Skip to content
Notifications
Clear all

Migrating from pfSense to Sophos XGS for a 40-user law firm - lessons learned

2 Posts
2 Users
0 Reactions
4 Views
(@kellyd)
Trusted Member
Joined: 1 week ago
Posts: 40
Topic starter   [#3854]

Hey everyone, I’ve been lurking here for a bit but this is my first real post, so go easy on me! 😅 I’m the de facto IT guy at my firm (we’re a 40-person law office, mix of onsite and remote), and we just finished migrating our main firewall from a pretty beefy pfSense box to a Sophos XGS 126. Man, what a journey.

I was super comfortable with pfSense after like five years, but the partners wanted something with more integrated “support” and features that looked easier for someone else to manage if I ever got hit by a bus (their words, not mine!). We looked at Fortinet and WatchGuard too, but Sophos kept coming up for SMBs. I have so many thoughts and comparisons swirling in my head, I just need to get them out and see if my experience matches yours.

The biggest thing for me was the whole mindset shift. pfSense feels like a super powerful toolbox where you build everything yourself. Sophos XGS feels more like a polished appliance where a lot is pre-configured, but you have to learn *their* way of doing things. Like, the concept of “Services” for firewall rules instead of just ports/hosts tripped me up at first, but now I kinda see the logic for repeatable policies.

Our main drivers were the built-in VPN (we’re using the SSL VPN client, which is way smoother for the non-techy attorneys than OpenVPN), the integrated web filtering (we needed to lock down certain categories for compliance), and the centralized reporting. Getting the site-to-site VPNs up with our cloud provider was actually simpler than on pfSense, once I figured out where all the settings lived.

Some random lessons learned the hard way:
* The migration isn’t a “migration” in the traditional sense. You can’t import pfSense configs. I had to build a new rule set from scratch, which was actually a good chance to clean up years of legacy rules, but it took a solid weekend of planning.
* The Web Application Firewall (WAF) module for our external-facing client portal was a big selling point, but tuning it to not block legitimate traffic was a project in itself. Way different from mod security on pfSense.
* Support. We have the basic support, and actually calling them for a NAT issue was… an experience. Better than no support, but you really have to advocate for yourself. The online knowledge base is pretty deep though.
* Licensing. This is still fuzzy to me. Having the firewall, web filter, and support all on one license feels simpler, but also more “all-or-nothing” compared to the à la carte world of pfSense packages.

I’m still in that phase where I’m wondering if certain things are just better in Sophos, or if I’m missing the pfSense way. For those of you who made a similar jump, how did you handle the change in workflow? And for the long-time Sophos admins, what are the hidden “gotchas” or awesome features I should be looking into next, maybe around the automated threat response or the SD-WAN features? I’m all about automating workflows where possible.



   
Quote
(@jasonb)
Estimable Member
Joined: 1 week ago
Posts: 115
 

Yeah, that "toolbox vs appliance" feeling hits hard. It's like switching from a manual transmission to an automatic - you gain some convenience but you really miss the direct control sometimes.

The Services thing for firewall rules is a perfect example. Once you get used to it, especially in a business setting, it makes managing things like "Zoom" or "Microsoft 365" way cleaner than tracking a dozen IPs and ports. But the initial learning curve is real.

How'd your cutover weekend go? Any surprises when everyone logged in Monday morning?


Let's build better workflows.


   
ReplyQuote