Fortinet FortiGate vs Sophos XG comparison

Cancel
You must select at least 2 products to compare!
Fortinet Logo
123,063 views|89,961 comparisons
90% willing to recommend
Sophos Logo
60,004 views|43,112 comparisons
93% willing to recommend
Comparison Buyer's Guide
Executive Summary
Updated on Sep 13, 2023

We performed a comparison between Fortinet FortiGate and Sophos XG based on our users’ reviews in five categories. After reading all of the collected data, you can find our conclusion below.

  • Ease of Deployment: Users of both Fortinet FortiGate and Sophos XG agreed that deployment was quick and straightforward.
  • Features: Reviewers of Fortinet FortiGate felt the software has excellent stability, great features, and an excellent firewall and VPN solution. Sophos XG is regarded as a complete firewall solution that is suitable for small and mid-sized businesses. Users say the VPN is valuable for remote workers.
  • Room for Improvement: FortiGate users said the solution was hard to integrate with non-Fortinet solutions, and a few remarked that the SD-WAN could be improved. Sophos XG's interface earned mixed reviews, with many feeling it was overly complex. Others said that the reporting features also need some work. 
  • Pricing: Whereas users of Fortinet FortiGate felt that the software was costly, especially since each feature needs a separate license, reviewers of Sophos XG felt the software was reasonably priced, and a few remarked on the benefit of the flexible pricing offered.
  • Service and Support: Fortinet FortiGate users mentioned that the software needs better and quicker support. In comparison, Sophos XG users had mixed reviews on technical support. Some were very happy with the level of support, while others felt there was a significant delay in response time.
  • ROI: Users of both Fortinet FortiGate and Sophos XG saw a great ROI after implementing the software.

Comparison Results: Fortinet FortiGate and Sophos XG had similar user ratings regarding ease of deployment, service and support, and ROI. In terms of features, each software has its pros and cons. Fortinet FortiGate offers some great features, but it is a little more complex and needs better reporting. Sophos XG provides a stable, complete firewall solution, but it fails to integrate well with other products, and the SD-WAN needs improvement. Sophos XG was the better option for pricing, as they offer flexible pricing based on region.

To learn more, read our detailed Fortinet FortiGate vs. Sophos XG Report (Updated: March 2024).
768,857 professionals have used our research since 2012.
Q&A Highlights
Question: Which solution do you prefer: Fortinet FortiGate or Sophos XG?
Answer: I evaluated both for a multi-site environment, and eventually chose FortiGate, based on the centralized management and reputation of Fortinet. Eventually we plan to move to FortiSwitches and maybe even Fortinet access points, so it makes sense to use Fortimanager to manage all the Fortinet devices. Sophos also have a good solution, but reading reviews of the XG I got the impression they were not as reliable or had as many features as Fortigate.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"​Easy to implement, and it is also reliable.​""The most valuable feature is the policy routing and application control.""It's quite comfortable to handle the FortiGate firewall.""You can create multiple Virtual Domains (VDOMs), which are treated as separate firewall instances.""It's a user-friendly firewall. Most of the tasks are very simple. It's simple to configure and troubleshoot this firewall.""All of the features of Fortinet FortiGate are useful and the security protection is good.""This version is stable. I don't have any issues with this solution, in our environment, it works well.""From the firewall perspective, the rules and policies are very sufficient and easy to use."

More Fortinet FortiGate Pros →

"Sophos XG Firewall is very usable, very easy to install, and very user friendly.""The tool's most valuable feature is threat protection and DLP features. So far, basic DLP features like content protection and blocking. Furthermore, for remote users, features such as back filtering and application control are available, allowing for command and control from our side. It is very easy to understand policy applications.""I like their firewall and the intrusion detection feature""The SL VPNs are the most valuable feature. I have a lot of systems out of the head office that need to connect to the local networks, and they all connect wirelessly via the Sophos VPN client.""The filtering is very easy to do. You can segment and create profiles for usage very easily.""The solution is more cost-effective than FortiGate, Cisco and Palo Alto, which have very expensive licenses.""This is a very stable solution.""The solution offers a good firewall endpoint and email encryption."

More Sophos XG Pros →

Cons
"Due to its higher cost, Fortinet FortiGate can lead to increased operational expenses.""I would like to see more advanced developments of a wireless controller in the future.""The integration with third-party tools may be something that they should work on.""Fortinet needs more memory to save the log files. We need it to save the logs on the hardware and not in the cloud. I know this feature is available in FortiCloud, but if we need this log locally, it is not available.""The solution needs to improve its integration with cybersecurity.""There is a lot of improvement needed with SSL-VPN.""The ease of use could be improved.""Lacks training for new features."

