behaviour. The resulting report gives threat responders full visibility into attacker techniques for proactive threat hunting. 📖 docs →

🚨 MDR Threat Feeds

Customers with Sophos MDR licenses get live threat intel automatically pushed from the Sophos MDR operations team directly to the firewall. Malicious IPs, domains, and URLs are blocked in real time without any manual intervention — preventing lateral movement of compromised hosts the moment a threat is identified by the MDR team. 📺 Watch demo →

🌐 Third-Party Threat Feeds

New in v22.0 — ingest external IOC threat feeds (STIX/TAXII and custom formats) from any third-party intelligence provider directly into Sophos Firewall policy. Malicious indicators are automatically translated into firewall rules to block matching traffic, keeping the firewall current with the wider threat landscape beyond Sophos's own intelligence. 📺 Watch demo →

📡 NDR Essentials & NDR Active Threat Intelligence

Integration with Taegis NDR iSensor and NDR Essentials — Sophos Firewall acts as a network sensor, feeding traffic telemetry to Sophos Taegis for AI-powered behavioural analysis and cross-estate correlation. NDR Essentials provides network detection and response for organisations that need deep visibility beyond endpoint-only solutions, detecting threats that evade signature-based engines.

How they work together: Sophos X-Ops provides the intelligence backbone → MDR Threat Feeds deliver real-time auto-response → Third-Party Feeds extend coverage to external IOC sources → NDR Essentials adds network-layer behavioural detection. All four feed into a unified Active Threat Response posture on Sophos Firewall v22.0.

Cloud and SaaS Application Detection

Shadow IT — employees using unsanctioned cloud services like Dropbox or Google Drive — poses data security risks. Sophos Firewall provides full visibility and control over cloud applications, allowing IT to sanction, unsanction, or apply QoS policies per application.

Protection Checklist — Identifying Security Gaps

Protection & Security Gap Assessment Progress
0 / 0
Protection & Security Gap Assessment
0 / 11
Management

Management

Sophos Firewall is managed via a secure HTTPS web UI. Color-coded widgets and an intuitive UX provide a shorter learning curve for administrators with no prior firewall experience. All tools for day-to-day tasks and network diagnostics are bundled — no add-on modules or paid subscriptions required.

The firewall provides at-a-glance information on whether the network is under attack, alerting administrators to misconfigurations and important security notifications. The live log viewer is available from every screen with a single click.

Management Evaluation Checklist

Management Evaluation Progress
0 / 0
Management Evaluation
0 / 5
PoC Verification

Proof of Concept Success Verification Check

Once Sophos Firewall has been deployed according to requirements, it is time to evaluate success criteria. Customers may have their own testing methodologies; the checklists below can be used to verify the setup systematically.

Network Connectivity Requirement

Network Connectivity — Testing & Verification Progress
0 / 0
Network Connectivity — Testing & Verification

Security and Authentication Requirement — Egress Filter Policy

Egress filtering inspects outgoing data traffic and prevents unauthorized traffic from leaving. Policy focuses on client-side protection, reducing attack surface, and enforcing acceptable use policy.

Egress Filter Policy Progress
0 / 0
Egress Filter Policy

Security and Authentication Requirement — Ingress Filter Policy

Ingress filtering applies when Sophos Firewall receives packets from an untrusted source or WAN interface. Policy focuses on securing web services, email, and NAT configurations.

Ingress Filter Policy Progress
0 / 0
Ingress Filter Policy

Logging, Reporting, and Administration Checklist

Administration is an essential part of network protection. Correct security practices and visibility into network activity help distinguish normal from abnormal behaviour — enabling proactive prevention.

Administration Policy Progress
0 / 0
Administration Policy
Review

Review the Findings

The framework in this guide is designed to provide guidance across various use cases and test scenarios. The appropriate depth and focus of the PoC will be influenced by the organization's security maturity level, industry vertical, and regulatory guidelines.

Need help? If at any stage you would like assistance running or assessing the findings of your proof of concept, contact the Sophos GSE team at gse@sophos.com.

