My new homelab Firewall is insane! // Sophos XGS 2100

  Рет қаралды 52,548

Christian Lempa

Christian Lempa

Күн бұрын

Пікірлер: 246
@chriscarvajal7543
@chriscarvajal7543 2 жыл бұрын
Love Sophos. I had an XG85w until recently upgraded to the XGS 87w. Very pleased with the ability to configure and secure my home network.
@christianlempa
@christianlempa 2 жыл бұрын
So cool to hear that :)
@deephousefridays1911
@deephousefridays1911 2 жыл бұрын
can you use the free home version on it ?
@mariotubelecce
@mariotubelecce 2 жыл бұрын
this is the overkillest overkill of all homelab videos!
@christianlempa
@christianlempa 2 жыл бұрын
Yeah 😆
@umair-altaf
@umair-altaf 2 жыл бұрын
I think you are right, but it is still good to have such fw at home and not only in data centers
@svettnabb
@svettnabb 2 жыл бұрын
That is a juicy piece of gear. Sophos with Zero trust (using the endpoint health/heartbeat) is nice functionality. Sophos also have network switches now.
@christianlempa
@christianlempa 2 жыл бұрын
Oh yeah, guess which switch will be added soon to my lab!
@kevinyu9934
@kevinyu9934 2 жыл бұрын
This is very helpful. I adopted Sophos XG as my main firewall now. Thanks for the amazing content!
@christianlempa
@christianlempa 2 жыл бұрын
Cool to hear! Thanks ;)
@justinrutledge1221
@justinrutledge1221 Жыл бұрын
Whether or not you the viewer like Sophos or not, it sure is refreshing to see a "home lab" that isn't just a copy cat of someone else's Unifi crap. I have used Sophos off and on for several years and I have to agree with Christian on their current quality and feature set. Yes, the XG vs UTM debate will rage on for years, but they are making steady progress.
@canadianwildlifeservice8883
@canadianwildlifeservice8883 Жыл бұрын
The feature set is unsurpassed by any other free firewall, but the UI of the web filter is worse than anything imaginable
@Traumatree
@Traumatree 11 ай бұрын
@@canadianwildlifeservice8883 My home lab is setup with Fortigate + Fortiswitch + FortiAP and I can assure you it surpasses what Sophos offer by a mile. At a cost though.
@MelroyvandenBerg
@MelroyvandenBerg 6 ай бұрын
I hate unifi so much 😅
@Wahinies
@Wahinies 5 ай бұрын
​@canadianwildlifeservice8883 *laughs in Fortigate*
@gswhite
@gswhite 2 жыл бұрын
Great video, thanks. I run Unifi UDM Pro with their AP's. Very happy. I run pFsense before, and was very happy with the solution.
@christianlempa
@christianlempa 2 жыл бұрын
Sounds great as well!
@MichaelSmith-fg8xh
@MichaelSmith-fg8xh 2 жыл бұрын
What's been the experience going from pfsense to Unifi for routing?
@gswhite
@gswhite 2 жыл бұрын
pFsense is a much more efficient and more rounded firewall/router than UDM Pro. Unifi is not as accomplished at routing over pFsense. But over the last year UniFi have made significant improvements to function and the interface. You can’t beat UniFi for their equipment either. Their WiFi 6 kit and switches are superb and I work in I.T. Their SDN approach for their kit is spot on and I am very happy with it. Having a single cohesive platform is nice. I have often thought of placing a pFsense in front of my UDM Pri but the would have double NAT issues. I do love pFsense though and now they offer the advanced license for free for home users it is tempting to go back
@AddiComedy
@AddiComedy 11 ай бұрын
I would love to pick your mind on security, you're one of the only knowledgeable sophos channels. 🌟
@christianlempa
@christianlempa 11 ай бұрын
thank you so much :)
@Glatze603
@Glatze603 2 жыл бұрын
Realy great Christian and thanks a lot for your time and your expertise! I love the Sophos XG functions ips, web filtering and app control. I use a Sophos XG as my second firewall in my homelab (lan > opnsense > dmz > sophos xg > internet) - ok, this is what the bsi recommends in case you have systems in a dmz (cgnat-connection) and that´s not a typical homelab infrastructure, but I like to do things a little bit more secure and it works very good.
@christianlempa
@christianlempa 2 жыл бұрын
Thank you so much! It's great to do this in a homelab, and I think it's important for everyone who runs a server. Maybe a bit overkill, but as you correctly said - we like to do things a bit more secure :)
@Bob-i4x5x
@Bob-i4x5x Жыл бұрын
Hey Christian, out of curiousity, can you tell me what the hardware specs are on the XGS2100 (e.g. open an advanced shell and run "cat /proc/cpuinfo" "cat /proc/meminfo". I only ask because the XG/SG series have pretty standard x86_64 Intel architecture (e.g. I have an XG210 w/a Celeron G3900 & 8GB RAM), and I am curious what has changed with the XGS series. Thanks!
