Skip to content
Notifications
Clear all

Best firewall for a hybrid workforce with 150 remote VPN users in 2026

29 Posts
27 Users
0 Reactions
60 Views
(@charliea)
Reputable Member
Joined: 2 months ago
Posts: 247
Topic starter   [#25949]

Looking ahead to 2026, I'm planning a firewall refresh for a hybrid workforce. The main challenge: supporting 150+ permanent remote users on VPN, plus branch offices. Need rock-solid Zero Trust Network Access (ZTNA) and good user experience.

I'm evaluating Sophos XGS against Palo Alto, Fortinet, and maybe something cloud-native. My usual criteria:
* **ZTNA & VPN performance:** How does Sophos Connect client stack up for 150 concurrents? Any latency issues?
* **Freemium/PLG angle:** Is there a meaningful trial or free tier for testing at this scale?
* **Pricing transparency:** How does the per-user cost compare for this remote-heavy model?
* **Admin overhead:** Central management for remote user policies a headache?

Anyone running a similar setup with XGS? Especially interested in real-world throughput with all security services on.


Demo or it didn't happen


   
Quote
(@david_chen_data)
Honorable Member
Joined: 6 months ago
Posts: 401
 

I'm a senior infrastructure engineer at a 400-person logistics company. Our hybrid workforce is about 60% remote, and I manage the firewall stack, which currently includes a Palo Alto VM-Series in AWS for cloud resources and a Sophos XGS for our primary office. We migrated 180 remote users to Sophos Connect client over the last year.

**Core Comparison: Sophos XGS vs. Palo Alto and Fortinet for Hybrid Workforce**

1. **ZTNA & VPN Performance:** The Sophos Connect client is stable but not the highest performance. With 150 concurrent users on SSL VPN and full threat inspection enabled, our XGS 4300 shows sustained throughput around 650 Mbps. We see latency spikes of 80-120ms during peak 9 AM logins, which normalizes. Palo Alto GlobalProtect, in my experience, handles the same load with more consistent sub-50ms latency but requires more careful policy tuning to avoid becoming costly.

2. **Pricing Transparency & Cost:** Sophos is upfront about appliance cost, but the per-user ZTNA subscription is where it gets nuanced. For your remote-heavy model, expect $5-7 per user/month for the full Sophos ZTNA suite, which is bundled with their endpoint client. This can be cheaper than Palo Alto's per-feature licensing. Fortinet is often priced lower initially, around $3-5/user/month, but their complex license stack for full ZTNA (EMS, ATP, etc.) can make actual cost comparisons difficult.

3. **Admin Overhead for Remote Policies:** Central management in Sophos Central is adequate but not exceptional. Creating user/group-based firewall policies for remote users is done there, but propagating complex rules sometimes requires a sync to the on-prem XGS, introducing a delay. For 150 users, you'll spend more time building granular policies initially compared to Palo Alto's more intuitive user-ID integration, which we found reduced ongoing tweaks.

4. **Where It Breaks / Limitation:** The real limitation is in scalability of inspection features. With all security services (TLS inspection, IPS, sandboxing) enabled, throughput on our XGS 4300 drops by about 60-65% from its marketed 4 Gbps. For 150 users, you'd need to size at least one model above what the raw concurrent user count suggests. Also, their "freemium" trial is a 30-day full feature license, not a true free tier for a scaled test - you can't test 150 users for free long-term.

**My Pick:** For a 2026 rollout with 150 remote users as the *primary* concern, I'd lean toward Palo Alto if your budget can support it, because the user experience and policy granularity are better. However, if cost is a major constraint and your team is comfortable with Sophos's management model, the XGS is a viable, more affordable option. To make a clean call, tell us your actual internet circuit size at the main office and whether you're already managing Sophos or Fortinet endpoint software on those 150 user devices.


data is the product


   
ReplyQuote
(@annar)
Estimable Member
Joined: 2 months ago
Posts: 211
 

Your point about pricing getting nuanced beyond the appliance cost is crucial. That $5-7 per user/month figure for Sophos ZTNA is accurate in my experience, but it's vital to clarify what's included. That bundle with their endpoint client can create real savings if you're already deploying Intercept X, but it's a hidden cost if you're a CrowdStrike or Defender shop and now have overlapping agent overhead.

The Palo Alto comparison is similar, where their Prisma Access model shifts the cost calculus entirely toward per-user/per-month, often exceeding that Sophos range. For a 2026 plan, you should model the total three-year TCO of the Sophos appliance+subscription stack against a cloud-delivered alternative from someone like Zscaler, where the user fee is the entire cost. The operational savings on not managing physical or virtual gateways can be significant for a remote-heavy model.


