Hey folks, been setting up a secure remote workflow for a small engineering team and thought I'd share our recent hardware evaluation. We were deciding between the Sophos XGS 136 (Appliances are nice) and the Netgate 8200 running pfSense+.
The main requirement was rock-solid site-to-site VPN for about 30 users, many of whom need to work with large CAD files over the wire. Latency and stability were the top priorities, not just raw throughput. We also needed solid traffic shaping to ensure Zoom calls weren't ruined by a massive file sync.
Here's what we found:
**Sophos XGS 136**
* **VPN Performance:** IPsec throughput is great, and the Sophos Connect client is surprisingly easy for the less tech-savvy staff. SSL VPN performance was also solid for road warriors.
* **Traffic Shaping:** The "QoS" policies are intuitive. We could easily guarantee bandwidth for RDP/VoIP and limit bulk transfers without deep diving into custom rules.
* **The Catch:** The licensing. To get the full threat protection features (which we wanted for web filtering), you're on a yearly subscription. The hardware cost is just the beginning.
* **Config Snippet (Traffic Rule):**
```bash
# Example of a simple Sophos traffic rule prioritizing Zoom
Rule Name: Priority-Zoom
Service: Zoom-Cloud-Meetings
Action: Accept with QoS
QoS Policy: High-Priority (70% bandwidth guarantee)
```
**Netgate 8200**
* **VPN Performance:** Raw IPsec performance was comparable, maybe a tad better on pure routing. OpenVPN performance felt a bit more tunable for edge cases.
* **Traffic Shaping:** This is where pfSense's `limiter` and `shaper` rules shine for granular control, but the learning curve is steeper. The GUI wizard helps, but custom tweaks are a CLI affair.
* **The Catch:** You're the admin. No support hand-holding unless you pay for it. The 8200 hardware is robust, and the pfSense+ software subscription is cheaper than Sophos's full suite, but you trade off some out-of-the-box polish.
**Our Verdict:** We went with the **Sophos XGS**. For a small team without a dedicated network engineer, the unified management and easier troubleshooting won out. The subscription cost stings, but the time saved in configuration and support was worth it for us. The Netgate box is a beast and probably more "fun" to tinker with, but we needed a set-and-forget appliance.
Anyone else run a similar setup? Would love to hear how you handle large file transfers over VPN without killing other real-time apps. Any specific queue or limiter settings on pfSense you'd recommend if we revisit this?