Proof of Value Guide
PoC Progress Overview
Click any card to jump to that section.
What's New in Sophos Firewall v22.0
Sophos Firewall OS v22.0 is the current major release, introducing significant new capabilities across threat detection, identity management, and network operations. 📖 Full v22.0 docs →
🛡️ NDR Active Threat Intelligence
Integration with Taegis NDR iSensor and NDR Essentials — delivers network detection and response with AI-powered behavioral analysis. Sophos Firewall acts as a sensor feeding telemetry to Taegis for correlation across the entire estate.
🌐 Third-Party Threat Feeds (Active Threat Response)
Ingest external IOC threat feeds directly into policy. The Active Threat Response with MDR Threat Feeds lets Sophos MDR automatically push threat intel to block malicious IPs and domains in real time.
🔑 Microsoft Entra ID SSO
Microsoft Entra ID (Azure AD) integration with Captive Portal SSO — users authenticate via their Entra credentials. Eliminates duplicate user directories and reduces friction for cloud-first organizations.
🔒 Let's Encrypt Certificates
Native Let's Encrypt ACME certificate provisioning and auto-renewal for WAF and SSL VPN. Removes the need for manual certificate management.
🌍 DHCP Prefix Delegation (IPv6)
Full IPv6 DHCPv6-PD support — automatically delegates IPv6 prefixes to downstream routers, enabling enterprise-grade IPv6 deployments without manual subnetting.
💾 Backup & VPN Enhancements
Selective backup restore of config sections. SD-WAN policy routing improvements, BGP enhancements, and IPsec IKEv2 improvements for site-to-site tunnels.
XGS Series Hardware (Current Generation):
Desktop: XGS 88/88w · 108/108w · 118/118w · 128/128w · 138
Rack/Mid-range: XGS 2100/2300/3100/3300/4300/4500 | Enterprise: XGS 5500/6500/7500/8500
All XGS appliances include the Xstream Flow Processor for hardware-accelerated TLS inspection and FastPath traffic offloading.
📺 TechVids — v22.0 Feature Walkthroughs
Auto-renewal for WAF & SSL VPN
IOC ingestion & policy blocking
MDR threat feed auto-blocking
Azure AD authentication walkthrough
DHCPv6-PD enterprise setup
SD-WAN & IPsec improvements
Selective config section restore
First-time firewall setup walkthrough
Introduction
This guide is designed for Sophos system engineers to get the best results from a Sophos Firewall deployment during a proof of concept (PoC) exercise. It covers how to approach different PoC scenarios and concludes with success criteria checklists to eliminate security gaps.
The guide includes suggested questionnaires covering pain points with existing solutions, the recommended workflow, and how to present findings with recommendations to improve security posture in a customer's environment. Content is based on Sophos Firewall v22.0. For questions, contact the Sophos GSE team at gse@sophos.com.
Overview
Sophos Firewall provides unrivaled visibility into risky users, unwanted applications, suspicious payloads, and persistent threats. It integrates a full suite of modern threat protection technologies that are easy to set up and maintain. Unlike legacy firewalls, Sophos Firewall communicates with other security systems on the network, enabling it to act as a trusted enforcement point — automatically containing threats and blocking malware from spreading or exfiltrating data in real time.
Sophos Firewall has three key advantages over other network firewalls:
Visibility
Superior visibility into risky activity, suspicious traffic, and advanced threats through a visual dashboard, cloud and on-box reporting, and unique risk insights.
Protection
Powerful next-gen protection technologies including deep learning and intrusion prevention to keep the organization secure against known and unknown threats.
Response
Automatic threat response via Synchronized Security — instantly identifies and isolates compromised systems on the network to stop threats from spreading.
Initial Deployment & Administration
Sophos Firewall offers flexible deployment options to meet the needs of any organization. It can be deployed in four ways:
Hardware Appliance
Sophos Firewall hardware devices come pre-loaded and ready to deploy. Delivers Visibility, Protection, and Response out of the box.
Software
Install Sophos Firewall onto any Intel-compatible hardware. Ideal for organizations wanting to Consolidate, Simplify, & Save on hardware costs.
Virtual Appliance
Runs on VMware, Citrix, Microsoft Hyper-V, Nutanix, and KVM. Suitable for Retail, Branch Office, ICS & SD-WAN environments.
Cloud (Azure / AWS)
Deploy Sophos Firewall in the cloud on Azure and AWS for Synchronized Security & Automated Response in cloud-native environments.