Conclusion

Conclusion — Suggested Activities & Workflow

First 10 Days Activities

4
Review the list of customer requirements and expectations. Document pain points and the specific problems to be solved. If the customer lacks clear requirements, use the visibility, protection, and response checklists above as a guide.
5
Size the correct model with future growth in mind. Consider current competing firewall models, issues the customer has experienced, and budget constraints alongside technical requirements.
6
Document the network topology (before/after Sophos deployment), acceptable disruption timeframe, and key contact details. Confirm the failover scope — whether partial or all network traffic will route through the firewall.
7
Verify Sophos Firewall compatibility with third-party SIEM, SOAR, 2FA, load balancers, and network monitoring solutions before beginning the PoC.
8
Record VPN throughput and download/upload performance from server/client applications prior to Sophos deployment to establish a clear baseline for before/after comparison.
9
If the appliance will remain connected during the PoC in a live environment, prepare a clear step-by-step rollback guide for the customer to restore to the previous state if disruption exceeds acceptable downtime.
10
Agree on a PoC completion date with the customer. Once agreed, the SE or account manager should send a calendar invite to officially close the PoC and schedule a findings presentation.

Day 30 — Proof of Concept Review

Use the information gathered during the 30-day trial to fully evaluate Sophos Firewall:

1
Present findings from the dashboard, scheduled reports, and Security Activity Reports (SAR) covering the past 30 days of deployment.
2
Review findings related to attack vectors and the cyber-attack kill chain. Has the customer been able to identify unknown applications? Can they now identify risky user behavior that could lead to a breach?
3
Highlight threat intelligence reports and Sandstorm findings. Place screenshots and key findings in a PowerPoint document in a concise, orderly format for the customer presentation.
4
Review network traffic optimization using traffic shaping policies to prioritize traffic based on applications, users, and services.
5
Identify security gaps for servers and applications hosted in cloud environments (AWS, Azure). Make appropriate recommendations for cloud security posture using Cloud Optix.
6
Wireless, UEM, endpoint, and server security controls are important aspects not fully covered by gateway security. Make appropriate recommendations for security add-ons and the MDR (Managed Detection and Response) service.
7
If uptime is absolutely critical, make appropriate recommendations for the TAM (Technical Account Manager) service and local reseller onsite support.
8
After recommendations are presented, the customer can engage Sophos Professional Services for customization, deployment, and knowledge transfer.
9
Final question: Based on Sophos Firewall's 30-day trial, does the organization have a better view into its security posture? Has visibility meaningfully improved?

Additional Resources: In addition to this Sophos Firewall PoC Guide, refer to the Sophos Endpoint PoC Guide and Cloud Optix PoC Guide when more than one product is involved in the opportunity.

Licensing

Licensing

Sophos Firewall uses a subscription-based licensing model. All licenses are managed through Sophos Central — the cloud management platform. 📖 License information docs →

License Bundles

🔵
Base Firewall

Core firewall + routing, Basic AV, IPS, App control, On-box reporting. Included with hardware purchase.

🛡️
Xstream Protection

Network Protection + Web Protection + Zero-Day Threat Protection (Sandstorm). Most common bundle.

🌐
Central Orchestration

SD-WAN, Site-to-Site VPN orchestration from Sophos Central. Required for managed SD-WAN deployments.

License Information & Registration

Licenses are tied to the device serial number and activated via Sophos Central. To view license status: go to System → Licensing → License information in the Sophos Firewall admin console. The page shows each subscription module, expiry date, and activation status.

Trial/PoC Licensing: During a PoC, Sophos partners can provision a 30-day NFR (Not for Resale) trial license via the Sophos Partner Portal. This enables full Xstream Protection features. Contact your Sophos SE or channel manager to provision trial keys before the PoC begins.