@TH3S3R4PH
@TH3S3R4PH 2 жыл бұрын
Im using the virtual appliance of sophos for many years now... Great stuff also with HA and so on
@christianlempa
@christianlempa 2 жыл бұрын
Cool! HA is nice
@mrd4233
@mrd4233 2 жыл бұрын
Nice demo and extreme powerful firewall for homelab!
@christianlempa
@christianlempa 2 жыл бұрын
Thanks mate!
@Mr..E..
@Mr..E.. 2 жыл бұрын
Amazing video, very detailed. Much appreciated!
@christianlempa
@christianlempa 2 жыл бұрын
Thanks :)
@emilnaklicki6837
@emilnaklicki6837 Жыл бұрын
Cool video. Just curious, why not go with the sophos switch at this point. It would make for an interesting video as well. I'm curious if that would be managed from the firewall like Fortinet does it.
@AdHdEntertainmentLLC
@AdHdEntertainmentLLC 2 жыл бұрын
I am planning my first homelab for Cybersecurity research so plan on new firewall and server builds.
@christianlempa
@christianlempa 2 жыл бұрын
Cool!
@Gnanmankoudji
@Gnanmankoudji Жыл бұрын
Hi! Is the XGS 2100 noisy? Our rack is not in a soundproof room, so it could be a problem if it's noisy.
@mihawk3302
@mihawk3302 5 ай бұрын
This video is so good. Thanks!
@christianlempa
@christianlempa 5 ай бұрын
Glad you liked it!
@vasquezmi
@vasquezmi Жыл бұрын
Hello sir I recently purchased a used Sophos XG300 series. I wanted to inquire about some of the reporting and identity features in zenarmor. Are there comparisons in sophos or are those licenses we would have to purchase.
@procheeseburger_2
@procheeseburger_2 2 жыл бұрын
love it! if I didn't get to use a Paloalto I'd be looking at both PFsense and Sophos
@christianlempa
@christianlempa 2 жыл бұрын
Thanks mate! Paloalto and PFSense are also great btw :)
@aflawrence
@aflawrence Жыл бұрын
I just rewatched this as I was able to get a Sophos 210XG hardware appliance, I am really curious if you have some ideas or links to explore setting up rules and policies. Also, really interested in your current Sophos setup and rules.
@christianlempa
@christianlempa Жыл бұрын
I’ve done a video about XG on Proxmox, maybe that’s helping you
@RealLordy
@RealLordy 2 ай бұрын
What is the cost of running the appliance on a yearly basis (on license level)? Note: asking this before having seen the complete video
@christianlempa
@christianlempa 2 ай бұрын
The base license is included, only if you need full protection or additional features you have to pay. That's why I would recommend running the SFOS software on an intel-based computer or in a VM, it's cheaper and you got all the features from the home version for free ;)
@DerTim
@DerTim 2 жыл бұрын
I have a question: I have a Portainer Setup online for beta features, but I would like to use an SSO especially for apps like the registry frontend from Konrad Klein. Is there a simple ready-for-prod solution to use for this? I use nginx as reverse proxy. ;)
@Marc-td7nn
@Marc-td7nn Жыл бұрын
Can you buy just the appliance and then load the homeuser free license?
@christianlempa
@christianlempa Жыл бұрын
You can, but you need to erase the disks and reformat it with the software iso
@canadianwildlifeservice8883
@canadianwildlifeservice8883 Жыл бұрын
​​@@christianlempa is the XGS supported by ESXi free edition....that you are aware of? Proxmox has all the features but many users are only familiar with VMware.
@Bob-i4x5x
@Bob-i4x5x Жыл бұрын
@@canadianwildlifeservice8883 I'm not sure that question makes any sense. XG Home software can probably run on anything that can emulate a standard x86_64 desktop architecture, but the XGS is a hardware platform.
@canadianwildlifeservice8883
@canadianwildlifeservice8883 Жыл бұрын
@@Bob-i4x5x let me rephrase it. Does ESXi support installation on the XGS firewall appliance? Yes the firewall software ISO can be installed within ESXi, but does ESXi support the hardware of the XGS? Proxmox can run on anything, but VMware has more limited hardware support.
@Bob-i4x5x
@Bob-i4x5x Жыл бұрын
@@canadianwildlifeservice8883 Gotcha, that is a much more niche question. Seems to me, at this point, XGS hardware, being current, would be an overly expensive server base. My guess is that, with the x-stream offload chip that things are a bit more proprietary than the SG/XG hardware.
