Comparing Sophos Firewall Bundles
Sophos currently offers two official appliance bundles for Sophos Firewall: Standard and Xstream. Avanet Epic Protection is also available from Avanet. Epic is not a third official Sophos bundle; it combines Xstream Protection with the separately licensed Email Protection and Webserver Protection modules.
This distinction is important for purchases and renewals. It shows which components Sophos bundles directly, which ones Avanet combines into a package, and which functions can be added or omitted individually later.
Quick decision: Standard covers classic gateway security. Xstream adds advanced analysis, DNS, orchestration, reporting, and Active Threat Response functions. Avanet Epic is suitable when Mail Protection and WAF are also to run directly on the firewall.
The Three Purchasable Options at a Glance
- Sophos Standard Appliance Bundle: Base License plus Standard Protection with Network Protection, Web Protection, and Enhanced Support for classic firewall, IPS, web, and Application Control tasks.
- Sophos Xstream Appliance Bundle: Base License plus Xstream Protection with Network Protection, Web Protection, Enhanced Support, Zero-Day Protection, Central Orchestration, DNS Protection, and additional Active Threat Response functions.
- Avanet Epic Protection: Xstream Protection plus Email Protection and Webserver Protection as an Avanet package.
For an XGS Appliance, the appliance bundle also includes the Base License. In protection-only, renewal, virtual, or cloud offers, the Base License and protection subscriptions may be listed differently. The specific offer, platform, and components actually listed are therefore always decisive for the order.
A bundle is also no substitute for sizing. Whether, for example, an XGS 128 or XGS 2300 is suitable depends on throughput, users, TLS Inspection, VPN, ports, growth, and redundancy. The Sophos Firewall Sizing Guide explains this decision.
Verify the Offer and Active Licenses
This article was last reviewed on September 24, 2026 and takes into account Sophos documentation published through September 14, 2026. Product names and promotions can change. Before ordering or renewing, compare every line item in the offer—not only the bundle name—with the active license inventory.
Sign in to Sophos Fusion (formerly Sophos Central), go to Profile icon > Licensing > Firewall licenses, and expand the relevant firewall. The fields mean:
- Features shows the enabled functions, for example
DNS Protection. - Subscription shows the subscription, for example
Xstream Protection Bundle; for Base, it shows the firewall model or type. - License distinguishes a paid
Subscriptionfrom anEvaluation. - Expiry shows the expiration date. An evaluation or a subscription nearing expiration is not evidence of the renewal term ordered.
The License ID is not the license key in the license schedule. For reliable verification, record the serial number, License ID, Subscription, Features, and Expiry together.
If reporting retention is decisive, also go to Profile icon > Licensing > Product licenses > Central Firewall Reporting > Manage. License type, Central storage used, Average daily upload, and Storage period show whether the expected tier and retention are actually effective.
An existing configuration does not prove that a license is valid. After expiration, settings remain visible and editable, but licensed protection is no longer enforced. Among other effects, Zero-Day analysis and certain Central Orchestration functions stop, Central Reporting falls back to seven days, emails are delivered without anti-spam and antivirus scanning, and existing WAF rules stop working. Before a planned expiration, verify not only the display but also the protection outcome.
Sophos Standard Appliance Bundle
Standard Protection includes Network Protection, Web Protection, and Enhanced Support. Together with the Base License, these components form the Standard Appliance Bundle for an XGS Appliance.
Network Protection
Network Protection provides IPS, Sophos X-Ops Threat Feeds, SD-RED management, and Security Heartbeat, among other functions. These features help detect network attacks, block known malicious destinations, and take the status of compatible Sophos Endpoints into account in firewall rules.
Web Protection
Web Protection includes Web Security and Control, Application Control including Synchronized Application Control, and Web Malware Protection. These functions control web access, applications, and downloads according to the organization’s policies.
Enhanced Support
During the valid term, Enhanced Support includes extended Sophos support, firmware and feature updates, and the specified hardware replacement service. The Base License alone must not be equated with this level of support. Understanding the Sophos Firewall Base License explains the differences.
Standard is usually suitable when a firewall protects classic branch, server, or client networks and IPS, Web Protection, Application Control, and reliable support are required. It is not a stripped-down firewall: many key protection functions are already included. Xstream only becomes worthwhile when its additional modules are technically required and will subsequently be operated.