High Availability (HA) Licensing

Sophos Firewall supports Active-Active and Active-Passive HA configurations for high-availability deployments. HA licensing works as follows: 📖 HA documentation →

HA Type License Requirement Notes
Active-Passive Primary node requires full license. Auxiliary/standby node requires a Base Firewall license only. Most common HA deployment. Auxiliary is on hot standby — takes over if primary fails.
Active-Active Both nodes require identical full licenses (same bundles and term). Load balances traffic across both nodes. Higher throughput but both nodes must be licensed equally.
HA Cluster (3+ nodes) Each node requires its own full license set. Supported on virtual and cloud deployments. Contact Sophos for multi-node pricing.

Important: HA failover will not function correctly if the auxiliary node's license has expired or is missing required modules. Always verify both nodes show "Active" subscription status before relying on HA for production.

Migration

Migration from Competitive Firewalls

Migrating from a competitive firewall to Sophos Firewall is a common PoC scenario. Sophos provides migration tools and documentation for the most common platforms. Below are platform-specific guidance and key considerations. 📖 Migration docs →

🔴 Migrating from Fortinet FortiGate

Fortinet customers typically migrate due to licensing complexity (FortiGuard bundles), high renewal costs, or lack of integrated endpoint visibility. The Sophos Migration Tool supports direct import of FortiGate configuration exports.

Key Migration Steps:
  • Export FortiGate config via CLI: execute backup config tftp
  • Import into Sophos Migration Assistant tool
  • Review firewall policy mappings (Fortinet uses security policies; Sophos uses firewall rules)
  • Map FortiGuard categories to Sophos web policy categories
  • Recreate SD-WAN rules using Sophos SD-WAN profiles
  • Re-establish SSL VPN or IPsec tunnels using Sophos VPN wizard
Common Gotchas:
  • FortiGate VDOM (virtual domain) configs require separate migration per domain
  • FortiGuard DNS filter categories differ from Sophos — review and remap
  • FSSO (Fortinet SSO) replaced by AD/LDAP auth or Entra ID in Sophos
  • Verify QoS/traffic shaping policy equivalents
🟠 Migrating from Palo Alto Networks

Palo Alto customers commonly migrate when facing renewal cost increases or when looking to consolidate endpoint + firewall under a single vendor. Sophos Firewall matches PAN-OS App-ID capabilities through its Xstream DPI engine.

Key Migration Steps:
  • Export PAN-OS config (Device → Setup → Operations → Export)
  • Map Security Policies → Sophos Firewall Rules (App + User + Zone)
  • Recreate URL filtering profiles using Sophos Web Policy
  • Migrate GlobalProtect VPN users to Sophos Connect / SSL VPN
  • Recreate NAT rules and address objects in Sophos
  • Verify Panorama-managed policies for multi-device environments
Common Gotchas:
  • PAN App-ID to Sophos App Classification may not be 1:1 — run Discover Mode first to verify
  • Decryption policies need to be recreated (Sophos uses HTTPS Inspection rules)
  • User-ID agent replaced by AD Sync / Sophos Transparent Auth
  • Zone-based policy logic differs — map zones to Sophos network zones carefully
🟡 Migrating from SonicWall

SonicWall migrations are common due to hardware EOL cycles, feature parity concerns, and high total cost of ownership. Sophos Firewall provides an equivalent or superior feature set for SMB and mid-market segments.

Key Migration Steps:
  • Export SonicWall config (System → Settings → Export Settings)
  • Map SonicWall Access Rules to Sophos Firewall Rules
  • Recreate Address Objects, Service Objects in Sophos
  • Migrate SSL-VPN / Mobile Connect users to Sophos Connect client
  • Verify Content Filtering Service (CFS) categories vs Sophos Web Policy
  • Recreate WAN Failover / load balancing as Sophos SD-WAN Gateway policy
Common Gotchas:
  • SonicWall uses "zones" similar to Sophos — mapping is relatively straightforward
  • CFS URL categories differ — review web policy mappings carefully
  • SonicWall App Control Advanced rules need manual recreation in Sophos App Control
  • GVC (Global VPN Client) users must move to Sophos Connect — communicate to end users

Migration Best Practice: Run Sophos Firewall in Discover/TAP mode for 7–14 days alongside the existing firewall before cutover. This identifies all traffic patterns, applications, and users so Sophos Firewall rules can be tuned before going live. It eliminates surprise policy gaps on Day 1.

