{"id":34021,"date":"2022-01-10T12:00:00","date_gmt":"2022-01-10T11:00:00","guid":{"rendered":"https:\/\/www.avanet.com\/blog\/is-it-worth-buying-the-new-xgs-hardware\/"},"modified":"2024-02-02T13:56:56","modified_gmt":"2024-02-02T12:56:56","slug":"is-it-worth-buying-the-new-xgs-hardware","status":"publish","type":"post","link":"https:\/\/www.avanet.com\/en\/blog\/is-it-worth-buying-the-new-xgs-hardware\/","title":{"rendered":"Is it worth buying the new XGS hardware?"},"content":{"rendered":"\n<p>I don&#8217;t know about you, but when it comes to products that I use every day and are indispensable to me, I&#8217;m always up to date with the latest developments. This concerns mostly technical devices, but I&#8217;m also a geek. \ud83d\ude04<\/p>\n\n<p>For all these devices, I follow a clear strategy when it is time to replace the product with its successor.\nI apply this strategy to Sophos Firewall in this blog post to find out whether it is worth switching to the new XGS hardware or not. <\/p>\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Spoiler: In most cases, it actually doesn&#8217;t. \ud83e\udd10<\/p>\n<\/blockquote>\n\n<h2 class=\"wp-block-heading\" id=\"h-4-grunde-um-uber-den-kauf-einer-neuen-xgs-firewall-nachzudenken\">4 reasons to think about buying a new XGS firewall<\/h2>\n\n<p>The new XGS hardware has been on the market since April 2021.\nThere are different factors when the purchase of an XGS hardware is really worthwhile.\nIn the following section, we look at 4 signs that can justify a purchase decision:  <\/p>\n\n<h3 class=\"wp-block-heading\" id=\"h-1-defekt\">1. defect<\/h3>\n\n<p>When a device breaks down and the warranty has expired, it often has to happen quickly and there is no time for in-depth research.\nHere, you should know in advance how to get the infrastructure up and running again and what the delivery times for a replacement device are, if any.\nThe firewall is the heart of the network.\nVery few can afford a longer interruption.\nHowever, companies with more than 20 employees often have an HA solution, which can alleviate the situation somewhat in the event of an outage.    <\/p>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.avanet.com\/en\/kb\/which-types-of-sophos-firewall-ha-clusters-are-available\/\">What are the variants for a Sophos Firewall HA cluster?<\/a><\/li>\n<\/ul>\n\n<h4 class=\"wp-block-heading\" id=\"h-sg-firewall-mit-utm-os\">SG Firewall with UTM OS \ud83e\udd15<\/h4>\n\n<p>Unfortunately, we often see customers with SG hardware still using the UTM OS.\nIn such a situation, the purchase of an XGS firewall is not recommended.\nThe operation should work again as soon as possible and there is no time for a migration to the SFOS.\nYou should therefore reorder the same model of the SG firewall as quickly as possible, in order to restore the configuration from the backup copy in an uncomplicated manner.   <\/p>\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>We generally recommend all customers who still use an SG Firewall with the UTM operating system to consider migrating to the SFOS.\nThe migration of the license is free of charge and the runtime will be taken over 1:1.\nFor the migration the following instructions may help you: <a href=\"https:\/\/www.avanet.com\/en\/kb\/install-sophos-xg-firewall-os-on-a-sg-appliance\/\">Install Sophos XG Firewall OS on an SG Appliance<\/a>  <\/p>\n<\/blockquote>\n\n<p>If you need assistance migrating from UTM to SFOS, we&#8217;ll be happy to help.\nThe UTM hardcore fans among you who don&#8217;t want to switch to SFOS under any circumstances can simply wait until the UTM OS goes End-of-Life.\nThat will certainly not be the case before the end of 2025.\nHowever, the following two blogposts may help you to change your mind:   <\/p>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.avanet.com\/en\/blog\/sophos-utm-end-of-support-for-end-of-2021\/\">Sophos UTM: End of support at the end of 2021<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.avanet.com\/en\/blog\/7-reasons-why-the-xg-firewall-sfos-is-better-than-the-utm\/\">7 reasons why XG Firewall (SFOS) is better than UTM<\/a><\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\" id=\"h-2-keine-updates-mehr\">2. no more updates<\/h3>\n\n<p>When a software has not received any updates for <strong>more than a year<\/strong>, my feelings change.\nIf it&#8217;s been <strong>over two years<\/strong> (often even before that), people start looking for alternatives to replace it. For this reason alone, it would be inconceivable for me to still operate a Sophos Firewall with the UTM operating system today. \ud83d\ude1c <\/p>\n\n<p>Anyone else who has SFOS installed on their SG Firewall or has an XG Firewall should check to see if their appliance can still have SFOS v18.5+ installed.\nIn the following post, we have described which appliances will no longer receive the latest version: <a href=\"https:\/\/www.avanet.com\/en\/blog\/sophos-firewall-appliances-supported-hardware-for-sfos-v18-plus\/\">Sophos Firewall appliances: supported hardware for SFOS v18+<\/a> <\/p>\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>Note<\/strong>: Sophos initially wanted to cut off SG Firewalls with SFOS and older generation XG Firewalls from updates as well.