Listing Thumbnail

    Sophos Cloud Firewall (BYOL)

     Info
    Sold by: Sophos 
    Deployed on AWS
    Sophos Firewall for AWS delivers advanced threat protection for AWS environments and assets. Protect networks, applications, ensure security of ingress and egress traffic, and maintain high web-application availability.
    4.6

    Overview

    Sophos Firewall integrates leading technologies into a single next-generation solution without compromising security. Highlights include deep packet inspection with IPS, ATP, URL filtering, and in-depth reporting; Bidirectional AV for WAF with authentication offloading, path-based routing, country-level blocking; and self-service SSL and HTML5 VPRN technologies to make connecting from anywhere and on any device a reality - without administrative overhead.

    Preconfigured templates and centralized policy management save time managing user, application and network policies, and provide pre-packaged web filtering, IPS, traffic shaping and app control policies for Active/Active and Active/Passive deployments spanning multiple availability zones.

    Sophos synchronized security allows organizations to link endpoints, cloud workloads, and firewall to relay health status and immediately to respond to threats on your network.

    Part of a complete SaaS security platform. A selection of Sophos AWS solutions are included below with more at https://www.sophos.com/en-us/public-cloud .

    If you have questions about Sophos solutions or need assistance with deployment and configuration, contact us at aws.marketplace@sophos.com .

    The cloud formation template to deploy Sophos Firewall will optionally collect Sophos Central account credentials (email and password used to login to https://central.sophos.com ). These credentials are used only once by the firewall to connect to Sophos Central and enable management services. This step is optional, and can be performed at any time after deployment, following the instructions available here.

    Highlights

    • Sophos XG Firewall combines advanced networking controls, protections such as Intrusion Prevention Systems (IPS) and Web Application Firewall (WAF), plus user and application controls. Saving time taken to deploy and integrate multiple products.
    • Web App Firewall (WAF) protects your web apps against common threats like SQL injection and Cross-Site Scripting. Next-Gen Firewall protection and reporting with stateful traffic inspection, Layer-7 application control, secure proxies, and IPS.
    • Sophos Firewall includes extensive reporting. Sophos Firewall provides full insights into user and network activity, surfaced using easy-to-understand indicators so you can take preventive measures before problems occur.

    Details

    Sold by

    Delivery method

    Delivery option
    Sophos Standalone Firewall for AWS
    Sophos Firewall GWLB (Deprecated - use PAYG)

    Latest version

    Operating system
    OtherLinux 22.0 GA

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Sophos Cloud Firewall (BYOL)

     Info
    Pricing and entitlements for this product are managed through an external billing relationship between you and the vendor. You activate the product by supplying a license purchased outside of AWS Marketplace, while AWS provides the infrastructure required to launch the product. AWS Subscriptions have no end date and may be canceled any time. However, the cancellation won't affect the status of the external license.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    Terminate the EC2 instance(s) at any time to stop incurring charges. You may email aws.marketplace@sophos.com  for questions regarding Sophos XG Firewall charges and refund requests.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Sophos Standalone Firewall for AWS

    This CloudFormation template allows you to deploy a Sophos XG Firewall Standalone. The template will bring up a single XG Firewall instance with two ENI network interfaces attached to the instance, each interface is in a distinct subnet. The first interface is dedicated to the private subnet to be protected by the XG Firewall, the second interface is dedicated to the public/external subnet. The IGW is automatically attache to the public subnet.

    CloudFormation Template (CFT)

    AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."

    Additional details

    Usage instructions

    You can manage your Sophos XG Firewall on AWS from the Web Interface using HTTPS (TCP port 4444), the command shell using SSH (TCP port 22), and via the API.

    Sophos XG Firewall requires a valid email address for administration purposes. This email address is not used for any other purpose and remains local to the Sophos XG Firewall AMI.

    Support

    Vendor support

    Sophos provides technical support via phone and web portal as part of your BYOL subscription. Phone: +1-844-591-2756 Web portal:

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.6
    605 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    80%
    17%
    2%
    0%
    1%
    0 AWS reviews
    |
    605 external reviews
    External reviews are from G2 .
    Mahesh C.

    Strong Admin Capabilities and Feature-Rich Sophos Firewall

    Reviewed on Apr 08, 2026
    Review provided by G2
    What do you like best about the product?
    Sophos firewall offers strong administrative capability, with easy implementation and plenty of useful features. It includes options such as ISP load balancing, a DHCP server, web filtering, and application filtering, among others.
    What do you dislike about the product?
    The licensing costs for some services should be included and built in.
    What problems is the product solving and how is that benefiting you?
    We use Sophos Firewalls in HA mode for a range of services, including inter-school connectivity via IPsec, web filtering, application filtering, and daily reports. We also rely on them for notifications and other related functions.
    Jitendra Kumar P.

    Robust UTM with Free SSL VPN and MFA Authentication

    Reviewed on Apr 06, 2026
    Review provided by G2
    What do you like best about the product?
    It offers UTM features, along with a free SSL VPN and MFA authentication.
    What do you dislike about the product?
    HA failover is not working properly. It is impacting production because the failover is failing.
    What problems is the product solving and how is that benefiting you?
    SSL VPN with MFA, plus flawless UTM features. We use this firewall as our core firewall, and all of our internal servers sit behind it.
    William E.

    Cloud-Managed, But Lacking Modern Network Management Improvements

    Reviewed on Mar 31, 2026
    Review provided by G2
    What do you like best about the product?
    Sophos Firewalls has two major advantages: it’s a cloud-managed firewall, and it provides good customer-facing reports.
    What do you dislike about the product?
    Sophos firewalls haven’t changed much in terms of functionality in years. The configuration may come with a newer UI, but underneath it still feels like the same basic firewall.

    What’s been most frustrating for me is that there still isn’t a straightforward way to manage VoIP—an extremely common part of any modern network—without having to drop into the CLI backend and disable VoIP inspection. It ends up being an all-or-nothing setting: either it’s on or it’s off.

    I’ve run into a similar limitation with DHCP options. Yes, the feature exists and it has been added, but it’s still very basic and doesn’t really support more modern management approaches for other devices, like Unifi APs.
    What problems is the product solving and how is that benefiting you?
    We initially deployed Sophos Firewall because we needed a way to manage firewalls in remote geographic locations where we couldn’t dispatch a technician. It also provided customer reports that met our clients’ requirements, which was an important part of why we chose it.
    Stefan N.

    Sophos Firewall in Education

    Reviewed on Mar 12, 2026
    Review provided by G2
    What do you like best about the product?
    Integrates with Sophos antivirus to provide a unified management console.
    What do you dislike about the product?
    Logs are only really viewable using a 3rd party tool
    What problems is the product solving and how is that benefiting you?
    We currently run two Sophos firewalls in an active/passive high-availability configuration. This setup automatically fails over between the two units if our internet service provider experiences an outage.
    William G.

    Complete traffic control with robust policies, NDR, and DNS protection

    Reviewed on Mar 10, 2026
    Review provided by G2
    What do you like best about the product?
    It is a very comprehensive device that helps perform all traffic control. It features robust policies for web control and application control. Additionally, with its new NDR utilities and DNS protection, it proves to be very useful.
    What do you dislike about the product?
    Some reports are a bit complex to understand, which is why it is necessary to download different ones to be able to understand the threat.
    What problems is the product solving and how is that benefiting you?
    When a company does not have a firewall to monitor all traffic, perform robust inspection, balance the load, create SD-WAN routes, and establish VPN connections, it becomes difficult to maintain control and security of the network.
    View all reviews