Remote Access

Remote VPN Users

Sophos Firewall provides multiple remote access VPN options to support remote workers. The recommended solution for most organizations is Sophos Connect — a lightweight SSL VPN client with automatic tunnel management. 📖 Remote Access VPN docs →

Sophos Connect (SSL VPN)

Recommended for most deployments. Auto-connects, supports split tunneling, MFA-ready. Client available for Windows, macOS, and Linux.

IPsec Remote Access

IKEv2/IPsec for clients that require it. Native support on iOS, Android, Windows, and macOS without additional client software.

Clientless VPN (HTML5)

Browser-based access to internal web apps and RDP/SSH — no client installation needed. Accessible via the Sophos User Portal.

How to Configure Sophos Connect (SSL VPN) — Step by Step

1
Enable SSL VPN: In the admin console, go to VPN → SSL VPN (Remote Access). Enable SSL VPN and configure the server certificate (use an existing trusted cert or Let's Encrypt). Set the VPN subnet (e.g. 10.10.10.0/24) and DNS servers.
2
Create VPN Users/Groups: Go to Authentication → Users and create user accounts, or sync from Active Directory / Entra ID via LDAP. Assign users to a VPN user group.
3
Configure Remote Access Profile: Go to VPN → SSL VPN (Remote Access) → Add. Define the permitted networks (split tunneling), assign the user group, and set the lease time and disconnect behavior.
4
Create Firewall Rule: Go to Firewall → Add Firewall Rule. Create a rule allowing traffic from the VPN zone to the internal LAN zone for required services. Apply appropriate security policy (IPS, web filtering).
5
Configure MFA (optional but recommended): Go to Authentication → Multi-Factor Authentication. Enable TOTP (Google Authenticator / Microsoft Authenticator) or integrate with your existing RADIUS/Azure MFA provider.
6
Distribute Sophos Connect Client: Users download the Sophos Connect client from the User Portal (https://[firewall-ip]/userportal) along with the pre-configured .scx connection file. Double-clicking the .scx file imports the VPN profile automatically.
7
Test and Verify: Have a test user connect from outside the network. Verify the correct IP is assigned from the VPN pool, check the SSL VPN log at Log Viewer → VPN, and confirm split tunneling is working as expected.

Remote Access Portal: Users can self-manage their VPN credentials, download the Sophos Connect client, and access Clientless VPN resources at: https://[your-firewall-IP-or-FQDN]/userportal

Site-to-Site VPN

For branch-to-branch or cloud connectivity, Sophos Firewall supports IPsec IKEv2 site-to-site VPN. 📖 Site-to-site VPN docs → Sophos Central Orchestration enables zero-touch SD-WAN mesh VPN across all branch firewalls from a single console — dramatically simplifying multi-site deployments.

United Kingdom & Worldwide
Tel: +44 (0)8447 671131
Email: sales@sophos.com
North America
Toll Free: 1-866-866-2802
Email: nasales@sophos.com
Australia & New Zealand
Tel: +61 2 9409 9100
Email: sales@sophos.com.au
Asia
Tel: +65 62244168
Email: salesasia@sophos.com
© Copyright 2026. Sophos Ltd. All rights reserved. · Sophos Firewall v22.0 · Interactive Web Edition
Success Criteria

PoC Success Criteria

Define the measurable targets that determine whether this PoC is a success. Set targets upfront, then fill in actual results as you work through the evaluation. The weighted score updates automatically.

No criteria defined yet
Weighted PoC Score
Total weight assigned: 0% (aim for 100%)
PoV Report

Generate PoV Report

Fill in the engagement details below, then click Generate Report to produce a branded, printable Proof of Value summary that captures all completed checklist items, dates, and findings.

PNG, JPG, SVG — max 2 MB. Displayed on the report cover.
CHECKLIST SUMMARY (auto-calculated from your progress above)