Comparing Sophos Firewall Bundles
Sophos currently offers two official appliance bundles for Sophos Firewall: Standard and Xstream. Avanet Epic Protection is also available from Avanet. Epic is not a third official Sophos bundle; it combines Xstream Protection with the separately licensed Email Protection and Webserver Protection modules.
This distinction is important for purchases and renewals. It shows which components Sophos bundles directly, which ones Avanet combines into a package, and which functions can be added or omitted individually later.
Quick decision: Standard covers classic gateway security. Xstream adds advanced analysis, DNS, orchestration, reporting, and Active Threat Response functions. Avanet Epic is suitable when Mail Protection and WAF are also to run directly on the firewall.
The Three Purchasable Options at a Glance
- Sophos Standard Appliance Bundle: Base License plus Standard Protection with Network Protection, Web Protection, and Enhanced Support for classic firewall, IPS, web, and Application Control tasks.
- Sophos Xstream Appliance Bundle: Base License plus Xstream Protection with Network Protection, Web Protection, Enhanced Support, Zero-Day Protection, Central Orchestration, DNS Protection, and additional Active Threat Response functions.
- Avanet Epic Protection: Xstream Protection plus Email Protection and Webserver Protection as an Avanet package.
For an XGS appliance, the appliance bundle also includes the Base License. In protection-only, renewal, virtual, or cloud offers, the Base License and protection subscriptions may be listed differently. The specific offer, platform, and components actually listed are therefore always decisive for the order.
A bundle is also no substitute for sizing. Whether, for example, an XGS 128 or XGS 2300 is suitable depends on throughput, users, TLS Inspection, VPN, ports, growth, and redundancy. The Sophos Firewall Sizing Guide explains this decision.
Sophos Standard Appliance Bundle
Standard Protection includes Network Protection, Web Protection, and Enhanced Support. Together with the Base License, these components form the Standard Appliance Bundle for an XGS appliance.
Network Protection
Network Protection provides IPS, Sophos X-Ops Threat Feeds, SD-RED management, and Security Heartbeat, among other functions. These features help detect network attacks, block known malicious destinations, and take the status of compatible Sophos Endpoints into account in firewall rules.
Web Protection
Web Protection includes Web Security and Control, Application Control including Synchronized Application Control, and Web Malware Protection. These functions control web access, applications, and downloads according to the organization’s policies.
Enhanced Support
During the valid term, Enhanced Support includes extended Sophos support, firmware and feature updates, and the specified hardware replacement service. The Base License alone must not be equated with this level of support. Understanding the Sophos Firewall Base License explains the differences.
Standard is usually suitable when a firewall protects classic branch, server, or client networks and IPS, Web Protection, Application Control, and reliable support are required. It is not a stripped-down firewall: many key protection functions are already included. Xstream only becomes worthwhile when its additional modules are technically required and will subsequently be operated.
Sophos Xstream Appliance Bundle
Xstream includes Network Protection, Web Protection, and Enhanced Support, as well as Zero-Day Protection, Central Orchestration, and DNS Protection. For an appliance, the Base License is added.
Zero-Day Protection
Zero-Day Protection analyzes eligible files using Machine Learning, Sandboxing, and Threat Intelligence. This can detect unknown malware that has not yet been covered by traditional signatures. However, the license alone is not enough: policies, supported file types, exceptions, the TLS Inspection concept, and monitoring determine which data is actually analyzed. The practical process is described in Sophos Firewall Zero-Day Protection.
TLS Inspection is not an exclusive Xstream feature. Network Protection and Web Protection are already included in Standard. Xstream becomes relevant through its additional Zero-Day analysis when decrypted traffic and downloads are to undergo more extensive analysis.
Central Orchestration and Reporting
Central Orchestration includes centralized SD-WAN VPN orchestration, Central Firewall Reporting Advanced, and the MDR/XDR Data Lake Connector. This is particularly useful for multiple firewalls, site connectivity, and recurring changes.
An active Xstream bundle provides a limited Advanced Reporting option with up to 30 days of retention. Among other things, it supports exports as well as saved and scheduled reports. The separately licensed Central Firewall Reporting Advanced can retain data for up to one year. Central Firewall Reporting with another active firewall subscription retains data for up to seven days. Depending on the firewall model and the volume of data generated, the storage limit may shorten the actual retention period. Sophos Firewall Central Reporting describes setup and operation.
General Sophos Central Firewall Management is not the same as Central Orchestration. Centralized management, backups, and firmware scheduling are already available with a paid firewall subscription, a bundle, or a support license; the Base License alone is not sufficient. For centrally executed changes, the Sophos Central Firewall Task Queue should be part of the control process.
DNS Protection and Active Threat Response
The DNS Protection included in Xstream protects DNS requests through the firewall integration. It is not the same as the endpoint-based DNS Protection in Workspace Protection. Sophos DNS Protection with Sophos Firewall shows the firewall configuration.
Threat Feeds also require a precise distinction:
- Sophos X-Ops Threat Feeds are part of Network Protection and are therefore included in Standard and Xstream.
- Third-party Threat Feeds and NDR Essentials require Xstream.
- MDR Threat Feeds additionally require a suitable Sophos MDR license in Sophos Central.
