Listing Thumbnail

    Sophos Cloud Firewall (BYOL)

     Info
    Sold by: Sophos 
    Deployed on AWS
    Sophos Firewall for AWS delivers advanced threat protection for AWS environments and assets. Protect networks, applications, ensure security of ingress and egress traffic, and maintain high web-application availability.
    4.7

    Overview

    Sophos Firewall integrates leading technologies into a single next-generation solution without compromising security. Highlights include deep packet inspection with IPS, ATP, URL filtering, and in-depth reporting; Bidirectional AV for WAF with authentication offloading, path-based routing, country-level blocking; and self-service SSL and HTML5 VPRN technologies to make connecting from anywhere and on any device a reality - without administrative overhead.

    Preconfigured templates and centralized policy management save time managing user, application and network policies, and provide pre-packaged web filtering, IPS, traffic shaping and app control policies for Active/Active and Active/Passive deployments spanning multiple availability zones.

    Sophos synchronized security allows organizations to link endpoints, cloud workloads, and firewall to relay health status and immediately to respond to threats on your network.

    Part of a complete SaaS security platform. A selection of Sophos AWS solutions are included below with more at https://www.sophos.com/en-us/public-cloud .

    If you have questions about Sophos solutions or need assistance with deployment and configuration, contact us at aws.marketplace@sophos.com .

    The cloud formation template to deploy Sophos Firewall will optionally collect Sophos Central account credentials (email and password used to login to https://central.sophos.com ). These credentials are used only once by the firewall to connect to Sophos Central and enable management services. This step is optional, and can be performed at any time after deployment, following the instructions available here.

    Highlights

    • Sophos XG Firewall combines advanced networking controls, protections such as Intrusion Prevention Systems (IPS) and Web Application Firewall (WAF), plus user and application controls. Saving time taken to deploy and integrate multiple products.
    • Web App Firewall (WAF) protects your web apps against common threats like SQL injection and Cross-Site Scripting. Next-Gen Firewall protection and reporting with stateful traffic inspection, Layer-7 application control, secure proxies, and IPS.
    • Sophos Firewall includes extensive reporting. Sophos Firewall provides full insights into user and network activity, surfaced using easy-to-understand indicators so you can take preventive measures before problems occur.

    Details

    Sold by

    Delivery method

    Delivery option
    Sophos Standalone Firewall for AWS
    Sophos Firewall GWLB (Deprecated - use PAYG)

    Latest version

    Operating system
    OtherLinux 22.0 MR2

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Sophos Cloud Firewall (BYOL)

     Info
    Pricing and entitlements for this product are managed through an external billing relationship between you and the vendor. You activate the product by supplying a license purchased outside of AWS Marketplace, while AWS provides the infrastructure required to launch the product. AWS Subscriptions have no end date and may be canceled any time. However, the cancellation won't affect the status of the external license.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    Terminate the EC2 instance(s) at any time to stop incurring charges. You may email aws.marketplace@sophos.com  for questions regarding Sophos XG Firewall charges and refund requests.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Sophos Standalone Firewall for AWS

    This CloudFormation template allows you to deploy a Sophos XG Firewall Standalone. The template will bring up a single XG Firewall instance with two ENI network interfaces attached to the instance, each interface is in a distinct subnet. The first interface is dedicated to the private subnet to be protected by the XG Firewall, the second interface is dedicated to the public/external subnet. The IGW is automatically attache to the public subnet.

    CloudFormation Template (CFT)

    AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."

    Additional details

    Usage instructions

    You can manage your Sophos XG Firewall on AWS from the Web Interface using HTTPS (TCP port 4444), the command shell using SSH (TCP port 22), and via the API.

    Sophos XG Firewall requires a valid email address for administration purposes. This email address is not used for any other purpose and remains local to the Sophos XG Firewall AMI.

    Support

    Vendor support

    Sophos provides technical support via phone and web portal as part of your BYOL subscription. Phone: +1-844-591-2756 Web portal:

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.7
    854 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    81%
    17%
    1%
    0%
    1%
    0 AWS reviews
    |
    854 external reviews
    External reviews are from G2 .
    TUMMALAPALLI A.

