This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Firewall - Roadmap?


is there a roadmap for the XGs for the next major versions and the planned functions?


This thread was automatically locked due to age.
Parents Reply Children
  • Hey Paul,

    V17.5.b is supposed to be due this week.


    V18.5.x - e3-1225v5 6gb ram with 4 ports - 20w. 
    If a post solves your question use the 'This helped me' link.
  • support says v17.5 is scheduled for November

  • Then what are the changes in 17.5? In the last roadmap I have seen there were 17.2, 17.3 and 18, no 17.5.

    With best regards,


    Sophos Certified UTM Architect

  • Hi Steppenwolf!

    17.5 beta should be already available in October.

    Quick overview of the key new features in v17.5:

    • Sophos Central Management of XG Firewall with new features for backup and firmware management, as well as a new zero-touch deployment option
    • Synchronized Security features including Lateral Movement Protection to prevent threats from spreading on the same network segment and Synchronized User ID to eliminate the need to integrate with Active Directory for user identification
    • Wireless APX access point support offers support for the new Wave 2 access points, providing faster connectivity and added scalability (and will come shortly following the main v17.5 release in MR1)
    • Education features such as policy-based control over SafeSearch and YouTube restrictions, block-page overrides, and Chromebook authentication support
    • Email features with Sender Policy Framework (SPF) anti-spoofing protection and a new MTA based on Exim which closes a couple of top requested feature differences with SG UTM
    • IPS protection is enhanced with the Cisco Talos IPS pattern library and more granular categories
    • Management enhancements including enhanced firewall rule grouping with automatic group assignment and a custom column selection for the log viewer
    • VPN and SD-WAN failover and failback including new IPSec failover and failback controls and SD-WAN link failback options
    • Client authentication gets a major update with a variety of new enhancements, such as per-machine deployment, a logout option, support for wake from sleep, and MAC address sharing
    • Airgap support enables XG Firewall to be updated via USB in situations where XG Firewall can’t get updates automatically via an internet connection due to an “airgap” or physical isolation (coming shortly following the main v17.5 release in a MR)
    • Sophos Connect IPSec VPN client, free for all XG Firewall customers, that makes remote VPN easy for end users (not part of v17.5 but being made available at the same time for early access)
  • Hi,

    were is v17.5.b hiding?


    V18.5.x - e3-1225v5 6gb ram with 4 ports - 20w. 
    If a post solves your question use the 'This helped me' link.
  • Never heard of 17.5.b unless someone in marketing invented the term.

    In short, the originally planned 17.2 and 17.3 with lists of features have been replaced with 17.5 and the list of features above.

    Also see where they mention "We are expecting the beta to be available in the coming days".


  • v17.5.b is the beta version of v17.5 to give it a name.


    V18.5.x - e3-1225v5 6gb ram with 4 ports - 20w. 
    If a post solves your question use the 'This helped me' link.
  • Sorry to hear the UTM/EXIM is the point of comparison for mail filtering, since UTM/EXIM:

    • is unable to examine the From header (the one that the user sees), so it cannot block forged values in this header (one common complaint is the inability to block From domain=receipient doman)
    • is unable to do filtering based on server name (whether Reverse DNS, Forward-Confirmed Reverse DNS, or Forward-confirmed DNS of HELO/EHLO name),
    • cannot check or enforce sender DMARC policy checking,
    • cannot export a message log into CSV, Excel, or any other usable format.

    Email filtering seems like the weakest component in UTM, so if XG is reaching up to meet UTM, it is reaching up to a pretty low goal.

  • Hello

    Is it still the same with EXIM version 4.91 ? Those first three items are deal killers for me.  I read that DKIM can be implemented on EXIM by calling external services.  Same for anti-spam et.c.  I do not know yet how EXIM was implement on XG.  Possibly it was done by Sophos already ...

    Paul Jr 

  • No one has rebuked me yet...  

    I would be hapoy to be wrong, or to be the motivation to implement features that should have been in place 10 years sgo.