@t4ir1
@t4ir1 2 жыл бұрын
It would be interesting to know if you get more features on the hardware appliance then you get with the home version? I really like this appliance but I am not sure about license costs, what is included in the free part and what you have to pay on the side. I'd like to make use of IPS definitely and the WiFi ecosystem, but I don't want to have to pay an yearly license for it.
@christianlempa
@christianlempa 2 жыл бұрын
The features are actually the same, there is a small difference in IPS signatures based on the appliance sizing, but the home license covers everything. It's however not possible to run the home license on Hardware models and it's limited to 4cpus and 6gb mem.
@t4ir1
@t4ir1 2 жыл бұрын
@@christianlempa thanks! Does this mean that if I get the hardware appliance, IPS is also included (with more signatures)? I saw that it was part of the network protection licensing package and I was not sure about costs.
@roya2045
@roya2045 2 жыл бұрын
Hi can you make videos on elastic search cloud to monitoring networks. Please reply
@christianlempa
@christianlempa 2 жыл бұрын
Puh maybe, yeah in the far future
@HerzGegenFame
@HerzGegenFame 2 жыл бұрын
Great video and showcase of the Sophos XG features! In my experience u should avoid bridges in Sophos or other firewall devices that don't have dedicated switch chips. For a homelab it's fine, but i wouldn't deploy bridges in prod since CPU switching has higher latency. Keep up the great work :)
@christianlempa
@christianlempa 2 жыл бұрын
Thanks mate! Great feedback. Btw bridges will be removed once I upgrade to my new Switch, guess which one it will be 😀
@HerzGegenFame
@HerzGegenFame 2 жыл бұрын
@@christianlempa Budget options that come to mind are the CRS317 If u only need 16 sfp+ cages or the CRS328-24P-4S+RM for poe and sfp+ :D
@TritonB7
@TritonB7 2 жыл бұрын
Agreed and great advice.
@christianlempa
@christianlempa 2 жыл бұрын
I've done a test with 10Gbit, as I now finally have one in my PC. And you're absolutely right, it seems the bridge interface is taking down the performance from 9.5Gbit to 6.5Gbit, which is really heavy! Btw, I'll test the new Sophos Switch in the Setup, then I can get rid of all bridge ports, luckily :)
@HerzGegenFame
@HerzGegenFame 2 жыл бұрын
@@christianlempa didn't even know that they released a Switch ^^ We are only working with the FWs. Looking forward to it
@zaluq
@zaluq 2 жыл бұрын
Still getting slow internet with Sophos XG even with no filtering , Pfsense ?
@salat
@salat 2 жыл бұрын
Is that short "includes paid promotion" enough? Since you work for Sophosin Germany, shouldn't there be a big "DAUERWERBESENDUNG" displayed in the corner? :)
@christianlempa
@christianlempa 2 жыл бұрын
Good question, probably more for a lawyer than me. I'm committed to mark it as a "promotion/advertisement" as long as I receive products without paying for them, or if I'm paid for making a video. But as far as I know, it is no clear regulation on how exactly that is needed in Germany, so therefore you might see many people who include a "DAUERWERBESENDUNG" banner, but it's just one way to handle this. And it was very common before youtube added the checkbox to mark a video as "paid promotion".
@n3m3f3
@n3m3f3 2 жыл бұрын
Love Sophos!
@parl-88
@parl-88 2 жыл бұрын
Great Video. Thanks sir!
@christianlempa
@christianlempa 2 жыл бұрын
Thanks np :)
@Spydaw
@Spydaw 2 жыл бұрын
Great video, thank you it was really insightful!
@christianlempa
@christianlempa 2 жыл бұрын
Thank you! Glad you liked it :) Btw, I'm thinking about a future k3s video and use it as a load balancer, let's see how that works :D
@Spydaw
@Spydaw 2 жыл бұрын
@@christianlempa Oh yea, that would be an awesome video, can't wait ;)
@anthonyjhicks
@anthonyjhicks 2 жыл бұрын
I'd love if you explained how to create security within local IPv6 networks rather than IPv4. I feel the IPv4 VLAN layer 2 is well explained, however I do not see how to achieve that security between separated subnets with IPv6 or even how to approach it correctly. As a result I end up with falling back to our old dated IPv4 approach - running seven IPv4 VLANs at home for Clients, Servers, Container, DMZ, IoT, Guest and VPN. How do I get that separation on IPv6? Sophos looks interesting but so IPv4 :)
@christianlempa
@christianlempa 2 жыл бұрын
Thank you so much! And great feedback :) I've not looked too deeply into IPv6, but that reminds me of doing that at some point!
@nate806
@nate806 2 жыл бұрын
Are you using a commercial license or home license? Do you have access to a partner to purchase the equipment?
