Looking at a firewall refresh for a ~50-store chain. Need rock-solid PCI compliance and solid VPN for remote POS support. Narrowed it down to Sophos XGS and WatchGuard M370.
Any real-world experience on these for retail?
* How’s the centralized management for multiple sites?
* Any gotchas with the built-in PCI compliance reports?
* We're heavy on email marketing, so integration with our CRM for security logs would be a plus.
Ran a trial of Sophos Central and liked the dashboard, but deployment at scale is the real test. Budget is a factor, but compliance is non-negotiable.
Trial first, ask later.
If you liked Sophos Central, its multi-site management is where that really pays off. I manage about 30 XGS boxes for a client with a similar distributed setup. The template-based configuration means you can push a standardized, PCI-compliant config to all stores and still tweak individual site settings without breaking the mold. The zero-touch provisioning for new sites is a huge time saver.
For your PCI reports, the built-in ones are a good start but they're a checkbox. You'll need to supplement them. The real integration work comes from pulling those security logs out via their API. I've set up a webhook from Sophos Central to pipe firewall and event logs into a CRM like HubSpot for a marketing team. It takes some custom scripting but it's reliable once built. WatchGuard's reporting felt more rigid to me, harder to get that data flowing elsewhere automatically.
The VPN performance on the XGS for POS traffic has been solid, but test the client on the actual remote hardware you'll use. I had one quirky driver issue with an older handheld scanner that took a week to pin down. Budget wise, don't forget to factor in the central management licensing for all those units, that's where the scale cost can sneak up.
api first
Good point about the centralized licensing being a cost factor. The per-device fee for Sophos Central adds up fast across 50 sites. You can offset it some by managing the initial config push centrally, then shifting sites to local management for day-to-day, but you lose real-time visibility.
On the webhook-to-CRM setup, which API endpoints did you find most useful for marketing? Just the high-level event summaries, or were you able to filter down to things like blocked outbound connection attempts that might indicate a compromised email tool?
And absolutely second the advice on testing the VPN client with the actual hardware. We once rolled out 20 sites only to find a conflict with a specific receipt printer's software. That was a painful rollback.
Spreadsheets > marketing slides.
That split approach of managing initial config centrally then dropping to local management introduces a real blind spot. The moment you lose that real-time visibility, you're no longer monitoring for compliance, you're just hoping the config sticks. For PCI, that's a significant audit finding waiting to happen.
On the VPN testing point, your receipt printer story is the perfect cautionary tale. It highlights why you need a full staging environment with all site-specific hardware, not just the firewall and a generic client. A conflict like that is a business-stopper.
Keep it constructive.