\nHowever, at the beginning of 2021, Sophos deviated from this plan and all current SG and XG models will still receive the latest SFOS versions. <\/p>\n<\/blockquote>\n\n<p>So unless you have an older revision of an SG or XG firewall that no longer receives updates, I can&#8217;t really recommend buying the XGS firewall here either.<\/p>\n\n<h3 class=\"wp-block-heading\" id=\"h-3-keine-garantie-mehr\">3. no more warranty<\/h3>\n\n<p>Another point that plays an important role in my personal purchasing strategy is a product&#8217;s warranty.\nAs soon as it expires, I automatically check whether there are any options for an extension or whether it is time to replace the product. <\/p>\n\n<p>The XG firewalls have a 5-year warranty with the corresponding license.\nIf you are one of the people who bought the first revision of an XG Firewall in 2016, your firewall is no longer covered by the manufacturer&#8217;s warranty.\nIn this case, I would make the following two considerations:  <\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>A single appliance is operated:<\/strong> Here the risk would be too great for me and I would replace the hardware with a new XGS model.<\/li>\n\n\n\n<li><strong>There are two appliances in an HA cluster:<\/strong> Here, too, I would aim for a change.\nIf the budget is not there, you can also wait until one of the two firewalls fails and then buy two new XGS models. <\/li>\n<\/ul>\n\n<h3 class=\"wp-block-heading\" id=\"h-4-nicht-genugend-leistung\">4. not enough power<\/h3>\n\n<p>The last item on my list that can contribute to the decision of a new purchase is the performance of a product.\nIt happens that firmware updates make a device slower over time as new features are packed in.\nOr, quite simply, one&#8217;s own requirements change so that the original performance no longer fits.  <\/p>\n\n<p>These points can also be applied to a Sophos Firewall.\nJust check the load of your firewall, because the number of devices in your network or the number of employees may have changed over the last few years, and the originally required performance no longer meets the current requirements.\nIn such a case, switching to XGS Firewall would certainly not be a bad idea, budget permitting.\nThe license can often be transferred to the new appliance free of charge.   <\/p>\n\n<p>On the other hand, do you have a current SG or XG firewall that still gets the latest updates from SFOS (SFOS 18.5+), is still covered by the manufacturer&#8217;s warranty and has no performance problems?\nThen buying an XGS firewall is not worth it.\nYou should only keep an eye on the End-of-Life date of the XG Firewalls.\nThis date was recently postponed by Sophos from 31.12.2024 to <strong>31.03.2025<\/strong>.   <\/p>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.avanet.com\/en\/blog\/end-of-sale-sophos-xg-firewall-hardware\/\">End of Sale: Sophos XG Firewall Hardware<\/a><\/li>\n<\/ul>\n\n<hr class=\"wp-block-separator has-css-opacity is-style-wide\"\/>\n\n<h2 class=\"wp-block-heading\" id=\"h-zusammenfassung\">Summary<\/h2>\n\n<p>If I apply the 4 points of my personal purchase strategy to the XGS firewall, there is probably no need for action for most existing customers.\nFor new customers, of course, the case is clear and here we would always advise the XGS hardware!\nFinally, I have put together a flowchart for you to help you with the purchase decision process.\nJust play through it yourself and you will get our clear recommendation at the end.   <\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-990x1024.png\"><img loading=\"lazy\" decoding=\"async\" width=\"990\" height=\"1024\" data-id=\"13478\" src=\"https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-990x1024.png\" alt=\"Sophos XGS Firewall decision flow\" class=\"wp-image-13478\" srcset=\"https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-990x1024.png 990w, https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-64x66.png 64w, https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-300x310.png 300w, https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-600x621.png 600w, https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-290x300.png 290w, https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-768x794.png 768w, https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-1485x1536.png 1485w, https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-1980x2048.png 1980w, https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-12x12.png 12w, https:\/\/www.avanet.com\/assets\/new-sophos-xgs-firewall-decision-flow-de-32x32.png 32w\" sizes=\"auto, (max-width: 990px) 100vw, 990px\" \/><\/a><\/figure>\n<\/figure>\n\n<p>For those who have an XG firewall and are undecided at the moment, I recommend the following blog article that describes what the difference is between an XG and an XGS firewall:<\/p>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.avanet.com\/en\/kb\/what-is-the-difference-between-an-xg-and-xgs-firewall\/\">What is the difference between an XG and XGS firewall?<\/a><\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\" id=\"kurz-zusammengefasst-die-entscheidenden-vorteile-der-neuen-xgs-hardware\">Briefly summarized: The decisive advantages of the new XGS hardware<\/h2>\n\n<p>The XGS series offers massively better performance by, among other things, processing traffic intelligently and efficiently and offloading certain tasks such as TLS inspection to the hardware.