@christianlempa
@christianlempa 2 жыл бұрын
I'm using the commercial license, the home isn't available for hardware appliances.
@dl2085
@dl2085 2 жыл бұрын
Can this firewall also work as an external load balancer for a kubernetes ingress controller? Similar to Kemp or haproxy?
@christianlempa
@christianlempa 2 жыл бұрын
I’m using a simple dnat rule which kinda does some load balancing between the nodes, if that’s what you’re asking.
@aallvvii99999999
@aallvvii99999999 2 жыл бұрын
Hi, Really nice video. Just a quick question, i bought used sophos xg 210 firewall now i want to transfer the device registration under my account. Unfortunately i am not able to contact current device registerar. Is there any way i can register the device under my account and enable evaluation licence as i will use it for my home network only. Thx
@RenaudSchweingruber
@RenaudSchweingruber 4 ай бұрын
Asking myself about physical XGS 2100 or 136 for my homelab or home version (4c, 6GB) virtualized on proxmox on a beefy i5-14500. Any advice ?
@christianlempa
@christianlempa 4 ай бұрын
A virtual firewall is less power hungry, but also less flexible and dependent on the hypervisor host. I prefer running a firewall outside of the hypervisor, but both are viable solutions
@darkjake80
@darkjake80 Жыл бұрын
Hey, Question for you. Are you using Sophos Home Edition Firewall or are you using a full enterprise license? I have a Sophos XG125 and am looking to switch to Sophos Firewall Home so I don't have to pay any license fees.
@christianlempa
@christianlempa Жыл бұрын
I’m using their enterprise license, but what you can do is flash the XG125 with the software version, make sure to erase all the partitions with gparted first. Then you can use the home license :)
@darkjake80
@darkjake80 Жыл бұрын
@@christianlempa To install Sophos Home on an XG125, I need to wipe my appliance clean? I tried to install without wiping it and that did not work. Based on your last comment, clearing the partitions is essential?
@christianlempa
@christianlempa Жыл бұрын
@@darkjake80 yes
@PowerUsr1
@PowerUsr1 2 жыл бұрын
To be clear without TLS decryption, MITM yourself, Sophos is not doing anything more than what Suricata on PFsense is doing. Best case pattern matching on secure traffic. The flexibility to assign different L7 policies per interface is lacking on both pfsense and OPNsense which is really strange but there are additional apps like Sensei that can fill the gap.
@ig00g1e
@ig00g1e Жыл бұрын
Wish more people knew this. Many implementors of this technology don'tadequately articulate the fine point. Meanwhile SMBs are paying 10s and thousands in licensing fees.
@mejohnm
@mejohnm 2 жыл бұрын
I have a question. How loud is the XGS 2100? I have my cabinet right next to my desk in my living room.
@mejohnm
@mejohnm 2 жыл бұрын
I heard you mention the firewall in another video that you can hear it from your small room next to your work room. Is it really that loud?
@MadChristianX
@MadChristianX 2 жыл бұрын
Is it possible to use this firewall with a free home license in a homelab? if yes are there any performace drops?
@BenGillam
@BenGillam 2 жыл бұрын
Nice setup, did you buy the firewall or did Sophos supply for the channel? Not the cheapest! Quite a bit of kit just sold this model to a client to install in a couple of weeks on a new site looking forward to seeing what difference the extra horse powder in the XGS line brings
@christianlempa
@christianlempa 2 жыл бұрын
Yeah the XGS has a lot of improvements to accelerate the traffic. Btw I got the devices for testing, as I'm working for this company.
@BenGillam
@BenGillam 2 жыл бұрын
@@christianlempa look forward to seeing more videos. Nice jacket too just noticed :) might have to hit up our account manager for some swag
@HisLoveArmy
@HisLoveArmy 2 жыл бұрын
Can you do active / active with two WANS?
@christianlempa
@christianlempa 2 жыл бұрын
Yes
@epictetus9766
@epictetus9766 2 жыл бұрын
Wow, that's a decent bit of kit. How do you find the performance vs your virtual machine? I've got a Sophos XG, on Proxmoxx (setup with your video), that has 4 10900K cores and 6GB RAM - it doesn't do very well with all the security features turned on.
@christianlempa
@christianlempa 2 жыл бұрын
I've not done any performance comparisons, but the XGS series has a specific processor that is used for the dpi computing, traffic offloading, etc. That has a huge performance improvement when using the security features, depends a lot on the use case, but it can be much faster than any other cpu. However, security features like IPS, SSL inspection can make a 10gbit/s to something like 2.5-3gbit/s, that is "normal" and expected.
