# Sophos Firewalls

Sophos provides an extensive comparison of its XGS firewall models based on key parameters like performance, connectivity, scalability, and use cases. Here’s a summarized comparison across different XGS series models:

***

#### **Comparison of Sophos XGS Firewall Models**

<table data-header-hidden><thead><tr><th></th><th width="98"></th><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Category</strong></td><td><strong>Model Series</strong></td><td><strong>Performance</strong></td><td><strong>Key Features</strong></td><td><strong>Use Cases</strong></td></tr><tr><td><strong>Desktop Firewalls</strong></td><td><strong>XGS 87/87w, XGS 107/107w</strong></td><td>Entry-level models, suited for small offices; &#x3C;1 Gbps throughput</td><td>4 GbE ports, optional Wi-Fi, USB ports, compact form factor</td><td>Ideal for small businesses and home offices requiring basic firewall and security features.</td></tr><tr><td></td><td><strong>XGS 116/116w, XGS 126/126w, XGS 136/136w</strong></td><td>Higher throughput (1-2 Gbps) and enhanced connectivity</td><td>8 GbE ports, optional Wi-Fi, additional scalability for branch offices.</td><td>Branch offices and SMBs needing more advanced connectivity and throughput.</td></tr><tr><td><strong>1U Rackmount Firewalls</strong></td><td><strong>XGS 2100, 2300, 3100, 3300</strong></td><td>Mid-range performance, up to 20 Gbps firewall throughput</td><td>8-12 GbE ports, SFP/SFP+ connectivity, modular bay options.</td><td>Suitable for mid-sized organizations or distributed enterprises with moderate traffic and remote-site integration needs.</td></tr><tr><td></td><td><strong>XGS 4300, 4500</strong></td><td>High-performance models with 40+ Gbps throughput</td><td>Up to 12 GbE ports, 4 SFP+ slots, 1U rackmount form factor, modular options for customization.</td><td>Distributed networks requiring high throughput, advanced application filtering, and scalability.</td></tr><tr><td><strong>2U Rackmount Firewalls</strong></td><td><strong>XGS 5500, 6500, 7500, 8500</strong></td><td>Enterprise-grade performance, supporting 100+ Gbps throughput</td><td>Up to 16 GbE ports, additional scalability via optional network modules, 2U rackmount form factor.</td><td>Ideal for large enterprises, campus environments, and data centers demanding high throughput and scalability.</td></tr><tr><td><strong>Remote Edge Devices</strong></td><td><strong>SD-RED 20, SD-RED 60</strong></td><td>Remote access security, supporting gigabit connectivity</td><td>Simplified deployment, plug-and-play functionality, secure VPN connections.</td><td>Extending secure network access to remote and branch locations without IT expertise.</td></tr></tbody></table>

***

#### **Key Performance Metrics**

| **Metric**                 | **Desktop Models** | **1U Rackmount Models** | **2U Rackmount Models** | **SD-RED Devices** |
| -------------------------- | ------------------ | ----------------------- | ----------------------- | ------------------ |
| **Firewall Throughput**    | <2 Gbps            | 20–40 Gbps              | 100+ Gbps               | 1 Gbps             |
| **IPS Throughput**         | \~1 Gbps           | 10–20 Gbps              | 50+ Gbps                | -                  |
| **SSL VPN Throughput**     | \~250 Mbps         | \~2–3 Gbps              | \~10+ Gbps              | -                  |
| **Concurrent Connections** | \~1 Million        | \~3–8 Million           | 10+ Million             | \~10,000           |

***

#### **Scalability and Modular Options**

| **Model Series**    | **Expansion Options**                                                               |
| ------------------- | ----------------------------------------------------------------------------------- |
| Desktop Models      | Fixed configurations with optional Wi-Fi modules and basic GbE ports.               |
| 1U Rackmount Models | Expandable network interfaces via optional modules (e.g., SFP+, GbE, or PoE ports). |
| 2U Rackmount Models | Maximum scalability with high port density and multiple redundant options.          |
| SD-RED Devices      | No scalability options; designed for simplicity and remote site integration.        |

***

#### **Sophos Central Integration**

All XGS firewalls are managed via **Sophos Central**, offering unified threat management (UTM), deep packet inspection (DPI), synchronized security with Sophos Endpoint solutions, and easy deployment through the cloud.

Now we will start the configuration on sophos FW home edtion......


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://ghoulsec.gitbook.io/ghoulsec-vault/cyber-security-base/network-security/firewalls/sophos-security-suite/sophos-firewalls.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
