{"id":131505,"date":"2023-09-12T14:13:35","date_gmt":"2023-09-12T13:13:35","guid":{"rendered":"https:\/\/www.avanet.com\/blog\/sophos-ztna-gateway-on-sophos-firewall\/"},"modified":"2024-08-12T10:51:19","modified_gmt":"2024-08-12T09:51:19","slug":"sophos-ztna-gateway-on-sophos-firewall","status":"publish","type":"post","link":"https:\/\/www.avanet.com\/en\/blog\/sophos-ztna-gateway-on-sophos-firewall\/","title":{"rendered":"Sophos ZTNA Gateway on Sophos Firewall"},"content":{"rendered":"\n<p>Since Sophos Firewall version 19.5 MR3 it is possible to use the Sophos ZTNA Gateway on the Sophos Firewall. The solution is really great and simple, but there is a catch, which there is to consider (15 GB).<\/p>\n\n<h2 class=\"wp-block-heading\">ZTNA Gateway (Cloud vs. On-premise)<\/h2>\n\n<p>The ZTNA Gateway is required to use Zero Trust. There are two different deployment modes: the on-premise gateway and the Sophos Cloud Gateway.<\/p>\n\n<p><strong>On-premise gateway<\/strong>: This mode allows direct and fast data connection without restrictions by installing the gateways in the company&#8217;s own data center or on a hypervisor within the company itself. Although it provides greater control over the infrastructure, it also requires increased management overhead, as firewall ports must be opened and NAT rules must be created.<\/p>\n\n<p><strong>Sophos Cloud Gateway<\/strong>: In contrast, Sophos Cloud Gateway provides secure and isolated network deployment through the use of a Sophos Cloud. This mode guarantees 99.999% availability and allows users to easily connect to applications without the need to open firewall ports or create NAT rules. One drawback, however, is the traffic limit of 15 GB per user per month, which can be reached quickly when used for network drives.<\/p>\n\n<p>There is no wrong decision here, because you always have the option to switch to the other method with relatively little effort.<\/p>\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;69e6f5e13211c&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"69e6f5e13211c\" class=\"wp-block-image size-large wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"467\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.avanet.com\/assets\/sophos-ztna-connector-sophos-firewall-1024x467.jpg\" alt=\"Sophos ZTNA Connector on Sophos Firewall\" class=\"wp-image-131385\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-ztna-connector-sophos-firewall-1024x467.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-ztna-connector-sophos-firewall-scaled-64x29.jpg 64w, https:\/\/www.avanet.com\/assets\/sophos-ztna-connector-sophos-firewall-300x137.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-ztna-connector-sophos-firewall-768x350.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-ztna-connector-sophos-firewall-1536x700.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-ztna-connector-sophos-firewall-2048x933.jpg 2048w, https:\/\/www.avanet.com\/assets\/sophos-ztna-connector-sophos-firewall-600x273.jpg 600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">Source: sophos.com<\/figcaption><\/figure>\n\n<h2 class=\"wp-block-heading\">ZTNA Cloud Gateway on Sophos Firewall<\/h2>\n\n<p>The SFOS v19.5 MR3 update integrates the <strong>ZTNA Cloud Gateway<\/strong> with the Sophos Firewall. This greatly simplifies the implementation of ZTNA, as a separate ZTNA Gateway VM is no longer required. The firewall now assumes the role of the ZTNA gateway, eliminating the need for hypervisor hosts and enabling rapid startup within minutes. Of course, if you have a firewall HA cluster, the ZTNA gateway is also highly available. Both the hardware appliance and the software solution can be used as a ZTNA gateway.<\/p>\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;69e6f5e1347ac&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"69e6f5e1347ac\" class=\"wp-block-image size-large wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"931\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.avanet.com\/assets\/add-sophos-firewall-ztna-cloud-gateway-1024x931.jpg\" alt=\"Add Sophos Firewall ZTNA Cloud Gateway to Central\" class=\"wp-image-131508\" srcset=\"https:\/\/www.avanet.com\/assets\/add-sophos-firewall-ztna-cloud-gateway-1024x931.jpg 1024w, https:\/\/www.avanet.com\/assets\/add-sophos-firewall-ztna-cloud-gateway-scaled-64x58.jpg 64w, https:\/\/www.avanet.com\/assets\/add-sophos-firewall-ztna-cloud-gateway-300x273.jpg 300w, https:\/\/www.avanet.com\/assets\/add-sophos-firewall-ztna-cloud-gateway-768x699.jpg 768w, https:\/\/www.avanet.com\/assets\/add-sophos-firewall-ztna-cloud-gateway-1536x1397.jpg 1536w, https:\/\/www.avanet.com\/assets\/add-sophos-firewall-ztna-cloud-gateway-2048x1863.jpg 2048w, https:\/\/www.avanet.com\/assets\/add-sophos-firewall-ztna-cloud-gateway-600x546.jpg 600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">Add Sophos Firewall ZTNA Cloud Gateway to Central<\/figcaption><\/figure>\n\n<h3 class=\"wp-block-heading\">Traffic limitation<\/h3>\n\n<p>This limitation is certainly not a disadvantage, but you should keep it in mind and plan for which applications you want to use ZTNA.<\/p>\n\n<p>With the cloud gateway, data traffic runs through a data center, which incurs traffic costs on the part of Sophos. Therefore, a limit of 15 GB per user per month was defined. If multiple users are licensed, the limit is aggregated across all users. So if you have data-hungry applications, the on-premise method is probably the better one.<\/p>\n\n<h2 class=\"wp-block-heading\">Licensing<\/h2>\n\n<p>No additional budget is required to use the ZTNA Gateway on the <a href=\"https:\/\/www.avanet.com\/en\/shop\/sophos-firewall\/\">Sophos Firewall<\/a>. The ZTNA Gateways are free of charge regardless of the deployment situation and do not require a license. Only the users who use the service must be licensed per user.<\/p>\n\n<p>Pricing: <a href=\"https:\/\/www.avanet.com\/en\/shop\/sophos-central-zero-trust-network-access\/\">Sophos Central Zero Trust Network Access<\/a><\/p>\n\n<h2 class=\"wp-block-heading\">Let&#8217;s go<\/h2>\n\n<p>For those who want to test the ZTNA gateway on the Sophos Firewall or even the on-premise gateway, here are a few helpful links to get you started:<\/p>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.avanet.com\/en\/kb-category\/zero-trust\/\">Avenet KB: Zero Trust Network Access<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/doc.sophos.com\/central\/ZTNA\/startup\/en-us\/setup\/AddGateway\/SophosCloudDeploymentMode\/index.html#__tabbed_1_4\" target=\"_blank\" rel=\"noopener\">Set up Sophos Cloud Gateways on Sophos Firewall<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.sophos.com\/en-us\/products\/sophos-central\/free-trial?id=0013000001EjyeY\" target=\"_blank\" rel=\"noopener\">Create Sophos Central trial account<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Since Sophos Firewall version 19.5 MR3 it is possible to use the Sophos ZTNA Gateway on the Sophos Firewall. The solution is really great and simple, but there is a catch, which there is to consider (15 GB). ZTNA Gateway (Cloud vs. On-premise) The ZTNA Gateway is required to use Zero Trust. There are two [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":131487,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[277],"tags":[],"class_list":["post-131505","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/131505","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/comments?post=131505"}],"version-history":[{"count":0,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/131505\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media\/131487"}],"wp:attachment":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media?parent=131505"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/categories?post=131505"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/tags?post=131505"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}