- Which Model?
- Which Subscription?
- More protection?
- Thinking Wireless?
The Sophos Rackmount Series is currently made up of 8 models. These are ideal for midsize and enterprise organizations looking for a rackmount form factor, strong throughput and enterprise-grade security. The table below highlights the main features of each model.
Options
Power over Ethernet
XGS 2100 / 2300 / 3100 / 3300 (1 x Optional Module - 4 x 1 GbE Max 60W Per Port)
XGS 4300 / 4500 (2 x Optional Module - 4 x 1 GbE Max 60W Per Port)
Storage
XGS 2100 / 2300 (128 GB SSD), XGS 3100 / 3300 (240 GB SSD)
XGS 4300 (240 GB SSD), XGS 4500 (2 x 240 GB SSD - Software RAID 1)
XGS 5500 / 6500 (2 x 480 GB SSD - Hardware RAID 1 Built In To CPU)
Redundant Power Supply
XGS 2100 / 2300 / 3100 / 3300 / 4300 (Optional External Redundant PSU)
XGS 4500 (Optional Internal Redundant PSU)
XGS 5500 / 6500 (2 x Internal Redundant PSU As Standard)
Throughput
Firewall Inspection
XGS 2100 (3 Gbps), XGS 2300 (3.5 Gbps), XGS 3100 (3.8 Gbps), XGS 3300 (40 Gbps)
XGS 4300 (75 Gbps), XGS 4500 (80 Gbps), XGS 5500 (100 Gbps), XGS 6500 (115 Gbps)
Threat Prevention
XGS 2100 (1.25 Gbps), XGS 2300 (1.4 Gbps), XGS 3100 (2 Gbps), XGS 3300 (2.7 Gbps)
XGS 4300 (4.8 Gbps), XGS 4500 (8.39 Gbps), XGS 5500 (12.39 Gbps), XGS 6500 (17.05 Gbps)
Firewall IMIX
XGS 2100 (15.9 Gbps), XGS 2300 (20 Gbps), XGS 3100 (22 Gbps), XGS 3300 (24.5 Gbps)
XGS 4300 (33 Gbps), XGS 4500 (37 Gbps), XGS 5500 (52 Gbps), XGS 6500 (60 Gbps)
Intrusion Prevention
XGS 2100 (5.8 Gbps), XGS 2300 (7 Gbps), XGS 3100 (9.82 Gbps), XGS 3300 (13.44 Gbps)
XGS 4300 (25 Gbps), XGS 4500 (35.69 Gbps), XGS 5500 (40 Gbps), XGS 6500 (48 Gbps)
NGFW
XGS 2100 (5.2 Gbps), XGS 2300 (6.3 Gbps), XGS 3100 (9 Gbps), XGS 3300 (12.5 Gbps)
XGS 4300 (23 Gbps), XGS 4500 (30 Gbps), XGS 5500 (38 Gbps), XGS 6500 (46.5 Gbps)
SSL / TLS Inspection
XGS 2100 (1.1 Gbps), XGS 2300 (1.45 Gbps), XGS 3100 (2.47 Gbps), XGS 3300 (3.13 Gbps)
XGS 4300 (8 Gbps), XGS 4500 (10.6 Gbps), XGS 5500 (13.5 Gbps), XGS 6500 (16 Gbps)
IPSec VPN Throughput
XGS 2100 (12 Gbps), XGS 2300 (15 Gbps), XGS 3100 (17 Gbps), XGS 3300 (21 Gbps)
XGS 4300 (51 Gbps), XGS 4500 (62 Gbps), XGS 5500 (78 Gbps), XGS 6500 (97 Gbps)
capacity
Interfaces
XGS 2100 / 2300 (8x 1GbE + 2 x SFP), XGS 3100 / 3300 (8 x 1GbE, 2 x SFP, 2 x SFP+)
XGS 4300 / 4500 (4 x 1GbE, 4 x 2.5GbE, 4 x SFP+)
XGS 5500 (8x 1GbE + 8 x SFP+), XGS 6500 (8 x 1GbE + 12 x SFP+)
Bypass Port Pairs
XGS 2100 / 2300 / 3100 / 3300 (1)
XGS 4300 / 4500 / 5500 / 6500 (2)
Flex Port Module Slots
XGS 2100 / 2300 / 3100 / 3300 (1)
XGS 4300 / 4500 (2) XGS 5500 / 6500 (2 + 1 High Density Module)
Optional Add-On Connectivity
All Models - SFP DSL Module VDSL2
Optional Flexi Port Modules
XGS 2100 - 4500
8 port GbE copper, 8 port GbE SFP fiber, 4 port 10GE SFP+ fiber, 4 port GbE copper bypass (2 pairs), 4 port GbE copper PoE +, 4 port GbE copper, 4 port 2.5 GbE copper PoE, 2 port GbE Fiber (LC) bypass + 4 port GbE SFP Fiber
Optional Flexi Port Modules
XGS 5500 - 6500
8 port GbE copper, 8 port GbE SFP fiber, 4 port 10 GbE SFP+ fiber, 4 port GbE copper bypass (2 pairs), 2 port 40 GbE QSFP+ fiber, 8 port 10 GbE SFP+ fiber, 2 port GbE Fiber (LC) bypass + 4 port GbE SFP Fiber, 2 port 10 GbE Fiber (LC) bypass + 4 port 10 GbE SFP+ Fiber, High-density module (NIC): 12 port GE copper + 4 port 2.5 GE copper
Max Total Port Density (inc use of modules)
XGS 2100 / 2300 (18), XGS 3100 / 3300 (20), XGS 4300 / 4500 (28)
XGS 5500 (48), XGS 6500 (68)
VPN Tunnels & Licenses