Sophos Xstream Appliance Bundle
Xstream includes Network Protection, Web Protection, and Enhanced Support, as well as Zero-Day Protection, Central Orchestration, and DNS Protection. For an appliance, the Base License is added.
Zero-Day Protection
Zero-Day Protection analyzes eligible files using Machine Learning, Sandboxing, and Threat Intelligence. This can detect unknown malware that has not yet been covered by traditional signatures. However, the license alone is not enough: policies, supported file types, exceptions, the TLS Inspection concept, and monitoring determine which data is actually analyzed. The practical process is described in Sophos Firewall Zero-Day Protection.
TLS Inspection is not an exclusive Xstream feature. Network Protection and Web Protection are already included in Standard. Xstream becomes relevant through its additional Zero-Day analysis when decrypted traffic and downloads are to undergo more extensive analysis.
Central Orchestration and Reporting
Central Orchestration includes centralized SD-WAN VPN orchestration, Central Firewall Reporting Advanced, and the MDR/XDR Data Lake Connector. This is particularly useful for multiple firewalls, site connectivity, and recurring changes.
An active Xstream bundle provides a limited Advanced Reporting option with up to 30 days of retention. Among other things, it supports exports as well as saved and scheduled reports. The separately licensed Central Firewall Reporting Advanced can retain data for up to one year. Central Firewall Reporting with another active firewall subscription retains data for up to seven days. Depending on the firewall model and the volume of data generated, the storage limit may shorten the actual retention period. Sophos Firewall Central Reporting describes setup and operation.
General firewall management in Sophos Fusion is not the same as Central Orchestration. Centralized management, backups, and firmware scheduling are already available with a paid firewall subscription, a bundle, or a support license; the Base License alone is not sufficient. For centrally executed changes, the Sophos Fusion Firewall Task Queue should be part of the control process.
DNS Protection and Active Threat Response
Xstream Protection licenses standalone DNS Protection for networks and locations. It does not include Sophos Endpoint; DNS Protection for endpoints instead belongs to Workspace Protection. These two entitlements must therefore not be treated as equivalent in an offer or at renewal.
To verify the entitlement, open Administration > Licensing on Sophos Firewall or Firewall Licensing in Sophos Fusion. The Firewall serial number, a valid Xstream Protection subscription, and its Expiry must match the expected account and term. DNS Protection only appears as a product in Sophos Fusion after the licensed firewall has been linked to that account, for example by registration, claiming the serial number, or enabling Fusion management.
If DNS Protection is missing despite Xstream, first check the serial number, account assignment, and expiry date rather than assuming an endpoint entitlement. Checking Sophos licenses and account assignment explains the effects of multiple firewalls, an account transfer, or license expiry. Sophos DNS Protection with Sophos Firewall shows how to integrate DNS Protection with Sophos Firewall.
Threat Feeds also require a precise distinction:
- Sophos X-Ops Threat Feeds are part of Network Protection and are therefore included in Standard and Xstream.
- Third-party Threat Feeds require the Xstream Protection Bundle.
- NDR Essentials specifically requires the Xstream Appliance Bundle.
- MDR Threat Feeds require the Xstream Protection Bundle plus Sophos MDR Essentials or Sophos MDR Complete in Sophos Fusion.
Xstream Protection Bundle and Xstream Appliance Bundle are not interchangeable for these requirements. NDR Essentials must therefore not be inferred from the word “Xstream” in an offer. Verify the exact subscription. Xstream does not automatically include a complete Sophos MDR service contract. In our experience, well-maintained Third-party Threat Feeds are a particularly tangible Xstream benefit because custom sources can be used directly for monitoring or blocking.
Avanet Epic Protection
Avanet Epic Protection combines Xstream Protection with Email Protection and Webserver Protection. Avanet packages this scope for purchase and renewal; the components and terms listed in the specific offer remain authoritative.
Epic is suitable when at least one of the additional tasks is deliberately to be run on the firewall:
- Email Protection: On-box anti-spam, antivirus, DLP, encryption, and malware protection for mail flow through the firewall. Sophos Firewall Mail Protection in MTA Mode explains the configuration.
- Webserver Protection: Web Application Firewall for published web servers and applications. The architecture and setup are described in Sophos Firewall WAF: Publishing Web Servers Securely.
These modules are not automatically useful in every environment. If email is already protected by Sophos Email, Microsoft 365, or another Secure Email Gateway, on-box Email Protection can create duplicate complexity. The same applies to WAF when applications are already behind a specialized reverse proxy, cloud WAF, or Application Gateway.