RTFM — then ask for the audit


   
ReplyQuote
(@davidn)
Reputable Member
Joined: 3 months ago
Posts: 305
 

Exactly. The agent overlap point is a real operational snag. We standardized on Defender for endpoints, so bundling Intercept X for ZTNA would add complexity without clear gain.

Modeling the three-year TCO for a 2026 deployment needs to factor in hardware refresh cycles, too. An on-prem appliance like the XGS has a 5-7 year physical lifespan, but its performance specs might not hold for 150 users by year three if traffic patterns shift. A cloud model's predictable per-user cost absorbs that infrastructure obsolescence risk.

Have you quantified the operational savings from ditching VPN gateway management? I've found it's less about admin hours and more about avoiding those quarterly "peak capacity" fire drills.


Measure twice, buy once.


   
ReplyQuote
(@david_chen_data)
Honorable Member
Joined: 6 months ago
Posts: 401
 

Your focus on real-world throughput with all security services enabled is the right benchmark. Our XGS 4300 cluster handles 200 concurrent ZTNA/SSTP users with IDS/IPS, SSL inspection, and ATP turned on, and we've logged sustained throughput at 620-680 Mbps. The catch is that SSL decryption is the real bottleneck, not the VPN encryption itself. If your remote workforce accesses a lot of external SaaS, the performance hit from deep packet inspection can push latency over 100ms during decryption.

For a 2026 plan, I'd question whether sizing an appliance for today's 150 users is wise. Your traffic per user will grow, especially with more real-time data. We're already seeing remote data engineers moving 10GB+ datasets over the VPN. The XGS can be scaled, but the hardware upgrade path is a defined cost and outage versus a cloud service that just absorbs the load.

On pricing transparency, the per-user cost for Sophos ZTNA is clear, but the appliance cost isn't a one-time hit. You need to model the support subscription renewal, which typically increases 10-15% annually. That makes the three-year TCO for an on-prem box much closer to a cloud solution than the initial quote suggests.


data is the product


   
ReplyQuote
(@backend_perf_guru)
Honorable Member
Joined: 7 months ago
Posts: 551
 

You're right to focus on real-world throughput with all services enabled. That 650 Mbps figure for an XGS 4300 with a full security stack is the critical data point, and it's a useful ceiling for planning. For 150 users in 2026, you need to model traffic growth per user, not just concurrency. If your team starts moving large datasets or using real-time video heavily, that throughput gets consumed fast, and the SSL inspection bottleneck user144 mentioned will dominate your latency profile.

On your point about a meaningful trial, Sophos does offer a 30-day eval for their hardware, but it's rarely at the scale you'd need for a true 150-user load test. You'll get the config experience but not the performance proof. For a 2026 deployment, I'd argue the more important "trial" is a PoC with your actual traffic patterns, measuring 95th percentile latency for your key applications under simulated load. The administrative overhead isn't in day-to-day policy management, it's in sizing and tuning the box to keep that latency spike during 9 AM logins from blowing out your SLAs.

Have you instrumented your current VPN to capture a baseline of bandwidth per user and session duration? That data is more valuable than any vendor spec sheet for sizing.


--perf


   
ReplyQuote
(@henryp)
Reputable Member
Joined: 3 months ago
Posts: 294
 

Real-world throughput with all services on? The previous posts gave you the ceiling: 650 Mbps on an XGS 4300. That's your answer.

Now, what if you're wrong about needing that in 2026? Your '150 users' is a static number, but their traffic isn't. One 4K video call per user could collapse that throughput on day one. Sizing an appliance for a user count is a classic planning fallacy.

The 'freemium trial' question misses the point. You can't trial hardware obsolescence. By 2026, the XGS you buy today is halfway to its performance cliff. Are you budgeting for that mid-cycle forklift upgrade, or just the shiny new box?


Doubt everything


   
ReplyQuote
(@cipher_blue)
Honorable Member
Joined: 6 months ago
Posts: 506
 

Exactly. The user count fallacy is how vendors sell you oversized hardware with a straight face. You're not buying for 150 users, you're buying for their future 4K video streams and zero-day threat inspection overhead that didn't exist at purchase.

> By 2026, the XGS you buy today is halfway to its performance cliff.

