Sophos UTM Retirement / EOL announced

Finally, Sophos announced the EOL of UTM. Interestingly, the EOL does not apply to Sophos UTM AWS....



Moved to Lifecylce and Migration Forum
[edited by: Raphael Alganes at 3:02 AM (GMT -7) on 23 Jun 2023]
Parents
  • Yes this is sad, I concur that the UTM, in what concerns the Sophos portfolio, is far superior, far more professional. I've tested yesterday a quick manual in place migration with XG.. It's okay'ish although far from the UTM if you ask me -- and when I saw that changing parameters on a parent interface would completely removed both, underneath VLANs as well as IPsec tunnels configured upon them, I've been thorn to say the least -- my AP50 not supported and so on... hence nothing for me I guess.

    I cannot think other than that Sophos actually lost the main "Astaro developers" of the UTM branch long ago -- which is perhaps why it was a bit dormant on new features etc. In the end it's a sad story because let's be honest, Sophos kills an incredibly good product, loved by the vast majority.

    Let's hope for the open source alternative.

  • You are so right. We have been using the product since the days of Astaro and really loved it. The XG line can't compare in any way. It is so much more complicated. We already have some of them in remote offices and have to replace our HQ UTM this year with XG. So sad...

  • ^^Why replace them with XG when there's other options available?

  • Hi Jay Jay,

    can you name some?

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • The other free alternatives --for home use-- right now would be: 

    1) Using the Zenarmor plugin with OPNsense/PfSense. *BUT* the free and paid home editions do not support HTTPS inspection for all ports. Full DPI is only (going to be) available in the business license.

    2)The OpenAppID addon for Snort used in pfSense. This turns PfSense into a layer 7 application layer firewall.

    3) Untangle NG Firewall Free v16. There is a free version available but it's difficult to find the download and I could not find a feature comparison that included the free version.

    If you can think of any other free alternatives let us know.

    Of course with paid versions you always have the well known players: Fortinet, SonicWall, Palo Alto, and others....

  • Untangle does not work without uplink to the vendor cloud. so not useable for me, home or busines, doesn't matter.

    i dont like vendors that call home and for me it's a security risk in an firewall enviroment.

     

  • By the way: did anyone ask sophos how much money they want for the UTM 9 ? Or if it is for sale ?

  • Untangle does not work without uplink to the vendor cloud. so not useable for me, home or busines, doesn't matter.

    i dont like vendors that call home and for me it's a security risk in an firewall enviroment.

    Almost all NGFWs call home, including Sophos, for AV pattern updates and to check for firmware. The home version of SFOS does not offer Heartbeat or Application synchronization so no need to worry. Disable the Sophos Assistant, un-register the firewall with Sophos Central, disable automatic hotfix installation, and telemetry and it should not be calling home.

Reply
  • Untangle does not work without uplink to the vendor cloud. so not useable for me, home or busines, doesn't matter.

    i dont like vendors that call home and for me it's a security risk in an firewall enviroment.

    Almost all NGFWs call home, including Sophos, for AV pattern updates and to check for firmware. The home version of SFOS does not offer Heartbeat or Application synchronization so no need to worry. Disable the Sophos Assistant, un-register the firewall with Sophos Central, disable automatic hotfix installation, and telemetry and it should not be calling home.

Children