• Hardware
    • Firewall
      • XG Appliances
        • XG 86
        • XG 106
        • XG 115
        • XG 125
        • XG 135
        • XG 210
        • XG 230
        • XG 310
        • XG 330
        • XG 430
        • XG 450
        • XG 550
        • XG 650
        • XG 750
      • XG Accessories
      • SG Appliances
        • SG 105
        • SG 115
        • SG 125
        • SG 135
        • SG 210
        • SG 230
        • SG 310
        • SG 330
        • SG 430
        • SG 450
        • SG 550
        • SG 650
      • SG Accessories
    • Access Point
      • Appliances
        • APX 120
        • APX 320
        • APX 530
        • APX 740
        • APX 320X
        • AP 100X
      • AP Accessories
    • RED
      • Appliances
        • SD-RED 20
        • SD-RED 60
      • RED Accessories
  • Licence
    • Firewall
      • XG Licences
        • XG 85
        • XG 86
        • XG 105
        • XG 106
        • XG 115
        • XG 125
        • XG 135
        • XG 210
        • XG 230
        • XG 310
        • XG 330
        • XG 430
        • XG 450
        • XG 550
        • XG 650
        • XG 750
      • SG Licences
        • SG 105
        • SG 115
        • SG 125
        • SG 135
        • SG 210
        • SG 230
        • SG 310
        • SG 330
        • SG 430
        • SG 450
        • SG 550
        • SG 650
      • SFOS Software
        • 1 CPU 4GB RAM
        • 2 CPU 4GB RAM
        • 4 CPU 6GB RAM
        • 6 CPU 8GB RAM
        • 8 CPU 16GB RAM
        • 16 CPU 24GB RAM
        • Unlimited CPU / GB RAM
      • UTM Software
        • 10 User
        • 25 User
        • 50 User
        • 75 User
        • 100 User
        • 150 User
        • 250 User
        • 500 User
        • 750 User
        • 1000 User
        • 1500 User
        • 2500 User
        • unlimited User
    • Central
      • Endpoint Protection
      • Intercept X
      • Intercept X Advanced
      • Intercept X Advanced with EDR
      • Intercept X Advanced with EDR and MTR
      • Server Protection
      • Intercept X Advanced for Server
      • Intercept X Advanced for Server with EDR
      • Intercept X Advanced for Server with EDR and MTR
      • Mobile
      • Intercept X for Mobile
      • Wireless
      • Email Gateway
      • Device Encryption
      • Phish Threat
      • Firewall Reporting
  • Service
  • Blog
  • Support
  • Contact
  • English
    • Deutsch
Sign in
My Account
Cart
  1. Home
  2. Blog
  3. Sophos Firewall
  4. Sophos XG Update v17
  • Sophos Firewall 34
  • Sophos Central 28
  • Avanet Shop 32
  • Security Life 14

Subscribe

Subscribe to our Newsletter, RSS Feed or follow us on Social Media to make sure you don't miss an article.

Subscribe Now
Sophos XG Update v17 - New features overview
sophos-firewall

Sophos XG Update v17: New features overview

Patrizio October 16, 2017

New SFOS will soon be released in version 17! I was already able to take a look at the release candidate and summarized its most important new updates here.

I will describe these new updates from SFOS v17 in this article. We are currently describing the release candidate, but the new version will be available to everyone already within a few weeks.

6 important features in SFOS Update v17

If you don’t want to read through all of this, check out the following Sophos video, where the XG v17 features are introduced in less than 4 minutes:

1. Synchronized App Control

A completely new feature is Synchronized App Control. XG Firewall has only been able to detect applications using signatures so far but, for example, with this you can block or even grant a guaranteed bandwidth (QoS). However, a large part of the traffic could not be classified. These included self-developed or unknown programs or applications that were deliberately not being perceived by using signatures.

Sophos has the possibility to recognize more applications with the v17, which is a drastic increase. However, synchronized security is required for this function. This means for you that you need “Sophos Central Endpoint Advanced” or “Intercept X” for your endpoints and “Sophos Central Server Protection Advanced” for your servers.