Deployment Modes
Gateway Mode
In Gateway Mode, Sophos Firewall acts as the primary network gateway — routing all traffic between internal segments and the outside world. This is the ideal solution for organizations replacing an existing firewall or deploying a new one. All security features are fully supported in this mode. 📖 Gateway mode setup →
Bridge Mode
In Bridge Mode, Sophos Firewall sits inline between an existing firewall and the internal network, adding deep packet inspection, IPS, malware scanning, and email content scanning without changing any IP schema. It augments security to an upstream firewall by detecting unknown applications and threats it may miss. Selected Sophos models support a hardware bypass module to ensure network continuity during hardware failure.
Best for: Organizations that want to add Sophos Firewall capabilities alongside an existing firewall without network reconfiguration. Supports Layer 3 bridge (mixed mode) for hybrid deployments. Selected XGS models support a hardware bypass module for uninterrupted traffic flow during hardware failure. 📖 Bridge mode setup →
Discover Mode (TAP / SPAN / Port Mirror)
Discover Mode — also known as Test Access Point (TAP), port mirroring, or SPAN mode — lets you deploy Sophos Firewall to passively monitor all network traffic without any changes to the existing network schema. A switch forwards a copy of every packet to the Sophos Firewall for analysis and reporting.
This mode is ideal for PoC demonstrations — a partner can identify threats the existing firewall is missing without disrupting the live environment. It also unlocks Synchronized Security capabilities, including endpoint health status visibility and automatic isolation of infected systems. 📖 Discover mode setup →
Visibility
Lack of visibility into security posture highlights a significant challenge: if you don't know how a threat got in, it's difficult to prevent future attacks. The longer a threat remains in the network, the greater the risk. According to a Vanson Bourne survey of 3,100 IT managers globally, organizations took an average of 13 hours to detect threats — ample time for attackers to deliver payloads.
Control Center
Sophos Firewall's Control Center provides an unprecedented level of visibility into activity, risks, and threats on the network. It uses traffic-light indicators to focus attention on critical items: Red requires immediate attention, Yellow indicates a potential problem, and Green means no action is required.
Sophos Central Management & Reporting
Sophos Central provides a unified interface for managing multiple Sophos Firewalls and the full Sophos security portfolio. It includes alerting, backup management, one-click firmware updates, and Group Firewall Management for synchronizing policies across all firewalls with a few clicks. Central Firewall Reporting (CFR) is bundled at no extra cost — delivering rich analytics on user behavior, application usage, and security events with interactive dashboards and drill-down syslog data. The free tier retains data for 7 days; CFR Advanced extends retention up to 365 days per firewall. Sophos Firewalls can also forward logs to external syslog servers or SIEM systems for long-term storage. 📖 Central management docs →
Key question: To highlight Sophos Firewall's visibility value, ask customers where their current firewall solution may be lacking. Use the checklist below to guide the conversation.
Visibility Assessment Checklist
Connectivity
When evaluating connectivity requirements, consider not only the current topology but also future growth. Select a firewall that offers flexible deployment options — both on-premises and cloud — with appropriate management tools. For organizations with small remote locations, consider SD-WAN to securely and affordably connect those sites.
SD-WAN (Software-defined Wide Area Network) is a virtual WAN architecture that allows enterprises to leverage any combination of transport services — MPLS, LTE, and broadband — to securely connect users to applications. Sophos Firewall v19+ provides granular routing decisions via SD-WAN profiles that route traffic based on application, network, user, or service, using SLA parameters (jitter, latency, packet loss) with active-backup and load-balancing support.
Sophos Firewall delivers zero-impact failover — automatically rerouting connections to the next available gateway when an active gateway goes down or fails its SLA, with no user-visible disconnection.
SD-WAN VPN Orchestration 📖 docs →
Sophos Central provides a dedicated SD-WAN Connection Group to manage connectivity between multiple Sophos Firewalls from a single interface. Select head office and branch firewalls, and Sophos Central automatically establishes IPsec route-based VPN tunnels between them in minutes — with no manual tunnel configuration required.
- Full-mesh — every site connected to every other site
- Hub-and-spoke — branches connect to a central hub
- Mix of both in a single SD-WAN group
- Zero-touch via Sophos Central — new XGS hardware auto-registers and pulls config
- Light-touch via USB stick — pre-stage config for remote deployments
- World map view of all connected sites with IPsec tunnel status
Connectivity Requirements Checklist
Protection
Network security has evolved as threats have shifted from direct network attacks to infecting systems and spreading laterally. Best practice is to segment the LAN into smaller subnets using zones or VLANs, then connect them through the firewall — enabling anti-malware and IPS protection between segments to identify and block lateral movement.
Next-gen Intrusion Prevention System (IPS)
Next-generation IPS provides advanced protection from modern threats, going beyond traditional server and network resources to protect users and applications on the network.