@canadianwildlifeservice8883
@canadianwildlifeservice8883 Жыл бұрын
Amazing that you can use Sophos on any PC, and add NIC cards to it to make it just like an XGS appliance. Be aware that the home license only supports up to 4 CPU cores and up to 6Gb of ram.
@christianlempa
@christianlempa Жыл бұрын
+1!
@derek400004
@derek400004 2 жыл бұрын
Hello! Can I ask if the XGS 2100 will be able to maximize a gigabit internet connection? I see some people benchmark the next level down (the XGS 136) and that firewall barely maintains 600 Mbps when NGFW settings are turned on, even if there is only 1 firewall rule and 1 wired user.
@balla2172
@balla2172 2 жыл бұрын
Do you need tobpay a fee for it to function?
@christianlempa
@christianlempa 2 жыл бұрын
Not for the basic functions, only for advanced features.
@michaelloving8004
@michaelloving8004 2 жыл бұрын
I'm running Sophos XG v19 on a hp dl380 g7 8gb ram raid 5 storage
@shetuamin
@shetuamin 2 жыл бұрын
Good demo. Thanks. I am waiting for 10g Lan video. I hope so, this will not going very costly.
@christianlempa
@christianlempa 2 жыл бұрын
You're welcome! Well we will see, 10gbit is never cheap
@MichaelSmith-fg8xh
@MichaelSmith-fg8xh 2 жыл бұрын
10gb switches (mikrotik) and NICs are affordable now
@nicholaskorfer8257
@nicholaskorfer8257 2 жыл бұрын
Will there be any disadvantages when I'm running this xgs firewall with an home licence?
@christianlempa
@christianlempa 2 жыл бұрын
The hardware appliance does not run with a home license, that only works on vms or software installations on your own hardware
@tongaexpress
@tongaexpress 2 жыл бұрын
I am really considering an XGS or a PFSense. The issue is I love and already use the Unifi Dream Machine Pro. Is it easy to set up one of those firewalls on the front end then go to the Dream machine?
@MichaelSmith-fg8xh
@MichaelSmith-fg8xh 2 жыл бұрын
Lawrence systems has a video on setting pfsense and udm pro up together. I don't see the good side of having two routers in series like that.
@christianlempa
@christianlempa 2 жыл бұрын
Thanks for sharing, yeah Tom has great videos about that ;) In theory you can combine all of them together (however, it might not make sense), it's just a matter of how you're configuring it.
@ChadHigh09
@ChadHigh09 2 жыл бұрын
Pfsense will not disappoint
@markarca6360
@markarca6360 2 жыл бұрын
I have seen one since it was Astaro (that company merged with Sophos). I have been an intern at a government agency here in the Philippines (They use Astaro Security Gateway, then it was replaced with a Sophos appliance). One of the good things is that it will download large files (such as ISO files), in itself, in order to save on bandwidth.
@christianlempa
@christianlempa 2 жыл бұрын
Cool that you still remember astaro 😉
@lewiskelly14
@lewiskelly14 2 жыл бұрын
How much did they pay you for this ad?
@christianlempa
@christianlempa 2 жыл бұрын
Nothing. I just genuinely like the products. I got the devices for free, regardless of making a video or not.
@blancfilms
@blancfilms 2 жыл бұрын
@@christianlempa My opinion: In videos like this you should disclose that you work for Sophos (for transparency sake)
@salat
@salat 2 жыл бұрын
He works at Sophos Germany.. :)
@scholziallvideo
@scholziallvideo 2 жыл бұрын
hi, perfect video. i use sophos xg in the datacenter where my virtual systems running. And a sophos xg on an intel nuc with 2 etherenet ports at home :)
@christianlempa
@christianlempa 2 жыл бұрын
Thanks again :)
@alonzosmith6189
@alonzosmith6189 2 жыл бұрын
Nice, something other than Unifi and Pfsense gateways. Thanks for sharing
@christianlempa
@christianlempa 2 жыл бұрын
Np! Glad you liked it
@RobinSimon105
@RobinSimon105 2 жыл бұрын
The XG Hardware Appliances are great .. but i prefer the UTM Firewall.. theses zones makes me crazy .. if there is more than a bunch of Destination NAT-Rules. And where is the Reverse Proxy for real webservers on the same https port? Also Running my UTM on an Dell R720 virtually. Like it! 😍
@christianlempa
@christianlempa 2 жыл бұрын
I think the Zone concept is great and makes things a lot easier, but yea it does need to time to get used to if you're coming from UTM ;)
@JasonsLabVideos
@JasonsLabVideos 2 жыл бұрын
Do you run Sophos Home XG on your 2100 ?
@christianlempa
@christianlempa 2 жыл бұрын
No, I'm using a hardware license.
