Management for MSPs

Hi,

nice to see this new feature. I hoped that the CM for firewalls will made the CFM und SFM obsolete.

But as the CM resides on the customers central account, you need to login in every customers through Partner Central to manages multiple firewalls as a MSP.

Before these where to seperate things:

- Assignment to Central for hearbeat

- Assignment to a Management SFM/SFM

 

Because SFM/SFM  not developed further, I don't know if this is an option for MSPs.

  • for some MSPs, yes it will be a viable option - but that's not the goal this first release of firewall management in Central is targeted at. Later this year, we'll add group management of firewalls, making it a much attractive replacement for CFM and SFM, but it will still only be available in the customer portal. So it will be suitable for MSPs that are fully managing their customer environments, or partners that are ok with managing firewalls one customer at a time (sso from partner dashboard into customer dashboard, then manage firewall policies per customer)

    For other Sophos products, we're already launching global policies, that can be managed through the partner dashboard, and pushed to customer accounts. We will integrate firewall management into a similar flow, once group management of firewalls is launched. This will allow partners to manage policies directly from the partner dashboard, and should be a suitable full replacement for SFM/CFM in all cases.

  • In reply to AlanT:

    So as I understand it is the current status that the SFM is not being replaced by the management of firewalls in Sophos Central?
    But you're planning the management of firewalls with in a groupwise manner out of central?

    The thing that we, as MSP, mostly need is an overview if the deployed firewalls an their live and historical state.
    In the SUM this was nice designed with live CPU, bandwidth and so on.

    So for now to get an advantage of the new feature in central I could create a new Central account and add the firewalls I have to fully manage?
    But now get lose of the monitoring of SFM/CFM.

  • In reply to Mr.Roboto:

    Our plan is definitely to replace SFM/CFM with Sophos Central, but it will take more than one step to get all the features needed to do that. In the mean time, it's expected that only MSPs with very light and specific management needs, would find Sophos Central adequate. The dashboard update coming in the next update will add CPU, memory, synsec, IPS, web usage, and ATP stats on the dashboard and per firewall, if that also helps. After the upcoming release, we'll add backup management, firmware management, and light-touch deployment, which will also make it easier for MSPs to monitor and manage firewall, over the next 2-3 months. Following that, we'll be building towards the next big update to central management, which will arrive later in the year, and be built on XG V18 capabilities. This is expected to be a more fully featured replacement for SFM and CFM. 

  • In reply to AlanT:

    Hi Alan,

    thank you this statement. I wish you would involve us more, because we must set our own strategies to handle things like management etc. and with this statement I can plan things for now.

    Is there any preferred method for setting up a Central account for MSPs to manage the customers firewalls?
    For example create a new Central customer for only managing the XGs or simply and them to our normal and existing company account?
    Or is the "Enterprise"-mode in Central a way to mange this?

    I would be glad about a short note.

  • In reply to Mr.Roboto:

    I want to give you a positive feedback from the Central FW management =:)

    To UI looks nice!! 

  • In reply to AlanT:

    Hi,

    at the moment I'am migrating our firewall management to the Central Management. This works fine, okay at the moment without the possibility to apply groupwise policys, but for the moment it works. you can't always want too much. ;)

    but now I'am at a point where my brain is smokin'.
    When I've got a customer, a managed-service customer:
    1. could I work with the "enterprises" function to mange them if they've got XG and Endpoint/Hearbeat
    2. What to do with a customer who has an MSP owned XG but uses selfowned endpoint-licences? Should I create a own Central-account for these customer and link it to my Central-Partner?

  • In reply to Mr.Roboto:

    Mr.Roboto

    Hi,

    at the moment I'am migrating our firewall management to the Central Management. This works fine, okay at the moment without the possibility to apply groupwise policys, but for the moment it works. you can't always want too much. ;)

    but now I'am at a point where my brain is smokin'.
    When I've got a customer, a managed-service customer:
    1. could I work with the "enterprises" function to mange them if they've got XG and Endpoint/Hearbeat
    2. What to do with a customer who has an MSP owned XG but uses selfowned endpoint-licences? Should I create a own Central-account for these customer and link it to my Central-Partner?

     

     

    Someone out there? :)

  • In reply to Mr.Roboto:

    You should build up one Central Instance per Customer. 

    This instance should have all Sophos Licenses in it (included all his XG Appliances).

    We highly recommend to not mix customers in one Sophos Central Admin Platform. 

    In Case you have a MSP XG Customer but with own Endpoint Licenses, your XG should be included in the Customer Central Instance and his Central Instance should be open for Partner Management. This is kinda a rare case. 

  • In reply to AlanT:

    Hello, alan,
    are there any news on the topic of management XG firewalls for MSPs? is it still worth investing in a firewall manager at this point?