    Sophos Firewall Keeps Our University Wi‑Fi Secure and Easy to Manage

    Reviewed on Sep 17, 2026
    Review provided by G2
    What do you like best about the product?
    What I like the best about Sophos Firewall is that it keeps my university Wi-Fi secure while still being easy to use.
    What do you dislike about the product?
    Sometimes it blocks legitimate websites too. That's the only thing I don't like.
    What problems is the product solving and how is that benefiting you?
    It helps protect my university Wi-Fi from unauthorized access and blocks unsafe websites. This gives me a safer and more reliable internet connection for daily browsing.
    Luis D.

    Effective Integration: Firewall and Client/Server Checks in a Single Portal

    Reviewed on Sep 14, 2026
    Review provided by G2
    What do you like best about the product?
    Integration, within a portal, of firewall and client/server verification.
    What do you dislike about the product?
    The management of Access Points is not integrated with VLANs, making network configuration and administration less straightforward.
    What problems is the product solving and how is that benefiting you?
    In the management of clients and on the web applications we try to block
    Shashikant D.

    Sophos Firewall: Easy to Learn, Outstanding Security

    Reviewed on Sep 10, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Sophos Firewall is very simple and easy to understand and maintain. As a security engineer, the simplicity helps me in my daily work. It provides proper updates, and the support from the staff is very good. I learned how to use it in a very short time, which gives me confidence to implement rules effectively.
    What do you dislike about the product?
    Nothing is there I like to dislike the firewall
    What problems is the product solving and how is that benefiting you?
    I use Sophos Firewall for security and network segmentation. It's very simple and easy to understand, making it quick to learn and implement. I shifted from older legacy firewalls due to its excellent support and updates, providing a secure environment.
    Mahendra P.

    Sophos: Reliable Performance and Feature-Rich Security

    Reviewed on Sep 10, 2026
    Review provided by G2
    What do you like best about the product?
    Sophos is a very good product. It offers multiple useful features, and we have been using it since 2018. So far, it has been working very well for us without any major issues or trouble. We are very satisfied with its performance and reliability.
    What do you dislike about the product?
    We require the option to keep one previous firmware version available as a backup to ensure the security and stability of the product.
    What problems is the product solving and how is that benefiting you?
    Sophos Firewall provides very good security. The number of external attacks has significantly decreased due to the effective IPS/IDS engine of the Sophos Firewall
    Aayushi J.

    Synchronized security is a game changer.

    Reviewed on Aug 26, 2026
    Review provided by G2
    What do you like best about the product?
    The level of network visibility and the implementation of the Xstream architecture stand out immediately. Having the Xstream Deep packet inspection DPI engine handle AV, IPS, Web Filtering, and app control in a streamlined architecture keeps throughput high even under heavy loads and heavy TLS 1 .3 inspection. From an administrator's daily workflow, synchronized security is a game-changer. The way the firewall communicates directly with endpoint agents to share health heartbeats and automatically isolate compromised machines cuts down incident response times significantly. Additionally, managing multiple distributed appliances through sophos central simplifies everything from firmware pushes backups to group rule management. The built-in SD-WAN orchestration and multi-path performance routing have also made multi-branch connectivity much more reliable.
    What do you dislike about the product?
    The unified policy paradigm-while powerful once you get used to it-takes some time to master if you are migrating over from traditional zone-and-rule firewalls like Cisco ASA or FortiGate. Finding specific NAT configurations embedded within or alongside standard firewall rules can feel slightly non-intuitive during the initial setup phase. Furthermore, initial fine-tuning of deep TLS decryption policies requires careful exception-building to prevent breaking internal web apps or line-of-business software, though the built-in pre-packaged exception lists help mitigate this.
    What problems is the product solving and how is that benefiting you?
    We primarily use it for perimeter defense, secure site-to-site SD-WAN mesh connectivity, and granular user-based application access control. It has solved issues regarding shadow IT visibility and encrypted threat blind spots. The automation features-such as active threat response tied back to endpoint logs-have lifted a heavy operational burden off our lean IT Security team.
    View all reviews