@JasonsLabVideos
@JasonsLabVideos 2 жыл бұрын
@@christianlempa That sounds very pricy.
@elmeromero303
@elmeromero303 2 жыл бұрын
Good Video. Thanks. I was using it since it was called Astaro - a German Company that was buyed by Sophos. For Home Lab purpose i (would) use the free Version on a good Hardware Appliance. Not everyone has a Budget of several thousand EUR/USD for the expensive yearly license subscriptions. Maybe you can make a Video of a DIY Appliance with the free Sophos Version?
@christianlempa
@christianlempa 2 жыл бұрын
Yeah, I worked in the old offices of Astaro after they go aquired, very cool team! Maybe I'll do another video about the Home Version at some point, but IDK yet
@thecamtechh
@thecamtechh 10 ай бұрын
Nice, how much is it ?
@christianlempa
@christianlempa 10 ай бұрын
Cool! Honestly... I don't know :D
@marcuslindberg1279
@marcuslindberg1279 2 жыл бұрын
Pfsense is the way to go 😉
@christianlempa
@christianlempa 2 жыл бұрын
Pfsense is great, but it's good to have some choices isn't it? :D
@BrianDilks
@BrianDilks 2 жыл бұрын
Great video. Would love to see some more budget friendly hardware options as well.
@christianlempa
@christianlempa 2 жыл бұрын
Thanks :) you can just use the home version on a PC or VM for a budget option
@JasonsLabVideos
@JasonsLabVideos 2 жыл бұрын
Good luck with that Sophos is a CPU intense piece of software.
@JasonPhillipsXeariaN
@JasonPhillipsXeariaN 2 жыл бұрын
Wow man. Your home Sophos is overkill. My company has used XG115s and XG125s for small to medium sized businesses 10-100 people 100+ devices for years with no issues. We are running XG210s in HA for COLO server/VOIP applications, and XGS3100 in HA for larger business 100+ people 1000+ devices. I'm certified as a Sophos Architect and I just use a Sophos home license on an old Datto NUC type box. Never had an issues either. That license gets me all the features I actually use. No need for NFR renewals like I had to do when I had actual Sophos hardware.
@christianlempa
@christianlempa 2 жыл бұрын
Cool! Another Sophos fan :)
@Maxzier14
@Maxzier14 Жыл бұрын
hi i need advice my hospital plans to buy sophos with an xtrean license and web server protection with 300-500 devices I wonder what series? is xgs 2300 enough or xgs3300?
@JasonPhillipsXeariaN
@JasonPhillipsXeariaN Жыл бұрын
@@Maxzier14 That is hard to answer without knowing your environment and your needs. Do you have an estimation of the throughput, and services that you will need to enable on the firewall? That is going to be your biggest issues with size. As you enable services like IPS, HTTP/HTTPS/FTP/Web Filtering, Advanced Threat (If licensed), Web Server Protection (etc...). It really starts to eat in to your throughput and will slow down all traffic. This can really be a problem if your WAN connection(s) are faster. This could be as little as a 200+ Mbit connection. You can start to lose a lot of your speed when you enable filtering services. Is is also possible see slower internal zone speeds even if those services aren't enabled for them. From a security and compliance standpoint. I recommend that you use as much of the filtering options as you have available. We had this issue several times when newer connections became available. We could only get less than 200 Mbit speed out with some of the gen.1 and gen.2 XG's with the Web Filtering/HTTP/HTTPS/FTP services turned on. Luckily the XGS offloads "trusted" with traffic due to the xstream routing and doesn't scan it. That does help with overall throughput. I would still size to your overall need without considering the offloading just to be safe. If you have a Sophos login. They have an assisted sizing guide. It's called the Firewall Sizing Calculator. If not there is a PDF sizing guide available. You will have to do some of your own calculations based on estimated connection count and throughput numbers. Sophos will always try to oversize you when recommending firewalls. You should be able to get a pretty good idea what you really need by adding up the estimated throughput needs compared to the charts though. Also something else you need to consider since you are a hospital, and any downtime is probably not acceptable. You need to be in HA (High availability). That is two+ firewalls active at any time. You have different HA option that can affect your traffic too. You can have traffic flowing out of multiple firewalls, or just have one live and the rest backup. The HA is necessary to guarantee uptime. All firmware updates require a reboot. If you are in HA. The live one(s), or primary depending on your config will update its firmware, transfer traffic to one of the other firewalls. When the primary comes back up, each will update its own firmware by priority. You won't see any downtime. Hope that was helpful. You can talk to your sales rep, and they should work with you, or get an engineer involved. Just remember they will try to oversell to you. It helps to have an idea of your actual needs.