Xstream supplements the X-Ops feeds already available with Network Protection with third-party feeds, NDR Essentials, and MDR/XDR feed integration. This does not automatically include a complete Sophos MDR service contract. In our experience, well-maintained Third-party Threat Feeds are a particularly tangible Xstream benefit because custom sources can be used directly for monitoring or blocking.
Avanet Epic Protection
Avanet Epic Protection combines Xstream Protection with Email Protection and Webserver Protection. Avanet packages this scope for purchase and renewal; the components and terms listed in the specific offer remain authoritative.
Epic is suitable when at least one of the additional tasks is deliberately to be run on the firewall:
- Email Protection: On-box anti-spam, antivirus, DLP, encryption, and malware protection for mail flow through the firewall. Sophos Firewall Mail Protection in MTA Mode explains the configuration.
- Webserver Protection: Web Application Firewall for published web servers and applications. The architecture and setup are described in Sophos Firewall WAF: Publishing Web Servers Securely.
These modules are not automatically useful in every environment. If email is already protected by Sophos Central Email, Microsoft 365, or another Secure Email Gateway, on-box Email Protection can create duplicate complexity. The same applies to WAF when applications are already behind a specialized reverse proxy, cloud WAF, or Application Gateway.
Epic therefore does not simply mean “more is better.” The package is useful when Xstream, Mail Protection, and WAF are genuinely required and responsibilities for quarantine, certificates, exceptions, logs, and changes are in place.
Which Bundle Fits the Environment?
The selection starts with the operating model, not the discount.
Standard is usually sufficient when:
- IPS, Web Protection, and Application Control are the main protection modules;
- one or a few firewalls are operated without centralized VPN orchestration;
- up to seven days of Central Reporting or a dedicated syslog/SIEM are sufficient;
- Zero-Day, DNS, and third-party feed functions are not planned.
Xstream is appropriate when:
- Zero-Day Protection is integrated productively into suitable web or download policies;
- firewall DNS Protection or third-party Threat Feeds are used;
- multiple sites are managed through Central Orchestration;
- up to 30 days of Central Reporting with exports and scheduled reports are required;
- NDR Essentials or other Xstream-bound Active Threat Response functions are part of the security concept.
Avanet Epic is appropriate when:
- the Xstream functions are required;
- email traffic is also to be protected through the firewall;
- published web applications are to use the integrated WAF;
- mail and WAF operations are genuinely covered organizationally.
ZTNA must not be planned as an included Xstream or Epic user license. A Sophos Firewall can serve as a ZTNA Gateway, but the actual usage rights for users belong to the separate Workspace Protection model. Zero Trust and ZTNA explains the fundamentals and components.
Evaluating Promotional Offers and Terms
Hardware bundles and multi-year promotions can be economically attractive. However, they do not change the technical requirements. Discounts, terms, and available combinations depend on the model, country, and time and should therefore always be assessed against the current offer.
Five questions help before making a decision:
- Which modules will actually be configured and monitored from the first year?
- Which functions are only planned, and is there a date and a responsible person for them?
- What are the total costs and upfront payment over the full term?
- What renewal costs will arise after the promotion?
- Are functions already paid for covered by other products?
An inexpensive Xstream offer makes sense when its additional functions are used. If they are not operated, Standard may be the better and clearer decision despite a smaller hardware discount.
What a Bundle Does Not Replace
A bundle enables functions but does not configure them. It does not mean that the firewall is correctly sized or that IPS, TLS Inspection, Zero-Day Protection, reporting, HA, or backups are configured appropriately.
Planning for a new firewall must therefore also include configuration after the Setup Wizard, a tested backup and restore concept, and a controlled firmware update process.
Renewal Checklist
The existing selection should not be renewed automatically:
- Check the serial number, model, and Sophos Central account.
- Document the Base License, support, and individual subscriptions separately.
- Compare the modules that are actually enabled and used with the offer.
- Question unused modules instead of silently continuing them.
- Justify new requirements with a specific implementation plan.
- Check reporting retention, exports, and syslog/SIEM integration.
- Assess the firmware version, update entitlement, and hardware lifecycle.
- For HA, check both nodes, roles, and the licensing model.
- For virtual firewalls, check the platform, CPU cores, RAM, and Base License.
- Do not mix up mail, WAF, DNS, MDR, and ZTNA licenses.
- Compare the term, upfront payment, and costs after a promotion.
The Sophos Firewall serial number and account assignment should be clear before an offer is prepared. If ownership of the firewall must change, Transferring a Sophos Firewall to Another Sophos Central Account explains the process. For older appliances, see Sophos XG vs. XGS: EOL and Migration.
Common Mistakes
- Treating Epic as an official third Sophos bundle: Offers and license views are interpreted incorrectly. Always classify Epic as an Avanet package comprising Xstream, Email, and Webserver Protection.
- Confusing Central Management with Central Orchestration: Standard Central management does not automatically require Xstream.
- Choosing Xstream only for TLS Inspection: TLS Inspection is not an exclusive Xstream feature. Zero-Day, DNS, orchestration, reporting, and Active Threat Response are the decisive additions.
- Assuming MDR is included in the Xstream bundle: Xstream provides firewall functions; MDR Threat Feeds additionally require a suitable MDR license.
- Purchasing Email Protection twice: First check where the mail flow is currently protected.
- Planning reporting too late: Retention of up to 7, 30, or 365 days provides different operational and audit options; the storage limit may further shorten the period.
- Equating the bundle with correct sizing: License scope and hardware performance are separate decisions.