Security Heartbeat™
Security Heartbeat provides constant communication between Sophos-protected endpoints and Sophos Firewall, enabling administrators to visualize endpoint health status in real time. Green = healthy; Amber/Yellow = attention needed; Red = immediate action required.
Lateral Movement Protection
When a computer is infected or nefarious activity is detected by either Sophos Firewall or an endpoint, it automatically isolates the infected device. Other machines in the same broadcast domain stop communicating with it until it is cleaned.
Synchronized Application Control
One of the key capabilities of an NGFW is detecting Layer-7 applications regardless of port or protocol. Every 30 seconds, Sophos-protected endpoints send health status and application information. Sophos Firewall categorizes traffic down to the application path on the endpoint — giving administrators full control over the network.
TLS 1.3 Scanning
Encrypted TLS/SSL traffic accounts for ~80% of internet traffic. Sophos Firewall can scan TLS 1.3 natively without downgrading to TLS 1.2. The Xstream architecture with Fastpath decrypts and scans traffic with minimal performance trade-off.
Active Threat Response — Components Overview
Sophos Firewall v22.0 unifies multiple threat intelligence and detection layers under the Active Threat Response framework. These components work together to detect, feed, and automatically act on threat intelligence — from zero-day files to live MDR-sourced IOCs.
Sophos X-Ops is the cross-functional threat intelligence team behind Sophos Firewall's advanced detection. When the firewall encounters a file with no prior conviction, it submits it to the cloud-based Sandstorm sandbox — using deep learning and Intercept X to emulate and analyse behaviour. The resulting report gives threat responders full visibility into attacker techniques for proactive threat hunting. 📖 docs →
Customers with Sophos MDR licenses get live threat intel automatically pushed from the Sophos MDR operations team directly to the firewall. Malicious IPs, domains, and URLs are blocked in real time without any manual intervention — preventing lateral movement of compromised hosts the moment a threat is identified by the MDR team. 📺 Watch demo →
New in v22.0 — ingest external IOC threat feeds (STIX/TAXII and custom formats) from any third-party intelligence provider directly into Sophos Firewall policy. Malicious indicators are automatically translated into firewall rules to block matching traffic, keeping the firewall current with the wider threat landscape beyond Sophos's own intelligence. 📺 Watch demo →
Integration with Taegis NDR iSensor and NDR Essentials — Sophos Firewall acts as a network sensor, feeding traffic telemetry to Sophos Taegis for AI-powered behavioural analysis and cross-estate correlation. NDR Essentials provides network detection and response for organisations that need deep visibility beyond endpoint-only solutions, detecting threats that evade signature-based engines.
How they work together: Sophos X-Ops provides the intelligence backbone → MDR Threat Feeds deliver real-time auto-response → Third-Party Feeds extend coverage to external IOC sources → NDR Essentials adds network-layer behavioural detection. All four feed into a unified Active Threat Response posture on Sophos Firewall v22.0.
Cloud and SaaS Application Detection
Shadow IT — employees using unsanctioned cloud services like Dropbox or Google Drive — poses data security risks. Sophos Firewall provides full visibility and control over cloud applications, allowing IT to sanction, unsanction, or apply QoS policies per application.
Protection Checklist — Identifying Security Gaps
Management
Sophos Firewall is managed via a secure HTTPS web UI. Color-coded widgets and an intuitive UX provide a shorter learning curve for administrators with no prior firewall experience. All tools for day-to-day tasks and network diagnostics are bundled — no add-on modules or paid subscriptions required.
The firewall provides at-a-glance information on whether the network is under attack, alerting administrators to misconfigurations and important security notifications. The live log viewer is available from every screen with a single click.
Management Evaluation Checklist
Proof of Concept Success Verification Check
Once Sophos Firewall has been deployed according to requirements, it is time to evaluate success criteria. Customers may have their own testing methodologies; the checklists below can be used to verify the setup systematically.
Network Connectivity Requirement
Security and Authentication Requirement — Egress Filter Policy
Egress filtering inspects outgoing data traffic and prevents unauthorized traffic from leaving. Policy focuses on client-side protection, reducing attack surface, and enforcing acceptable use policy.
Security and Authentication Requirement — Ingress Filter Policy
Ingress filtering applies when Sophos Firewall receives packets from an untrusted source or WAN interface. Policy focuses on securing web services, email, and NAT configurations.
Logging, Reporting, and Administration Checklist
Administration is an essential part of network protection. Correct security practices and visibility into network activity help distinguish normal from abnormal behaviour — enabling proactive prevention.