More Fortinet FortiGate Cons →

"The management console could be improved and the solution lacks good technical support.""They need to allow their solution to integrate with other products and not just other Sophos solutions.""It is already secure but it could be better in terms of other breaches that may occur.""Scalability it is a bit limited. We did a sizing exercise before the purchase. But that was just to fit our current needs. There was no room for having an option to upgrade the device. The only option that we have if we are grow in the near future, is to go for another model with higher specs, which is actually more expensive. In other words it doesn't have that modularity .""They need to do more quality checks before they release firmware upgrades. Currently, a few Cyberoam firewall customers are facing some issues while upgrading the Cyberoam firmware to Sophos. After the new firmware is installed, they are seeing some performance issues, which require some bug fixes. The performance is fine after getting the required support. Customers who are already using Sophos hardware are quite satisfied with this solution. Their support should also be improved. We are facing difficulties getting support on time through email or phone.""The number of ports, especially on the entry-level appliances, should be increased.""I would want the level of integration to have another device on your network that is also reliable.""We are not very happy with the customer support they provide — it's quite slow."

More Sophos XG Cons →

Pricing and Cost Advice
  • "Fortinet has one or two license types, and the VPN numbers are only limited by the hardware chassis make."
  • "These boxes are not that expensive compared to what they can do, their functionality, and the reporting you receive. Fortinet licensing is straightforward and less confusing compared to Cisco."
  • "Go for long term pricing negotiated at the time of purchase."
  • "Work through partners for the best pricing."
  • "The value is the capability of having multiple services with one unique license, not having the limitation per user licensing schema, like other vendors."
  • "Easy to understand licensing requirements."
  • "​We saved a bundle by not needing all the past appliances from an NGFW.​"
  • "The cost is too high... They have to focus on more features with less cost for the customer. If you see the market, where it's going, there are a lot of players offering more features for less cost."
  • More Fortinet FortiGate Pricing and Cost Advice →

  • "For licensing the XG 210, we paid approximately $3000 for three years. There are no additional fees on top of this."
  • "It's a suitable price and license."
  • "We are paying about $1,500 yearly for the Enterprise Plus. As far as I know, there aren't costs above this standard fee."
  • "The Sophos pricing, in general, is better than SonicWall, Fortinet, WatchGuard, or anybody else."
  • "We paid for our licensing for three years, upfront, and there are no costs in addition to the standard fees."
  • "The price is cheaper than that of some competing vendors."
  • "The pricing is flexible. Sophos looks at a country's economy and offers flexible pricing. This is how they have managed to penetrate the market."
  • "It's approximately $6,000 for each device."
  • More Sophos XG Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Firewalls solutions are best for your needs.
    768,857 professionals have used our research since 2012.
    Comparison Review
    Anonymous User
    I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main hang-ups will be with the VIP/load balancing and SSL. For some reason that completely escapes me, both of these vendors make getting valid certificates onto their boxes unnecessarily difficult -- the Fortinet appliances more so than the Sophos UTM appliances. At one point a Fortinet engineer had to write an entire manual on how to get an SSL certificate uploaded successfully on the 4.x firmware Sophos: The one feature that is missing (and this makes some amount of sense) from the Sophos appliance is BITS caching for updates. Other than that, Sophos offers a full replacement for TMG on UTM9. The XG platform also offers a replacement for the TMG; however, some of the rumblings about upcoming releases suggests that Sophos is going to give XG the Apple iOS treatment and "streamline" the interface...potentially cutting out/hiding some functionality. On the effectiveness of the NGFW, Sophos is mostly good but has a few issues blocking all pieces of an application. For instance, we had to build custom blocking rules for OpenVPN (the vpn was being used to bypass the content filter) because the default Application Control wasn't effectively blocking the application. Fortinet: If it… Read more →
    Answers from the Community
    Sherif Anter
    Harish (Kumar) - PeerSpot reviewerHarish (Kumar)
    Real User

    Go with Sophos XG or if you have tight budget and technical expertise then can move with pFsense.

    Dr. Ravi_Sharma - PeerSpot reviewerDr. Ravi_Sharma
    Real User

    Dear Sharif.


    For 150 users any firewall will work perfectly. You can choose as per your convenience, availability, price, and better implementation partner in your region. Keep a bigger box at the central location and configure SD-WAN. SOPHOS has by default SD WAN. Make sure you have secure access to the cloud and all endpoints should have endpoint protection else only firewall will not help.

    Most of the cloud service providers work on any-any rule because their responsibility is network uptime and availability. Security of your setup is your responsibility.

    Manageability is better in Fortinet however features are better in SOPHOS. License bundle & ATP functions are are good in SOPHOS. Support response is good in SOPHOS but you will find less tickets in FORTINET once it is implemented as per your setup.

    Overall both are good for your setup. You can choose as per convenience.


