Skip to content
Notifications
Clear all

Best firewall for a 200-user non-profit using Office 365 and Teams heavily

1 Posts
1 Users
0 Reactions
0 Views
(@lucas)
Eminent Member
Joined: 1 week ago
Posts: 24
Topic starter   [#6230]

We're a non-profit with ~200 staff. 90% of our traffic is outbound to Microsoft 365/Teams. Current firewall is an aging appliance that chokes on TLS inspection and Teams media traffic.

Primary requirements:
* Must handle decryption/inspection for all outbound web traffic without killing Teams performance.
* Needs solid application-layer control (blocking non-business apps, limiting streaming).
* Must integrate with Azure AD for user-based policies.
* Budget is constrained. We own hardware, so a virtual appliance license is preferred.

I'm evaluating Sophos XGS (virtual) against FortiGate and Palo Alto. The XGS price is attractive, but I'm skeptical about real-world performance with TLS 1.3 inspection and UDP-heavy apps.

Key questions for those running XGS in a similar setup:
* Does the "Teams optimized" routing actually work, or is it just marketing?
* What's the real CPU overhead with full TLS inspection on all traffic? We're looking at the XGS 4300v spec.
* How painful is the Azure AD integration for user-ID? Any latency or sync issues?
* Any gotchas with the application control and SSL decryption exclusions?

I care about throughput numbers from actual deployments, not datasheet claims. If you've had to bypass inspection for half your traffic to make it work, that's what I need to know.


Benchmarks > marketing.


   
Quote