\nThe new dual-processor architecture with a multi-core CPU and an Xstream flow processor enables better hardware acceleration.\nIn the coming SFOS versions, more processes will be optimized here for the new hardware.  <\/p>\n\n<p>Each unit features a 64-bit CPU and a separate Xtream processor, also known as a Network Processing Unit (NPU).\nThe new series is equipped with additional network ports, allowing optional modules to be added and flexible options for network port selection.\nThe XGS series now offers PoE (Power over Ethernet) ports and fail-to-wire (bypass), allowing traffic to continue even if the device loses power.  <\/p>\n\n<h3 class=\"wp-block-heading\" id=\"network-flow-fastpath\">Network Flow FastPath<\/h3>\n\n<p>Unlike the virtual FastPath, which is processed by the CPU in the XG series, the FastPath in the XGS series is processed by the Xstream flow processor.\nThis is located between the CPU and the physical ports with the PCIe (PCI Express).\nThus, the data traffic outsourced to the FastPath is handled by the Xstream Flow processor and the CPU is less burdened to deal with other tasks that cannot (yet) be outsourced.  <\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-network-flow-fastpath.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"462\" data-id=\"13479\" src=\"https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-network-flow-fastpath-1024x462.png\" alt=\"Sophos XGS - Network Flow FastPath\" class=\"wp-image-13479\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-network-flow-fastpath-1024x462.png 1024w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-network-flow-fastpath-64x29.png 64w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-network-flow-fastpath-300x135.png 300w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-network-flow-fastpath-600x271.png 600w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-network-flow-fastpath-768x347.png 768w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-network-flow-fastpath-18x8.png 18w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-network-flow-fastpath.png 1240w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/figure>\n\n<h3 class=\"wp-block-heading\" id=\"fail-to-wire\">Fail-to-Wire<\/h3>\n\n<p>Fail-to-Wire is a fault tolerance feature that protects enterprise communications in the event of a power failure.\nIn this case, the WAN and LAN are bypassed, transparently protecting network connectivity.\nThis relay establishes a physical connection between the two ports in the bypass pair and forwards traffic whether power is present or not.  <\/p>\n\n<p><strong>Note<\/strong>: Fail-to-Wire is not enabled by default and must be configured via the extended shell using the xgs-ftw command.<\/p>\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-fail-to-wire.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"538\" data-id=\"13480\" src=\"https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-fail-to-wire-1024x538.png\" alt=\"Sophos XGS - Fail-to-Wire\" class=\"wp-image-13480\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-fail-to-wire-1024x538.png 1024w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-fail-to-wire-64x34.png 64w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-fail-to-wire-300x158.png 300w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-fail-to-wire-600x315.png 600w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-fail-to-wire-768x404.png 768w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-fail-to-wire-18x9.png 18w, https:\/\/www.avanet.com\/assets\/sophos-xgs-firewall-fail-to-wire.png 1256w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/figure>\n\n<h2 class=\"wp-block-heading\" id=\"promos\">Promos<\/h2>\n\n<p>Have you come to a decision and would like to purchase a new XGS Firewall? Then don&#8217;t forget to take a look at our promo page first. The discounter Sophos has a suitable promo for almost every scenario. \ud83d\ude05<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I don&#8217;t know about you, but when it comes to products that I use every day and are indispensable to me, I&#8217;m always up to date with the latest developments. This concerns mostly technical devices, but I&#8217;m also a geek. \ud83d\ude04 For all these devices, I follow a clear strategy when it is time to [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":21346,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[277],"tags":[],"class_list":["post-34021","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/34021","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/comments?post=34021"}],"version-history":[{"count":0,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/34021\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media\/21346"}],"wp:attachment":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media?parent=34021"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/categories?post=34021"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/tags?post=34021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}