@FYDanny
@FYDanny 2 жыл бұрын
Im using Sophos XG210 more than 2 years at my home. Now running with XGS2300😆
@epictetus8028
@epictetus8028 2 жыл бұрын
Very nice! Do you put the home licence on that hardware?
@Caphaldor94
@Caphaldor94 2 жыл бұрын
I'd love to get my Hands on one of these...I'll even take one of the Desktop Models :D. Currently running a virtual v19 one infront of my "Homelab" Server (rented at Hetzner).
@christianlempa
@christianlempa 2 жыл бұрын
Wow cool! I still need to update mine to v19 😆
@Caphaldor94
@Caphaldor94 2 жыл бұрын
@@christianlempa Got the v19 briefing webinar at my old Job and used the EAP immediatly. Still need to get a hardware for the Home, redundant internet connections in the near Future.
@stefandietzel5024
@stefandietzel5024 2 жыл бұрын
I‘m happy, when our Sophos Firewalls are replaced with Forti. 🙂
@christianlempa
@christianlempa 2 жыл бұрын
Ouch, I don't want to hear that 😉
@BallerBubi
@BallerBubi 2 жыл бұрын
Nice one christian! Who doesn't love a bit of an overkill on the home network :) How did or would you handle guest WiFi with the Sophos access points?
@christianlempa
@christianlempa 2 жыл бұрын
Thank you! Absolutely, we like to go crazy on home labs :D I'm not running a Gues WiFi at Home, but it's pretty easy to do that. The usual WiFi can be "bridged to AP LAN", which will just bridge all WiFi clients to the LAN zone. You can also create another wifi network as a separate zone, this will be a separate interface you can put in a different zone and control with firewall rules seperately. That's how you typically set up a Guest WiFi, you can also think about adding hotspots and vouchers to that. Hope that helps ;)
@zachfenton608
@zachfenton608 2 жыл бұрын
Sehr schön.
@christianlempa
@christianlempa 2 жыл бұрын
Danke :)
@NiceDevil
@NiceDevil 2 жыл бұрын
Nice video as always... unfortunately the Sophos XG isn't as good as the UTM from the past :/ it lacks a lot of features... just one stupid missing thing "NTP Server"... yep you read right, the XG isn't providing the NTP service for your lab. The XG got a RevProxy but can't do LetsEncrypt... realy strange the decisions Sophos made, especially with their support right now. That is just my experience so far (using a XG right now virutalized in home lab for testing, and UTM SG210 at company)... Nice to have the new next gen features but not at the cost of "standard stuff"
@christianlempa
@christianlempa 2 жыл бұрын
Can absolutely understand what you're saying. However XG has some nice features UTM doesn't have, so it always depends on the use case what's really needed.
@Scraptor
@Scraptor 2 жыл бұрын
Haha, erstmal eine 2k Firewall für das Homelab :D Find ich gut das Sophos da auch "kleineren" KZbinrn etwas sponsert. Deine Stromrechnung will ich allerdings nicht :D
@christianlempa
@christianlempa 2 жыл бұрын
Na klar, wenn schon, denn schon! 😀
@salat
@salat 2 жыл бұрын
Er ist doch "Technical Account Manager at Sophos"..
@Scraptor
@Scraptor 2 жыл бұрын
@@salat Ah okay das wusste ich nicht, danke.
@acb9193
@acb9193 2 жыл бұрын
I added Sophos xg free after one of your videos😁
@christianlempa
@christianlempa 2 жыл бұрын
So cool! 😁👍
@msedv5424
@msedv5424 2 жыл бұрын
Sehr geiles Projekt! Wie bekommt meine Sophos ohne Partner zu sein? Vermutlich selbst Partner geworden und das NFR Kit genommen? Auf jeden Fall cool, mehr davon!!
@christianlempa
@christianlempa 2 жыл бұрын
Vielen Dank! Das ist mein Testgerät, da ich dort arbeite ;)
@MaurizioPiraccini
@MaurizioPiraccini 2 жыл бұрын
A 300 users / 4k $ firewall seems excessive for a home lab! I'm considering 2 of them for a mid sized company, to replace 2 watchguard M370.
@christianlempa
@christianlempa 2 жыл бұрын
Oh yeah it's an absolute overkill 😁
@jesusandrade1292
@jesusandrade1292 2 жыл бұрын
I love this video and another sophos XG. I used in my lab and a little clients in a virtual appliance and wow... I LOVE SOPHOS, is soooo better to pfsense, or Meraki Cisco. Thanks for sharing your knowledge and experience. Greetings from Caracas, Venezuela.
@christianlempa
@christianlempa 2 жыл бұрын
Thank you! Glad you liked the video 😀
@nixxblikka
@nixxblikka 2 жыл бұрын
Do you work for sophos?
