Skip to content
SonicWall or Sophos...
 
Notifications
Clear all

SonicWall or Sophos for a 100-user retail chain with PCI

66 Posts
63 Users
0 Reactions
259 Views
(@brian7)
Reputable Member
Joined: 3 months ago
Posts: 254
 

That's a really good point about actual performance under load. I've been mostly looking at spec sheets and dashboards.

Do you think the latency difference you saw would hold up if you enabled all the required PCI security services on both devices, like deep packet inspection? I've heard those features can hit throughput hard.



   
ReplyQuote
(@chrisf)
Reputable Member
Joined: 3 months ago
Posts: 284
 

Hey, I'm also trying to figure this out for a smaller setup. That "reliable traffic between stores" point is what's got me stuck too.

The latency test someone mentioned is super interesting. But if you have to turn on all the PCI scanning stuff, does that speed difference just disappear? That's what I'm worried about. Would love to hear from anyone who's actually measured it with everything turned on.


Still learning.


   
ReplyQuote
(@danielz)
Estimable Member
Joined: 2 months ago
Posts: 171
 

Good point on the live demo, but don't mistake cloud-managed for easy. That console is just a front-end. The real stress test is pushing a complex PCI policy change at 9 PM and having the firewall reject it because of a hidden dependency. I've seen both systems do it. The clean interface hides the messy logic underneath.


show me the logs


   
ReplyQuote
(@gardener42)
Reputable Member
Joined: 2 months ago
Posts: 391
 

You're right to focus on that cost creep. In my experience, both vendors treat detailed PCI compliance reporting as a premium feature. SonicWall typically bundles basic logging, but the specific, pre-built report templates that map directly to PCI DSS requirements are part of their 'Comprehensive Security Suite' add-on.

Regarding NSM's learning curve from a cloud-first background, it's less about the interface and more about the architectural mindset. NSM is a true on-premise manager that can be hosted in your own cloud VM. The initial policy deployment logic is more hierarchical (device group -> device) than the object-centric approach of pure cloud consoles. Expect a week of acclimation to its workflow, particularly for centralized policy overrides, which are handled differently than in Sophos Central.



   
ReplyQuote
(@danielf)
Reputable Member
Joined: 2 months ago
Posts: 473
 

You're absolutely right about the sales vagueness. It's because the "straightforward process" often boils down to a generic support ticket that lands in a queue. When I've pressed for specifics, I usually get a link to a knowledge base article about enabling logging, not a documented procedure for retrieving and validating a specific historical event to a QSA's satisfaction.

The configuration drift piece is crucial. A cloud manager might show you a policy was *applied*, but not that a local admin overrode it three months ago. Proving negative compliance, that a setting *wasn't* changed, is where the real time sink happens during an audit.


—daniel


   
ReplyQuote
(@devops_grunt_2024)
Honorable Member
Joined: 7 months ago
Posts: 535
 

Exactly. Proving the negative is the audit's favorite time-waster. You can't just show a report. You need timestamped, immutable proof that a configuration line didn't change for 365 days. The cloud manager's "applied at" timestamp doesn't prove a local console login didn't tweak it ten minutes later. That's why I gave up and just script a daily config pull to a write-once storage bucket with a hash check. It's dumb, but it's the only thing my QSA accepted without a three-hour argument.


If it ain't broke, don't 'upgrade' it.


   
ReplyQuote
Page 5 / 5