Visibility and Protection
Sophos Firewall offers the best protection to stop the latest hacks and attacks dead in their tracks – before they get on your network.
Deep Packet Inspection
The Xstream Deep-Packet Inspection (DPI) engine provides high-performance traffic scanning for IPS, AV, Web Protection, and App Control in a single streaming engine.
- TLS 1.3 inspection
- Next-Gen Intrusion Prevention (IPS)
- Zero-day threat protection
- Proxy-based dual-engine AV scanning
- Perimeter defenses
- Country-based blocking policy
Encrypted Traffic
Xstream TLS Inspection 1.3 with industry-leading performance, visibility, policy tools, and built-in intelligence removes an enormous blind spot in your protection.
- TLS 1.3 without downgrading
- Intelligent traffic selection
- Pre-packaged exception list
- Powerful policy engine
- Covers all ports/protocols
- Supports all modern cypher suites
- Unmatched visibility and error handing
Zero-Day and ML Protection
Sophos Firewall leverages Sophos’ industry-leading machine learning technology (powered by SophosLabs Intelix) to instantly identify the latest ransomware and unknown threats before they get on your network.
- SophosLabs Data Scientists
- Multiple Machine Learning Models
- Static File Analysis
- Dynamic file analysis
Cloud Sandbox
Sophos Zero-day Dynamic File Analysis uses next-gen cloud-sandbox technology powered by deep-learning and the best technology from Intercept X, to provide your organization with the best protection against zero-day threats like the latest ransomware and targeted attacks coming in through phishing, spam, or web downloads.
- Dynamic sandboxing analysis
- Deep learning static file analysis
Cloud Sandbox
Sophos Zero-day Dynamic File Analysis uses next-gen cloud-sandbox technology powered by deep-learning and the best technology from Intercept X, to provide your organization with the best protection against zero-day threats like the latest ransomware and targeted attacks coming in through phishing, spam, or web downloads.
- Dynamic sandboxing analysis
- Deep learning static file analysis
Web Protection
Sophos’ Web Protection engine is backed by SophosLabs and includes innovative technologies required to identify and block the latest web threats.
- Advanced Web Protection
- Pharming protection
- HTTPS scanning
- Potentially unwanted app control
- SophosLabs
Synchronized Security
Our revolutionary Security Heartbeat links your Sophos managed endpoint with your firewall to share health and other valuable information enabling an automated and coordinated response to isolate threats and prevent lateral movement.
- Security Heartbeat
- Destination Heartbeat Protection
- Synchronized App Control
- Lateral Movement Protection
- Synchronized User ID
Advanced Threat Protection
Sophos Firewall delivers advanced threat protection to instantly identify bots and other advanced threats while defending your network from today’s sophisticated attacks.
- Security Heartbeat
- Multi-layered, call-home protection
- Intelligent firewall policies
- Traffic light style indicators
User Identity
User identity-based policies and unique user risk analysis give you the knowledge and power to regain control of your users before they become a serious threat to your network.
- User identity powers all firewall polices and reporting
- User Threat Quotient (UTQ) identifies the top risk users on your network
- Synchronized User ID
- Flexible authentication options including directory services
- Two-factor Authentication (2FA) One-time Password Support for Access to key system areas
Application Control
Complete application visibility and control over all applications on your network with deep-packet scanning technology and Synchronized App Control that can identify all the applications that are currently going unidentified on your network.
- Visibility and control over thousands of applications
- CASB cloud app visibility
- Synchronized App Control
- User-based application policies
- Traffic shaping (QoS) prioritizes bandwidth allocation to critical applications and limits bandwidth for non-business applications
Web Control
Full visibility and control over all your web traffic with flexible enforcement tools that work the way you need, with options for user and group enforcement of activity, quotas, schedules, and traffic shaping.
- Enterprise Secure Web Gateway (SWG) policy model
- Template-driven activity control with predefined workplace and compliance policies
- Education and SafeSearch features
- Comprehensive traffic enforcement
- Traffic shaping (QoS)
Content Control
Flexible, user-based monitoring and control of keyword content and downloadable content, including files types via FTP, HTTP, or HTTPS.
- Web keyword monitoring
- File download filtering templates
- Policy-based outbound email DLP
- Web caching
Business Applications
Combine next-gen firewall capabilities with our enterprise-class web application firewall to protect your critical business applications from hacks and attacks while still enabling authorized access.
- Next-generation IPS
- Web Application Firewall
- Granular, user-based protection
Email and Data
Protect your email from spam, phishing, and data loss with our unique all-in-one protection that combines policy-based email encryption with DLP and anti-spam.
- Full MTA store and forward support
- Live anti-spam
- SPX encryption
- Policy-based DLP
- Self-serve user portal