Epic therefore does not simply mean “more is better.” The package is useful when Xstream, Mail Protection, and WAF are genuinely required and responsibilities for quarantine, certificates, exceptions, logs, and changes are in place.
Which Bundle Fits the Environment?
The selection starts with the operating model, not the discount.
Standard is usually sufficient when:
- IPS, Web Protection, and Application Control are the main protection modules;
- one or a few firewalls are operated without centralized VPN orchestration;
- up to seven days of Central Reporting or a dedicated syslog/SIEM are sufficient;
- Zero-Day, DNS, and third-party feed functions are not planned.
Xstream is appropriate when:
- Zero-Day Protection is integrated productively into suitable web or download policies;
- firewall DNS Protection or third-party Threat Feeds are used;
- multiple sites are managed through Central Orchestration;
- up to 30 days of Central Reporting with exports and scheduled reports are required;
- NDR Essentials or other Xstream-bound Active Threat Response functions are part of the security concept.
Avanet Epic is appropriate when:
- the Xstream functions are required;
- email traffic is also to be protected through the firewall;
- published web applications are to use the integrated WAF;
- mail and WAF operations are genuinely covered organizationally.
ZTNA must not be planned as an included Xstream or Epic user license. A Sophos Firewall can serve as a ZTNA Gateway, but the actual usage rights for users belong to the separate Workspace Protection model. Zero Trust and ZTNA explains the fundamentals and components.
Evaluating Promotional Offers and Terms
Hardware bundles and multi-year promotions can be economically attractive. However, they do not change the technical requirements. Discounts, terms, and available combinations depend on the model, country, and time and should therefore always be assessed against the current offer.
Five questions help before making a decision:
- Which modules will actually be configured and monitored from the first year?
- Which functions are only planned, and is there a date and a responsible person for them?
- What are the total costs and upfront payment over the full term?
- What renewal costs will arise after the promotion?
- Are functions already paid for covered by other products?
An inexpensive Xstream offer makes sense when its additional functions are used. If they are not operated, Standard may be the better and clearer decision despite a smaller hardware discount.
What a Bundle Does Not Replace
A bundle enables functions but does not configure them. It does not mean that the firewall is correctly sized or that IPS, TLS Inspection, Zero-Day Protection, reporting, HA, or backups are configured appropriately.
Planning for a new firewall must therefore also include configuration after the Setup Wizard, a tested backup and restore concept, and a controlled firmware update process.
Renewal Checklist
The existing selection should not be renewed automatically:
- Check the serial number, model, and Sophos Fusion account.
- Document the Base License, support, and individual subscriptions separately.
- Compare the modules that are actually enabled and used with the offer.
- Question unused modules instead of silently continuing them.
- Justify new requirements with a specific implementation plan.
- Check reporting retention, exports, and syslog/SIEM integration.
- Assess the firmware version, update entitlement, and hardware lifecycle.
- For HA, check both nodes, roles, and the licensing model.
- For virtual firewalls, check the platform, CPU cores, RAM, and Base License.
- Do not mix up mail, WAF, DNS, MDR, and ZTNA licenses.
- Compare the term, upfront payment, and costs after a promotion.
The Sophos Firewall serial number and account assignment should be clear before an offer is prepared. If ownership of the firewall must change, Transferring a Sophos Firewall to Another Sophos Fusion Account explains the process. For older appliances, see Sophos XG vs. XGS: EOL and Migration.
Common Mistakes
- Treating Epic as an official third Sophos bundle: Offers and license views are interpreted incorrectly. Always classify Epic as an Avanet package comprising Xstream, Email, and Webserver Protection.
- Confusing Sophos Fusion management with Central Orchestration: Standard firewall management through Sophos Fusion does not automatically require Xstream.
- Choosing Xstream only for TLS Inspection: TLS Inspection is not an exclusive Xstream feature. Zero-Day, DNS, orchestration, reporting, and Active Threat Response are the decisive additions.
- Assuming MDR is included in the Xstream bundle: Xstream provides firewall functions; MDR Threat Feeds additionally require a suitable MDR license.
- Purchasing Email Protection twice: First check where the mail flow is currently protected.
- Planning reporting too late: Retention of up to 7, 30, or 365 days provides different operational and audit options; the storage limit may further shorten the period.
- Equating the bundle with correct sizing: License scope and hardware performance are separate decisions.