Review the Findings
The framework in this guide is designed to provide guidance across various use cases and test scenarios. The appropriate depth and focus of the PoC will be influenced by the organization's security maturity level, industry vertical, and regulatory guidelines.
Need help? If at any stage you would like assistance running or assessing the findings of your proof of concept, contact the Sophos GSE team at gse@sophos.com.
Conclusion — Suggested Activities & Workflow
First 10 Days Activities
Day 30 — Proof of Concept Review
Use the information gathered during the 30-day trial to fully evaluate Sophos Firewall:
Additional Resources: In addition to this Sophos Firewall PoC Guide, refer to the Sophos Endpoint PoC Guide and Cloud Optix PoC Guide when more than one product is involved in the opportunity.
Licensing
Sophos Firewall uses a subscription-based licensing model. All licenses are managed through Sophos Central — the cloud management platform. 📖 License information docs →
License Bundles
Core firewall + routing, Basic AV, IPS, App control, On-box reporting. Included with hardware purchase.
Network Protection + Web Protection + Zero-Day Threat Protection (Sandstorm). Most common bundle.
SD-WAN, Site-to-Site VPN orchestration from Sophos Central. Required for managed SD-WAN deployments.
License Information & Registration
Licenses are tied to the device serial number and activated via Sophos Central. To view license status: go to System → Licensing → License information in the Sophos Firewall admin console. The page shows each subscription module, expiry date, and activation status.
Trial/PoC Licensing: During a PoC, Sophos partners can provision a 30-day NFR (Not for Resale) trial license via the Sophos Partner Portal. This enables full Xstream Protection features. Contact your Sophos SE or channel manager to provision trial keys before the PoC begins.
High Availability (HA) Licensing
Sophos Firewall supports Active-Active and Active-Passive HA configurations for high-availability deployments. HA licensing works as follows: 📖 HA documentation →
Important: HA failover will not function correctly if the auxiliary node's license has expired or is missing required modules. Always verify both nodes show "Active" subscription status before relying on HA for production.
Migration from Competitive Firewalls
Migrating from a competitive firewall to Sophos Firewall is a common PoC scenario. Sophos provides migration tools and documentation for the most common platforms. Below are platform-specific guidance and key considerations. 📖 Migration docs →
Migration Best Practice: Run Sophos Firewall in Discover/TAP mode for 7–14 days alongside the existing firewall before cutover. This identifies all traffic patterns, applications, and users so Sophos Firewall rules can be tuned before going live. It eliminates surprise policy gaps on Day 1.
Remote VPN Users
Sophos Firewall provides multiple remote access VPN options to support remote workers. The recommended solution for most organizations is Sophos Connect — a lightweight SSL VPN client with automatic tunnel management. 📖 Remote Access VPN docs →
Recommended for most deployments. Auto-connects, supports split tunneling, MFA-ready. Client available for Windows, macOS, and Linux.
IKEv2/IPsec for clients that require it. Native support on iOS, Android, Windows, and macOS without additional client software.
Browser-based access to internal web apps and RDP/SSH — no client installation needed. Accessible via the Sophos User Portal.
How to Configure Sophos Connect (SSL VPN) — Step by Step
Remote Access Portal: Users can self-manage their VPN credentials, download the Sophos Connect client, and access Clientless VPN resources at: https://[your-firewall-IP-or-FQDN]/userportal
Site-to-Site VPN
For branch-to-branch or cloud connectivity, Sophos Firewall supports IPsec IKEv2 site-to-site VPN. 📖 Site-to-site VPN docs → Sophos Central Orchestration enables zero-touch SD-WAN mesh VPN across all branch firewalls from a single console — dramatically simplifying multi-site deployments.
How Do I Configure…?
Quick reference for the most common configuration tasks. Each item links directly to the relevant section of the Sophos Firewall v22.0 documentation.
Documentation Quick Links
All official Sophos Firewall v22.0 documentation is available at docs.sophos.com. Key sections are linked below for fast reference during a PoC.
Initial setup, licensing, admin access
Policies, networking, security modules
SSL VPN, IPsec, User Portal, RED
CLI reference, diagnostics, advanced config
HA setup, licensing, failover monitoring
AWS, Azure, VMware, Hyper-V, KVM
Fortinet, Palo Alto, SonicWall, Check Point
REST API, automation, integrations
Sophos Community — questions, tips, KB articles
PoC Success Criteria
Define the measurable targets that determine whether this PoC is a success. Set targets upfront, then fill in actual results as you work through the evaluation. The weighted score updates automatically.
Generate PoV Report
Fill in the engagement details below, then click Generate Report to produce a branded, printable Proof of Value summary that captures all completed checklist items, dates, and findings.