First impression and feedback

Hi All,

I migrated my home box from MR7 to v17 and all good.

In my case, the IPS did not start automatically after the reboot.

The other thing is the UI is faster than v16 but the Network menu is very slow compared to the others. I have only 2 NICs and 2 VLAN.

Last thing, where is the policy test?

  • lferrara,

    I hear you load and clear!  :)  My day job exposes me to a vast amount of different vendors and security device type/class.

     

    Do not get me started on the CLI of XG.   :)

     

    -Ron

  • Ron,

    I am a Security Specialist. In my case, I follow different brand because when you perform auditing, you need to deal with different brands. I am on the community when I have free time, during the night to give my feedbacks, impressions from what I learn from the IT field. XG can work as home SOHO appliance but not in certain environment where the basic features are obvious....

    XG is still far away from this approach and for well-organized OS.

  • lferrara If you are a home user, a geek, and/or someone who works in the cyber security field this can go either way. In my case I am all three.  :)  I am not a huge fan of the cloud based e-mail systems, the free or low cost hosting providers so I host my own internet presence behind my UTM to protect my assets. So the things I still see lacking in XG in no specific order are:

    • UTM to XG migration tools
    • White/Black listing of e-mail addresses at the user level
    • SMTP Proxy (This is no where near what UTM does)
    • LetsEncypt support
    • Web categorization
    • Country Blocking
    • IPv6 Support (Comcast Internet deploys via DHCP)
      • It gets an IPv6 that only the XG can use only but nothing behind it can and when it does it does not route.
    • Portscan detection

    The above are just to name a few that I have on my laundry list of what i am watching for in XG before migrating from my trusty UTM. My biggest driver as a home user is the UTM license of only 50 IP addresses. Both UTM and XG have issues dealing with how Comcast hands out its IPv6 addresses for both a home and business class internet connections.

    -Ron

  • Hello Billy,

    I could only agree, in two sentences, a very accurate analysis of the current state.  Thank you very much for your independent analysis.

    [:D]

    Regards

    alda

  • I agree with

    XG and UTM can be used at home with no big missing features. Here the discussion and the moods are about XG that is not an Enterprise Ready Product even if it received several awards. Benchmarks use fixed tools and technique to test appliances but the real feedback is the field, the customer and threats.

  • rrosson said:

    Home User running UTM active

    Home User Following XG with a VM for testing and praying.

    [:D][:D][:D][:'(]

     

    For home users, sophos has great offerings and the clear winners are sophos UTM and sophos XG. Resellers are having trouble because they were given an impression that SG was going to be EOL when copernicus/XG was first introduced. They sold the newer XG firewalls because that made more sense and users demanded XG due to aggressive marketing. Its mostly water under the bridge but some of those resellers look like complete liars now two years after initially deploying XG.

  • Ben,

    A large portion of home users more than likely jumped to XG due to only having a CPU/MEM limit and not an IP address limit. Couple that with the popularity of IPv6 was an extra push to go to XG. I have been using UTM(SG) for quite some time with the 50 IP address limit and in doing so I have had to refrain from enabling IPv6 among a few other things. Keep in mind under UTM one IPv4 address plus one IPv6 address counts as two IP addresses against the home license. In todays home network the 50 IP limit can be exhausted rather quickly.

    Home User running UTM active

    Home User Following XG with a VM for testing and praying.

     

    -Ron

  • I did look at UTM originally but I remember there was some limitation on the number of devices I could have. I was already close at that time and now have way more devices to control (IoT etc).

    Thanks for the suggestion.

  • ch5525: did you try the sophos utm? you'll find a nice, polished and mature firewall product with UTM features. The only problem here is that parts have been neglected for a while, but overwall its still sellable and a great home product.

    ---

    Sophos UTM 9.3 Certified Engineer

  • alda said:

    maybe it's time to say goodbye

     

    I'm using the Sophos XG 16 Home license on bring my own hardware. I am appreciative for the free license provided by Sophos for home users.

    I'm going to rebuild from scratch (long story) once XG 17 is GA.  

    I am open to another option, a different product since I will be rebuilding anyway.  I know my way around XG now and it has worked just fine for me. That said, if there is something better out there then I am open to it. Please let me know what options there are and where people jump ship to I do not wish to purchase an official hardware appliance since I already have my own hardware so I would be looking for software only.

    thank you!