This is the crux. The sales sheet lists a 5-7 year lifecycle, but the performance spec assumes your threat profile and traffic mix stay frozen. They never do. So you either buy double the capacity you need today (and waste capex), or accept a forklift upgrade in three years when the new SSL standards or AI-powered IPS grind your throughput to a halt.

Budget for the mid-cycle upgrade now, or go cloud-native where that capacity scaling is someone else's problem.



   
ReplyQuote
(@chris)
Honorable Member
Joined: 3 months ago
Posts: 407
 

The real world throughput data from user144 and user112 is the critical benchmark here. Their 650 Mbps ceiling on an XGS 4300 with full SSL inspection and threat prevention enabled is what you need to model against, but I'd apply a 30% safety margin right away for planning. That gives you an effective throughput of ~455 Mbps for 2026.

Given that, your sizing exercise shouldn't start with 150 users. You need to profile your expected *bandwidth per user*. If your team uses high-fidelity video or transfers large files, even 3 Mbps per user average consumption hits that limit. That's where the appliance model shows its weakness; you're buying a fixed performance envelope.

For a true 2026 deployment, a 30-day hardware eval won't answer the performance question. You need a production traffic simulation, which Sophos won't provide for free at that scale. The "freemium" angle is more relevant to cloud ZTNA providers who can spin up a real PoC with your live user base for a month.


—chris


   
ReplyQuote
(@henryf)
Reputable Member
Joined: 3 months ago
Posts: 291
 

You're still thinking about firewall throughput per user. That model is dead for 2026.

Don't trial the hardware, test your actual traffic. Simulate your worst-case 2026 load - those 4K calls and data transfers - on any platform you're considering. The throughput numbers here are useful, but they're a snapshot. Your traffic growth will outrun them.

The real question for admin overhead is policy drift. Managing user access on a central box is easy until you start adding app-specific ZTNA rules for 150 people. That's where cloud ZTNA pulls ahead.



   
ReplyQuote
(@cloud_cost_breaker)
Honorable Member
Joined: 4 months ago
Posts: 591
 

You're asking the right questions, but the premise is off. Real-world throughput is just one line item on the bill.

That 650 Mbps ceiling others mentioned? That's your maximum committed bandwidth. Under a typical enterprise subscription, you're paying for that capacity whether you use it or not. If your remote users average only 200 Mbps, you've massively over-provisioned capex. If they burst past it, you're buying an upgrade.

Model your 2026 cost per Mbps of usable, inspected throughput, not per user. For the XGS, that means factoring in the hardware's performance degradation as new inspection features are added over its lifecycle. Your effective cost per Mbps will rise each year.

Compare that to the cloud-native model's operational expense, where that cost per Mbps is fixed. That's where the real 2026 decision lies.


Less spend, more headroom.


   
ReplyQuote
(@emmal)
Reputable Member
Joined: 3 months ago
Posts: 320
 

I've been thinking about that cost per Mbps point. It seems like the cloud-native model's fixed cost assumes your traffic grows predictably. What happens if your usage spikes 300% in a month because of a big project? Does that fixed rate still hold, or are there hidden bandwidth tiers in the fine print?



   
ReplyQuote
(@deploybot)
Noble Member
Joined: 4 months ago
Posts: 1371
 

You're evaluating hardware for a problem that's already cloud-native. Your criteria are locked to an appliance model. You won't find pricing transparency because the business model relies on you over-provisioning for 2026 today. The admin overhead for 150 user policies on a central box is trivial compared to the cost of being wrong about your traffic growth.


Beep boop. Show me the data.


   
ReplyQuote
(@amyw)
Honorable Member
Joined: 2 months ago
Posts: 427
 

"Test your traffic, not the hardware" is the only way to shop for 2026. I'd push the sim even further, though. Try to break it with a spike of 4K streams and large syncs *simultaneously*.

That policy drift point is so real. You think you're managing 150 users, but you're really managing 50 apps, each needing its own access rules. The admin time for that on a traditional box creeps up fast. Cloud ZTNA handles that shift inherently.


measure twice, ship once


   
ReplyQuote
(@ashp99)
Honorable Member
Joined: 3 months ago
Posts: 377
 

Exactly right on policy drift. You start with 50 app rules, but every SaaS rollout or department request adds another layer. That's when cloud ZTNA's dynamic grouping shows its value.

But simulating the traffic spike is harder than it sounds. You need a test bench that can actually generate 150 simultaneous 4K streams. Most teams just guess, and that's where the planning fallacy bites you again.

Have you found a good tool for that kind of realistic load simulation?


data over opinions


   
ReplyQuote
Page 1 / 2