    Hope this will help.. Greetings .. Ravi

    Yafar Khan - PeerSpot reviewerYafar Khan
    Real User

    In my opinion, the first point of strength is the support, and FortiGate is doing a great job in terms of support. It has numerous reference guides for configuration. The other advantage is ease of management in both the UI and CLI levels. You can use FortiGate modules to protect against web and virus attacks.

    Andre Boettcher  - PeerSpot reviewerAndre Boettcher
    MSP

    Hello Sharif,  


    I prefer FortiGate SDWAN Devices (FortiGate) even though we also deliver Sophos to our clients. 


    The decentralized FortiGate devices work as firewalls with an excellent security ecosystem. FortiGate and most other items work as Hardware units or on virtual machines.



    As a Telco company we have a lot of companies working in different industries with various requirements. We can support them all with FortiGate.
    Our customers prefer the security features, the stable ecosystem for life cycle management, for device/user/policy management, thread detection & prevention, intrusion prevention, sandboxing, ... the low operation effort to build a stable company network that supports the need of any customer size.

    In our business, we also like that the architecture of a company network can be easily changed if the customer requirements change. From single-line sites to Data Centers with high availability and Cloud integration FortiGate can be used in any design.

    The different security features that can be added by the license are powerful and integrated into the management dashboard. Updates of protection mechanisms against new threads happen automatically as soon as a new protection mechanism is available when new threads occur. The security team at Fortinet is excellent.

    Greetings
    Andre

    Cesar Reza - PeerSpot reviewerCesar Reza
    Reseller

    Hi, XG is EOL the new series is XGS, both are excellent equipment but I prefer Fortigate, why ??? DHCP slection, leader SD-WAN, many IPSEC dynamics is possible on SOPHOS but is limit the are conflicts with many IP's dynamics you need to use DDNS, SSL tunnel for remote clients, VRF, advanced routing with OSPF and BGP ("as path"). Greetings  









    Questions from the Community
    Top Answer: When you compare these firewalls you can identify them with different features, advantages, practices and usage at large. In my opinion, Fortinet would be the best option and l use Fortinet too.… more »
    Top Answer:From my experience regarding both the Sophos and FortiGate firewalls, I personally would rather use FortiGate. I know the firewalls change every 5 to 7 years as stated but you really do need to… more »
    Top Answer:As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite good. The most valuable features for me are their web and email filtering. I would… more »
    Top Answer:Palo Alto Networks NG Firewalls have both great features and performance. I like that Palo Alto has regular threat signatures and updates. I also appreciate that I can just import addresses and URL… more »
    Top Answer:Hi Arvind P ,  The Sophos XG firewall has a number of models right from XG86 to XG135w under the 1U Desktop Form Factor. The Sophos XG appliance that offers a direct competition to the Fortigate 80F… more »
    Top Answer:The Sophos UTM is a UTM and Sophos XG is the NGFW. First, you must know about the difference between a UTM and NGFW. They can not be compared with each other because the price, license, firewall… more »
    Ranking
    2nd
    out of 59 in Firewalls
    Views
    123,063
    Comparisons
    89,961
    Reviews
    48
    Average Words per Review
    661
    Rating
    8.4
    7th
    out of 59 in Firewalls
    Views
    60,004
    Comparisons
    43,112
    Reviews
    22
    Average Words per Review
    494
    Rating
    8.3
    Comparisons
    Also Known As
    FortiGate 60b, FortiGate 60c, FortiGate 80c, FortiGate 50b, FortiGate 200b, FortiGate 110c, FortiGate
    Learn More
    Overview

    Fortinet FortiGate enhances network security, prevents unauthorized access, and offers robust firewall protection. Valued features include advanced threat protection, reliable performance, and a user-friendly interface. It improves efficiency, streamlines processes, and boosts collaboration, providing valuable insights for informed decision-making and growth.

    Sophos XG Firewall is a complete firewall solution that provides all the real-time security and insights you need to protect your network from ransomware and advanced threats. Sophos XG Firewall provides visibility into suspicious users, unknown and unwanted apps, encrypted traffic, and other threats. With its advanced artificial intelligence capabilities, Sophos XG Firewall immediately identifies potential risks and intrusions on web servers and networks.

    Sophos XG Firewall Features

    Sophos XG Firewall offers a wide range of security features, including:

    • Application control: Prevent widespread infections with XG’s Security Heartbeat. XG Firewall automatically identifies the source of an infection on a network and automatically prevents it from accessing other network resources.

    • Synchronized user ID: Eliminate the need for client or server authentication agents by sharing user identification between the endpoint and the firewall through Security Heartbeat.

    • Centralized management: Easily manage all activities with Sophos Central. The XG cloud management platform allows users to easily set up, manage, and monitor XG firewalls along with other Sophos products. Some of Sophos Central’s features include alerting, backup management, one-click firmware updates, and rapid deployments of new firewalls.

