Skip to content
Avanet
Hosted Sophos Firewall connects offices and data centres through secure cloud infrastructure

Hosted Sophos Firewall: Firewall as a Service

Many companies already run their Sophos Firewall as a virtual appliance on VMware, Hyper-V, Azure, AWS or another cloud platform. However, this requires not only a firewall licence but also suitable compute, storage and network resources. It also involves operations, monitoring, backups, updates and responsibility when a fault occurs.

Not every company wants to build this platform itself or deal with hyperscaler costs, virtualisation, public IP addresses and redundant infrastructure. This is precisely why Avanet offers the Hosted Sophos Firewall as Firewall as a Service: we provide the virtual firewall in a suitable data centre and, depending on the operating model, also take care of security updates, monitoring, backups, maintenance and support.

The internal IT team can continue to administer the firewall itself, share tasks with Avanet or largely outsource operations to us. This provides a professional Sophos Firewall environment without the need to operate a local appliance or a dedicated cloud platform.

When Firewall as a Service makes sense

A virtual Sophos Firewall can also be operated on an in-house virtualisation platform or directly with a major cloud provider. This makes sense when the organisation already has cloud expertise, a suitable operating model and sufficient resources.

Firewall as a Service is particularly attractive when an organisation:

  • does not want to purchase and replace its own firewall hardware,
  • does not want to operate its own virtualisation or cloud platform,
  • wants to outsource operations, updates, backups and monitoring,
  • needs a central firewall for sites, VPNs, REDs or cloud workloads,
  • wants to size powerful CPU, RAM, NVMe and network resources flexibly,
  • prefers a dedicated contact and a defined SLA.

At Avanet, Sophos Firewall OS (SFOS) runs as a dedicated virtual firewall instance in a selectable data centre. The terms Hosted Firewall, Cloud Firewall, Firewall as a Service (FWaaS) and Virtual Firewall as a Service (VFWaaS) are also used for this model.

The instance has its own configuration, licence, public IP addresses, firewall rules, VPN connections and Security Policies. This provides the familiar Sophos Firewall features without having to purchase, operate and later replace a local XGS appliance.

ComponentAvanet offering
PlatformVirtual Sophos Firewall on professional data centre infrastructure
LocationChoice of data centres in Europe, the Americas, Asia, Australia and Africa
ResourcesCPU, RAM, storage and network connectivity matched to requirements
AdministrationSelf-managed, jointly operated or provided as a Managed Service
BillingMonthly or annually
NetworkPublic IPv4 and IPv6 addresses, redundant connectivity and local peering
Add-onsBackup, monitoring, SLA, Security Audit, SIEM integration and other services

The model is particularly suitable for central VPN and RED hubs, multiple sites, publicly accessible services, cloud workloads or companies that deliberately want to outsource firewall infrastructure and operations. The differences compared with a local appliance are explained in Sophos Firewall as hardware or virtual appliance.

What Avanet provides

  • No dedicated hardware or cloud platform: There is no need to purchase, install or later replace an appliance. Hosts, storage, networking and public addresses do not have to be provided in-house either.
  • Rapid deployment: The environment can be prepared, tested and then put into production without waiting for hardware delivery.
  • Flexible scaling: CPU, RAM and storage can be matched to actual requirements and adjusted when needs change.
  • Powerful platform: Current server processors, fast memory and NVMe storage provide a strong foundation for VPN, IPS, TLS Inspection and other compute-intensive features.
  • Redundant infrastructure: Power, compute, storage and network connectivity are designed for data centre operation.
  • Managed operations as required: Avanet can manage security updates, firmware planning, monitoring, backups, maintenance and incident handling.
  • Defined responsibilities: The SLA, response times, escalation paths and operational tasks are documented in the proposal.
  • Integrations: Syslog, SIEM, monitoring, Sophos Central and other services can be incorporated into the operating model.
  • Personal support: Planning, migration and operations are supported by an experienced Sophos team.

Performance and network connectivity

The virtual firewall does not run on the resource-efficient hardware of a small desktop appliance, but on professional server infrastructure. A high CPU clock speed, sufficient RAM and fast NVMe storage can make a noticeable difference, particularly for compute-intensive tasks. Actual performance nevertheless always depends on the selected sizing, traffic volume and enabled Security Features.

AreaImplementation
CPUCurrent server processors with at least 3 GHz; vCPU matched to the sizing
MemoryFast, low-latency RAM with high read and write performance
StorageFast NVMe or SSD storage, depending on the location
NetworkRedundant network design and local peering
AddressingIPv4 and IPv6 available
ScalingResources are sized to match usage and can be adjusted

In addition to bandwidth, sizing must take account of concurrent connections, VPN tunnels and enabled features such as IPS, Web Protection, Zero-Day Protection or TLS Inspection. Avanet helps with the selection; the technical principles are explained in the Sophos Firewall Sizing Guide.

Operations, updates and SLA

Hosting and administration can be combined flexibly.

Operating modelDivision of responsibilities
Self-managedAvanet provides the hosting infrastructure. The internal IT team manages the configuration, updates and rules.
Jointly operatedThe internal IT team and Avanet share administration, maintenance and support according to clearly defined responsibilities.
Managed ServiceAvanet takes responsibility for the agreed operational, maintenance, monitoring and support tasks.

