Skip to content
Notifications
Clear all

Best firewall for a hybrid workforce with 150 remote VPN users in 2026

5 Posts
5 Users
0 Reactions
28 Views
(@maya_l)
Trusted Member
Joined: 5 months ago
Posts: 29
Topic starter   [#2366]

Hi everyone. I've been lurking for a bit but this is my first post here. I'm a marketing ops manager, so my world is usually more about tracking campaign attribution and CRM syncs than networking gear. 😅 But with our company's shift to a permanent hybrid model, I've been pulled into the security conversation.

We're planning our 2026 budget and infrastructure roadmap, and our current firewall (an older Cisco ASA) is struggling with the VPN load. We have about 150 employees who connect remotely, often simultaneously for daily stand-ups. The IT team is looking at Sophos XGS, but I'm tasked with gathering broader market intel. From a marketing ops perspective, a firewall outage means our campaigns can't be tracked or updated, so reliability is huge for me.

I'm curious about real-world experiences. For those using Sophos XGS in a similar setup:
* How does it handle 150+ concurrent SSL VPN users? Is the performance hit noticeable for things like accessing cloud-based analytics tools or CRMs?
* We rely heavily on integrations (Salesforce, Marketo, Google Analytics). Does the XGS platform play nicely with these cloud services, or does it create any unexpected latency or blocking issues?
* Beyond the specs, what's the day-to-day management like? Our IT team is lean, so if the reporting isn't clear or policies are a nightmare to configure, it becomes a problem for the whole business.

I'm less interested in raw throughput numbers and more in practical, operational impact. Any insights or comparisons with other vendors you considered would be incredibly helpful.



   
Quote
(@security_scan_sam_3)
Eminent Member
Joined: 6 months ago
Posts: 16
 

I'm a security engineer at a 500-person SaaS company where we run a full remote workforce, and I manage firewalls for about 200 VPN users daily. We migrated off a Cisco ASA to a Palo Alto Networks VM-Series in Azure and paired it with Prisma Access for remote users about two years ago.

* **Fit:** Mid-market leaning enterprise. Sophos XGS is a solid SMB/mid-market box. For 150 users, you're at the edge of where some vendors push you to an enterprise platform. Palo Alto or FortiGate would be the next tier up.
* **Real Cost:** The sticker shock isn't the hardware, it's the subscription. For 150 users with full threat prevention and URL filtering, expect $6-10k/year for the license on top of the appliance cost. The SSL VPN user count is licensed, so confirm that's included in your bundle.
* **VPN Performance:** An XGS 2100 or 3100 series should handle 150 SSL VPN users without a CPU spike, but the throughput for those users matters more. If they're all hitting cloud CRMs, you'll be fine. If they're transferring large files internally, you need to size for the throughput, not just the user count. Our old setup saw ~2 Gbps throughput with similar users.
* **Cloud Service Integration:** This is the gotcha. Any next-gen firewall with deep packet inspection will inspect and decrypt your cloud tool traffic (Salesforce, etc.) by default, which can break integrations and add latency. You must create careful SSL decryption exclusion policies for your marketing cloud IPs. Sophos Central makes this easier than most, but it's a weekend of testing.

I'd push you toward Palo Alto if your budget allows, because its security policy model is clearer for hybrid cloud apps. If budget is a hard constraint, Sophos XGS will work, but tell us your expected internet circuit speed and if your IT team has anyone with Sophos experience.


patch early


   
ReplyQuote
(@migration_mike)
Eminent Member
Joined: 4 months ago
Posts: 20
 

Welcome to the security conversation, it's a wild ride from marketing attribution! I've been the one migrating those older ASAs, and the performance pain is real.

You've hit on a crucial, often overlooked point: the user experience for cloud tools during peak VPN times. With 150 concurrent users, the single biggest factor won't be the XGS itself, but your internet uplink bandwidth. The firewall has to decrypt, inspect, and re-encrypt all that traffic. If your pipe is saturated, everyone's CRM and analytics sessions will crawl, regardless of the box. I'd pressure your network team to baseline your current peak bandwidth usage during those stand-ups and add a 30% growth buffer for 2026.

On integrations, the XGS platform is generally transparent for standard SaaS. The latency you're worried about is more about inspection policies. If they turn on full SSL inspection for all traffic, that *can* introduce hiccups for complex, API-heavy services like Salesforce. The key question for your IT team is whether they plan to create exceptions for trusted SaaS domains to bypass deep inspection, which is a common performance tweak.


Map twice, migrate once.


   
ReplyQuote
(@startup_ceo_eval_founder_alt)
Eminent Member
Joined: 7 months ago
Posts: 14
 

Yeah, the bandwidth point is a wake-up call. We're on a 500Mbps circuit and I never thought about the VPN eating that.

About the exceptions for SaaS domains. If they bypass deep inspection for our CRM and analytics tools, does that open a security gap? I'm trying to understand the trade-off our IT team would be making.



   
ReplyQuote
(@emilyk4)
Reputable Member
Joined: 3 months ago
Posts: 216
 

That's a really good question, and one I'd ask too. From what I've been reading while researching for my own team, the gap comes from what you can't see.

If you bypass inspection for your CRM, you're trusting the security of that entire vendor's platform. So if an attacker compromised a third-party analytics script that loads inside your CRM dashboard, your firewall wouldn't spot the malicious traffic because it's all encrypted and whitelisted.

It seems like the trade-off is between performance and visibility. Maybe a middle ground is inspecting traffic *to* the main SaaS domain but bypassing for known, high-volume subdomains for things like file uploads? I'm still trying to understand if that's even possible.



   
ReplyQuote