    • Lateral movement protection: Automatically isolate compromised systems at every point in the network to stop attacks dead in their tracks.

    • Network protection: Protect networks from attacks and threats while providing secure network access.

    • Web protection: Gain clear visibility and control over all users’ web and application activity.

    • Web server protection: Solidify web servers and applications against hacking attacks while providing secure web access.

    • Email protection: Consolidate email protection with anti-spam, DLP, and encryption. XG’s Live Anti-Spam provides protection from the most recent spam campaigns, phishing attacks, and malicious attachments. Data Loss Prevention automatically triggers encryption on sensitive data in outgoing emails.

    Reviews from Real Users

    Sophos XG Firewall stands out among its competitors, among other reasons, for its intrusion detection capabilities, its user-friendly management platform, and in general, for being a complete and robust firewall solution.

    Niranjan P., a network & system support engineer, writes, “Sophos is a comprehensive solution which allows me to configure all the attendant products, such as Sophos's firewall, endpoint, and encryption features. A nice feature of Sophos is that it offers in sync and heartbeat security. When my clients have a perimeter involving Sophos firewall and endpoints with Sophos Endpoint, they can communicate with each other.”

    Antonio D., sales manager at INFOSEC, notes, “The product has a console that is based in the cloud for all their products. In this console, they have email security, firewall security, endpoint security, et cetera. All of the products on offer in the console are very useful for us. The solution is stable. The solution works well for enterprises and large-scale organizations.”

    Antony M., ICT/HMIS supervisor at a healthcare company, writes, “The VPN feature is the most valuable. It has come in handy during this period when people are working from home. The filtering feature is also valuable because you can easily filter the sites that you don't want to visit. You can also set timely surfing quotas”

    Sample Customers
    1. Amazon Web Services 2. Microsoft 3. IBM 4. Cisco 5. Dell 6. HP 7. Oracle 8. Verizon 9. AT&T 10. T-Mobile 11. Sprint 12. Vodafone 13. Orange 14. BT Group 15. Telstra 16. Deutsche Telekom 17. Comcast 18. Time Warner Cable 19. CenturyLink 20. NTT Communications 21. Tata Communications 22. SoftBank 23. China Mobile 24. Singtel 25. Telus 26. Rogers Communications 27. Bell Canada 28. Telkom Indonesia 29. Telkom South Africa 30. Telmex 31. Telia Company 32. Telkom Kenya
    Information Not Available
    Top Industries
    REVIEWERS
    Comms Service Provider16%
    Computer Software Company9%
    Financial Services Firm8%
    Manufacturing Company7%
    VISITORS READING REVIEWS
    Educational Organization20%
    Computer Software Company15%
    Comms Service Provider8%
    Manufacturing Company6%
    REVIEWERS
    Manufacturing Company11%
    Financial Services Firm9%
    Comms Service Provider8%
    Healthcare Company8%
    VISITORS READING REVIEWS
    Computer Software Company17%
    Comms Service Provider12%
    Government6%
    Manufacturing Company6%
    Company Size
    REVIEWERS
    Small Business48%
    Midsize Enterprise23%
    Large Enterprise30%
    VISITORS READING REVIEWS
    Small Business27%
    Midsize Enterprise32%
    Large Enterprise41%
    REVIEWERS
    Small Business61%
    Midsize Enterprise24%
    Large Enterprise15%
    VISITORS READING REVIEWS
    Small Business38%
    Midsize Enterprise19%
    Large Enterprise43%
    Buyer's Guide
    Fortinet FortiGate vs. Sophos XG
    March 2024
    Find out what your peers are saying about Fortinet FortiGate vs. Sophos XG and other solutions. Updated: March 2024.
    768,857 professionals have used our research since 2012.

    Fortinet FortiGate is ranked 2nd in Firewalls with 306 reviews while Sophos XG is ranked 7th in Firewalls with 192 reviews. Fortinet FortiGate is rated 8.4, while Sophos XG is rated 8.2. The top reviewer of Fortinet FortiGate writes "It's a reliable solution that's easy to install and cheaper than competitors ". On the other hand, the top reviewer of Sophos XG writes "Easy to use and deploy with an improved pricing structure in place". Fortinet FortiGate is most compared with Cisco Secure Firewall, Netgate pfSense, Meraki MX, Check Point NGFW and WatchGuard Firebox, whereas Sophos XG is most compared with Netgate pfSense, OPNsense, Sophos XGS, SonicWall TZ and Palo Alto Networks NG Firewalls. See our Fortinet FortiGate vs. Sophos XG report.

    See our list of best Firewalls vendors.

    We monitor all Firewalls reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.