Available operational services

  • Setup Services: Professional base configuration for a clean and secure start.
  • Migration: Transfer of an existing Sophos Firewall or implementation of a new cloud architecture.
  • Firewall maintenance: Planning and installation of security and firmware updates, configuration maintenance and regular reviews.
  • Health Check: Review of an existing configuration with specific recommendations for improvement.
  • Security Audit: Assessment of rules, access, protection features and operational processes.
  • Monitoring and backup: Monitoring, notifications and configuration backups.
  • SLA: Defined service hours and agreed response, escalation and recovery objectives.
  • Workshops: Practical training for the responsible administrators based on their own environment.
  • Integrations: Connection to SIEM, Syslog and other monitoring systems.

The included services are clearly specified in the proposal. This makes it transparent who installs updates, implements changes, checks backups, handles alerts and responds to incidents. An SLA always applies to the specifically agreed service and does not replace properly planned technical redundancy.

Available data centre locations

A Hosted Sophos Firewall can be deployed in a geographically suitable data centre. Shorter network paths reduce latency, while requirements for data location, cloud connectivity and public IP addresses can also be taken into account.

  • Europe: Germany (Frankfurt), France (Paris), the Netherlands (Amsterdam), Poland (Warsaw), Sweden (Stockholm), Switzerland (Lucerne and Nottwil), Spain (Madrid) and the United Kingdom (London).
  • Americas: Brazil (São Paulo), Chile (Santiago), Canada (Toronto), Mexico (Mexico City), the USA (Atlanta, Chicago, Dallas, Los Angeles, Miami, New York/New Jersey, Seattle and Silicon Valley) and Hawaii (Honolulu).
  • Asia and the Middle East: India (Bangalore, Delhi NCR and Mumbai), Israel (Tel Aviv), Japan (Osaka and Tokyo), Singapore (Singapore) and South Korea (Seoul).
  • Australia and Africa: Australia (Melbourne and Sydney) and South Africa (Johannesburg).

The data centre infrastructure is certified to ISO 27001. Particularly highly available infrastructure is also available at Swiss locations; according to the operator, one location achieves Tier IV with 99.998 per cent availability.

High availability of the platform and firewall

Redundant hosts, power supplies, storage, network components and uplinks reduce dependency on individual infrastructure components. Depending on the location and selected package, highly available platform and network services are used.

However, a single virtual firewall does not automatically constitute a Sophos Firewall HA cluster. The infrastructure can be highly available while SFOS itself continues to operate as a single instance.

If the firewall itself must also be redundant, a Sophos Firewall HA cluster can be planned as an additional component. The required architecture depends on the location, network, licensing and desired SLA. Availability, response time and recovery objectives are therefore defined specifically in the proposal.

Costs and billing

The Hosted Sophos Firewall can be billed monthly or annually. The price is made up of the components actually required:

  • Sophos Firewall licence and Security Subscription,
  • CPU, RAM and storage,
  • public IPv4 and IPv6 addresses,
  • network connectivity and data transfer,
  • backup and retention,
  • monitoring and Managed Services,
  • required SLA,
  • one-off setup or migration.

This means that organisations pay for the capacity they need and avoid an upfront hardware investment. Resources and services can be adjusted as requirements change.

From enquiry to operation

  1. Gather requirements: Record sites, bandwidth, users, VPNs, published services and Security Features.
  2. Define location and sizing: Select a suitable data centre, resources, IP addresses and licence.
  3. Define the operating model: Assign responsibilities for configuration, updates, backups, monitoring and support.
  4. Deploy the firewall: Avanet installs and configures the virtual Sophos Firewall.
  5. Perform the migration: Existing rules, VPNs, RED connections and services are transferred in a controlled manner.
  6. Verify functionality: Test routing, DNS, VPN, public services, logging and administrative access.
  7. Hand over operations: Formally document operating procedures, monitoring, backups and escalation paths.

For an existing Sophos Firewall, the configuration can often be transferred using a backup. Avanet checks compatibility, interfaces, licences, public IP addresses and any required adjustments in advance. The production cutover includes an acceptance test and rollback plan.

Interested in a Hosted Sophos Firewall?

Avanet is a Sophos Platinum Partner and provides support from architecture and product selection through to ongoing operations. Before preparing a proposal, we jointly assess whether a Hosted Sophos Firewall is suitable for the environment, which location makes sense and which resources, licences, integrations and operational services are required.

The following information is helpful when requesting a proposal:

  • preferred data centre location,
  • existing or new Sophos Firewall licence,
  • internet bandwidth and number of users,
  • number of VPN, RED and site-to-site connections,
  • required public services and IP addresses,
  • preferred operating model,
  • backup, monitoring and SLA requirements.

Request a no-obligation quote for a Hosted Sophos Firewall

FAQ

Can the Hosted Sophos Firewall be self-managed?

Yes. The firewall can be self-managed, jointly operated with Avanet or provided entirely as a Managed Service.

Can an existing Sophos Firewall be migrated?

In many cases, the existing configuration can be transferred. Avanet checks backup compatibility, licensing, interfaces, routing, VPNs and public services before the migration.

Is the Hosted Sophos Firewall automatically highly available?

The hosting infrastructure is designed with redundancy. If redundancy is required at the SFOS level, a Sophos Firewall HA cluster is planned separately.

Which locations are available?

Data centres are available in Europe, North and South America, Asia, Australia and Africa. The complete list of locations is provided in this article.

How is the Hosted Firewall billed?

Monthly or annual billing is available. The price depends on the licence, resources, location, IP addresses, data transfer and required operational services.

Patrizio