  • Sophos Central Endpoint Advanced
  • Sophos Central Intercept X
  • Sophos Central Server Advanced

You give the possibility to your XG Firewall to communicate with them with Sophos Central on the endpoints. Sophos calls this the “Security Heartbeat”. This allows the firewall to ask the endpoint which processes are active on the system and the endpoint returns that data and it is now also possible to assign unclassified traffic. There is also a video about it here:

2. Managing firewall rules

If you own an XG, you are currently aware of how to manage firewall rules. It’s very confusing and you needed to create a kind of “grouping” by the name of the rule. The rules are now displayed more compact, can be grouped together and the most important information is displayed in the overview. The following video shows you how this looks:

3. Policy Test Simulator

There is now also a policy tester at SFOS as in the UTM. You can test your firewall or web proxy rules without having to connect to the client with a remote tool. The following video shows you how the “Policy Test Simulator” works:

4. Blocking Web-proxy Keywords

Some companies, especially schools, often needed to block a website as soon as a particular word could be found. You can now create a keyword list and fill it with supposedly “bad” words in the new v17. If then in the future such a word appears on a web page, one can write this call into the log or block the page altogether completely. There’s a video about it again:

5. XG Firewall Setup Wizard

It wasn’t quite elegantly solved to set up and run a XG firewall with previous setup wizard. The process was a bit painful. Luckily, Sophos worked for the v17 on the setup wizard and made a few changes:

  • Password must be changed right from the start. This makes sense, since no XG firewall is connected with “admin” as username and password with the Internet.
  • Design was vigorously prettied up from my point of view.
  • Backup can be restored immediately.
  • Internet connection is now no longer required.
  • The Sophos ID and license can now be imported later. Once you start the appliance, you can install it with a 30 day trial license without first having to reach a license server first.

If you already have an Internet connection, there are three possibilities:

  1. 30 days test license
  2. Upload UTM license files (UTM to SFOS migration)
  3. Entering XG License key

Check out the new setup wizard in this video:

6. Unified Log Viewer

If there is a problem somewhere in the network, in most cases it already helps in the log of the firewall. Log Viewer of the v16.5 was, however, really a big miss and you will definitely be aware of this when you look at the new “Unified Log Viewer”. Absolutely every little detail became better! New Log Viewer is my absolute favorite feature from v17! Look for yourself, you’ll love it!

  • better clarity!
  • all log information
  • Search and filter across all logs
  • Search in older logs

More minor improvements

  • New tools for NAT, IPS, Web and VPN settings
  • IKEv2 VPN
  • Better IPSec VPN compatibility with other systems
  • Wildcard FQDN - This makes it easy to unblock cloud services
  • NAT improvements - New protocols are supported, no longer just TCP and UDP
  • Email Protection - Smart Host, Greylisting and Recipient Verification
  • Microsoft Azure High Availability

You can find all the innovations in detail in the following Sophos data sheet: XG Firewall : What’s New in v17

Conclusion

New SFOS v17 shows completely new features, but also very important improvements of existing functions. This update changes our attitude towards XG Firewall completely. We would recommended this only for smaller projects, but this looks completely different, above all because of the Log Viewer and new clarity of the firewall rules, that is essential for clean configuration and fast troubleshooting, which was almost impossible with larger networks so far.

Since the v16 was already a huge milestone against the v15, we had already started to prefer the XG over UTM for smaller projects. But now it is clear to us: “XG First”, which is strictly wrong, because it would be “SFOS First”. :)

You can now equip your hardware now with the new SFOS with a clear conscience, if you have a SG firewall with the UTM operating system. Licenses can be accepted, but the configuration not. This is not so bad from our point of view, because we already had several migrations from UTM to SFOS and in any case it is so good to rethink the configuration once again from scratch.


More information about SFOS v17:

  • What’s new in v17?

Sophos Platinum Solution Partner Logo

Purchase Advice

+41 44 585 24 68

Mo - Fr, 9:00 - 12:00 Uhr
Mo - Fr, 13:00 - 17:00 Uhr

Information

  • Payment
  • Shipping & Delivery
  • Order
  • Index of Information
  • Follow us
  • About us

Legal Issues

  • AGB
  • Legal Notice
  • Privacy Policy