SSL VPN Concurrent Tunnels
XGS 2100 / 2300 (2500), XGS 3100 / 3300 (5000), XGS 4300 (7500)
XGS 4500 (10000), XGS 5500 / 6500 (15000)
Our Serving suggestion
Internet Speed
< 1000 Mbps
XGS 2100 / 2300
< 1500 Mbps
XGS 3100 / 3300
< 5000 Mbps
XGS 4300 / 4500
Muliti Gbps
XGS 5500 / 6500
Number of Users
< 100
< 200
< 1000
1000's
Paul's Quick Tip
So here's my quick tip for selecting a Sophos Rackmount Series firewall to meet your needs. Having sold and managed literally thousands of firewalls across the world since I started in 1999, I have noticed one thing - Our browsing and data consuming habits effect a firewall's throughput. All the tests above were performed in labs and under controlled conditions.
I would always recommend taking the slowest speed published - in this instance something like the Threat Protection value and then dividing it by three. This will give you, from our experience, the worst speed you will get under the heaviest load conditions, with full protection turned on. Make sure this speed is faster than your internet connection and you will be good to go.
Example using a Sophos XGS 2100
Threat Protection speed is 1250 Mbps, divide this by 3 which gives you 416 Mbps. This is the slowest we believe this firewall will run under the heaviest of loads. Obviously if you want to turn some of the security services off, then you will make it run faster.
Gio's Advice
Your firewall is nothing without a live and updating subscription. Viruses, Malware and network threats, change almost hourly. Purchasing a security subscription means that your firewall will always be receiving the latest threat signatures, virus protection updates and filter block lists.
The best bit is that an active security subscription also gives you free firmware updates, technical support from Sophos and hardware warranty for the duration of the subscription.
Never view a security subscription like the warranty for a car. It is not there just in case something goes wrong, it is actually needed to make sure nothing goes wrong. You are only truly being protected if your firewall is auto updating and has an active subscription.
Base License
Every Sophos XG/XGS firewall comes with a base license as standard. This gives you the basic features to get going, but no ongoing updates or support.
standard protection
The Standard Protection Bundle provides all
essential security services needed to protect against known, as well as firmware updates, hardware warranty and 24x7 support
Xstream protection
The Xstream Protection Bundle builds on the features available in Standard, but adds in protection against unknown threat, often called Zero-Day, along with advanced SD-WAN capabilities and an extended reporting period.
base
standard
xstream
24x7 Enhanced Support
24/7 support, advanced replacement hardware warranty for the term of the subscription.
Fimware Updates
Keep your Sophos patched and up to date with regular firmware updates.
Xstream SD-WAN and Networking
Includes all networking, routing, and SD-WAN capabilities including zone-based stateful firewall, NAT, VLAN, SDWAN profiles, performance-based WAN link selection and monitoring, zero-impact WAN link transitions, and Xstream FastPath acceleration of SD-WAN VPN traffic.
Secure Wireless
Built-in wireless controller for Sophos APX wireless access points. Plug-and-play access point discovery makes setup easy. Support for multiple SSIDs, hotspots, guest networks, and the diverse encryption and security standards.