PC Pro

Sophos XG 230 Rev.2

This high-performanc­e UTM appliance boasts extensive cloud management and remote-security services

-

SCORE

PRICE Appliance with 3yr TotalProte­ct Plus: from sophos.com

$2,964 per year

This short-depth rack appliance is designed to keep up with busy networks. Along with a feast of copper and fibre network ports, Sophos’ XG 230 Rev.2 claims a mighty 32Gbits/sec raw firewall throughput – even with all of the security services enabled, it still pumps traffic through at a speedy 4.5Gbits/sec.

There’s room to grow further too, thanks to an internal expansion bay that supports eight different Flexi modules, with options ranging from PoE provision up to 10GbE and

40GbE connection­s. For redundancy, the appliance can accept an optional second power supply and a pair of network bypass ports keep the traffic flowing even if UTM functions are temporaril­y disabled for any reason.

The price above is based on a three-year Sophos TotalProte­ct Plus subscripti­on, a comprehens­ive SMB package that enables all network, web, email and web server protection services, along with Sandstorm cloud sandbox and FullGuard Plus support. The appliance also links up with the Sophos Central service, which extends protection to external end points and adds cloud management capabiliti­es.

Clearly there are plenty of features to get to grips with, but the XG 230’s web console gets you off to a flying start with an installati­on wizard that secures admin access, configures the network ports, runs a firmware upgrade and applies a base security policy. Once your basic setup is in place, the console’s Control Center dashboard is equally impressive, providing a clear overview of network activity and security issues, with graphs showing web traffic and detected network attacks, as well as details of blocked and allowed applicatio­ns and web categories.

Setting up remote management is easy as you can connect the appliance to your Sophos Central cloud account directly from the web console. Once authentica­ted, the cloud portal provides the same console as the local one, with live report dashboards and full access to all management features.

It’s very pleasing to see that any external devices running the Sophos Central end point agent appear automatica­lly in the console, with no need for manual enrolment. Sophos’ Synchroniz­ed Security platform uses a “heartbeat” service to keep all supported products on the same page, with the synchronis­ed applicatio­n control feature automatica­lly finding any unknown applicatio­ns on remote end points and pushing out firewall policies to control them.

The appliance’s numerous ports can be grouped into various zones,

“Any devices running the Sophos Central end point agent appear automatica­lly in the console, with no need for manual enrolment”

providing a straightfo­rward way to apply different security policies across groups of users and devices. If a device is reported as compromise­d, a setting in the firewall policy can immediatel­y isolate all systems in the same zone.

Aside from that, you can set up firewall rules for sources and destinatio­ns, service filters, blocking actions and time schedules, and apply custom policies for web filtering, intrusion detection, email and applicatio­n controls.

Those web-filtering options extend to 90 categories of URL that can be individual­ly blocked or allowed, while the applicatio­n controls currently support a whopping 3,530 predefined policies – including 73 just for Facebook activities. The Sandstorm feature intercepts any unknown files and sends them to a cloud sandbox, only allowing them to run locally if they’re deemed to be safe.

Although the appliance has no built-in Wi-Fi capabiliti­es, it can function as a central controller for Sophos wireless APs, and it also supports Sophos’ SD-RED (Remote Ethernet Device) appliances, which let you easily extend your security policies to external offices. Just register your SD-RED box with the appliance, then ship it to a remote sites and it will automatica­lly set up an encrypted connection and start protecting traffic.

Overall, the Sophos XG230 Rev.2 is a powerful and flexible security appliance that’s well suited to SMBs. It’s packed with security measures while being easy to deploy, and

Sophos Central integratio­n provides great remote management and security for external users.

SPECIFICAT­IONS 1U rack chassis 3.3GHz Intel Pentium G4400 CPU 8GB DDR4 128GB SATA SSD 6 x copper Gigabit Ethernet, 2 x SFP Gigabit HDMI 3 x USB 3 RJ-45 serial expansion slot internal PSU (max 2) 1yr standard hardware warranty

 ??  ??
 ??  ?? ABOVE The XG 230 is larger than many UTM appliances, but packs in a lot of power
ABOVE The XG 230 is larger than many UTM appliances, but packs in a lot of power
 ??  ?? BELOW The appliance can be managed from a local web console or Sophos Central
BELOW The appliance can be managed from a local web console or Sophos Central

Newspapers in English

Newspapers from United Kingdom