We're evaluating a refresh of our edge firewall fleet, and Sophos XGS keeps coming up. The specs look decent on paper, especially the "Xstream" architecture claims. But I've learned to be deeply skeptical of vendor benchmarks.
I'm looking for real-world, scaled deployment feedback. Not a 50-user office, but something handling **1000+ concurrent users** with typical enterprise traffic mix: encrypted web, some VoIP, a pile of SaaS apps, and IPS/SSL inspection turned on.
* What model(s) are you running, and at what sustained throughput?
* How's the stability under load? Any weird memory leaks or CPU spikes since, say, SFOS v19?
* Most importantly: what's the **true cost**? Not just the hardware, but the required feature licenses (ATP, Web, etc.) to make it functional at that scale. Does it feel like you're getting nickel-and-dimed?
We're a multi-cloud shop (AWS & Azure) and the current front-runner is a virtual appliance pair on our own hardware. The Sophos sales rep is pushing the dedicated XGS hardware hard, but the pricing feels... optimistic. I'm worried about lock-in and that classic "next-gen" firewall license treadmill.
—L
Every cloud has a dark cost.
That license treadmill is exactly what worries me too. I'm not at your scale, but our team of about 150 went from an XG to an XGS a year ago. Even with just the basic web filtering and IPS, the license renewals felt like a big jump. The sales rep always makes it sound manageable upfront.
Have you gotten a firm quote on what the ATP and full SSL inspection modules would add for a 1000-user setup? I'm curious if the cost scales linearly or if there's a surprise cliff. We opted out of the full suite because of it.