@christianlempa
@christianlempa 2 жыл бұрын
Yeah that's right. I guess now over 5 years
@erichuddleston4611
@erichuddleston4611 2 жыл бұрын
@@christianlempa me too! Enjoying this company so far 😁
@95923843
@95923843 2 жыл бұрын
I am using Fortigate 30E as my home firewall !
@ricomilland8654
@ricomilland8654 2 жыл бұрын
Nice video, do you know that the Sophos UTM (astaro) is a much more refined and stable product from Sophos,. That system is insanely simple, not confused an ugly like in XGS/Cyberoam, Everyone trying to use multiple vlan's with many rules know that XGS is just a toy and the UTM with the object based setting and rules is a lot better. The gui is older looking yes, but that is actually good thing beacuse it is tested and loved. it i easy to understand. The Cyberoram gui is prety but not usable for much more that wan+lan+dmz - You could make a video comparing the 2 systems
@christianlempa
@christianlempa 2 жыл бұрын
Hm, I don't know, I like the XG interface a lot more than UTM tbh.
@ricomilland8654
@ricomilland8654 2 жыл бұрын
​@@christianlempa The interface is more modern and looks good, but a better network product it is not (in my mind) i will encourage you to compare the features, and actully run them with configs with multiple vlan's multiple rules, countryblocking, waf/letsencrypt, regex There is a lot of features that does not exist in the new one. is is not without reason that the UTM still exist if it got discontinued pepole would go for a Palo Alto or a Fortigate.
@propeto13
@propeto13 2 жыл бұрын
Dell R210 II w/pfsense is still greater than XGS2100 in 2022
@christianlempa
@christianlempa 2 жыл бұрын
Well, that's just like your opinion man
@Martin-lo4kb
@Martin-lo4kb 2 жыл бұрын
Have you tried the IPv6 capabilities of the Firewall? IPv6 is poorly implemented in most Firewalls.
@MichaelSmith-fg8xh
@MichaelSmith-fg8xh 2 жыл бұрын
Seemed ok in pfsense and opensense although it was sometimes annoying to get a wan configuration that gave IPv6 internet (poorly documented, secret handshakes etc)
@christianlempa
@christianlempa 2 жыл бұрын
There is a IPv6 Support Page in the OnlineHelp, where you can find out what's supported and what not on the XG regards IPv6: docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/IPv6FeaturesServices/index.html Note, that might change in future versions of course!
@a.m.653
@a.m.653 2 жыл бұрын
Everyone who has worked with other firewall vendors knows that the Sophos XG is one of the worst firewalls on the market.
@BenGillam
@BenGillam 2 жыл бұрын
That’s utter rubbish There is probably better, but if you work with SMB and use Sophos AV they are great Capable and affordable
@TritonB7
@TritonB7 2 жыл бұрын
Agreed, their support has been abysmal.
@BenGillam
@BenGillam 2 жыл бұрын
@@TritonB7 what country? I’ve never had problems with support. Sales is another matter they relocated sales to Manchester I think and caused a lot of staffing issues
@JasonsLabVideos
@JasonsLabVideos 2 жыл бұрын
Agreed 100% its crap.
@flyingfpv1094
@flyingfpv1094 2 жыл бұрын
Seriously lacking in features network engineers look for which kills their creativity in network configuration.
@taetschmeischter
@taetschmeischter Жыл бұрын
eine Sophos Firewall und dann ein tp-link Switch, genau mein Humor ;-)
@linuscane
@linuscane 2 жыл бұрын
can you get a pop filter for your mic or do some basic eq to get rid of some of the plosive's as like "p's" & "b's". they seem a bit to strong in the audio.
@christianlempa
@christianlempa 2 жыл бұрын
Which part do you mean?
@linuscane
@linuscane 2 жыл бұрын
@@christianlempa i noticed it at about 6:20 but re watching other parts of the vid it didn't seem to bad might have just been that section. it was just a bit of putting really. might just be me:)
@christianlempa
@christianlempa 2 жыл бұрын
@@linuscane thanks! Might be when I'm a bit too close to the mic.
@MelroyvandenBerg
@MelroyvandenBerg 6 ай бұрын
You have two time an outro? 😅
@Lacsap3366
@Lacsap3366 Жыл бұрын
Das Problem das ich mit der XGS habe ist, dass man um die Sophos XGS sinnvoll nutzen zu können jährliche Lizenzen benötigt die gerne Mal 11.816,38 € für 3 Jahre kosten. Ohne diese Subscription kann die Sophos XGS nicht viel mehr als eine OPNSense. Wenn ich das richtig verstanden habe, kann die XGS ohne diese Subscription kein: - TLS Decryption - IPS - DPI - Web Security & Application Control - Zero Day Protection - Funktionsupdates Was die XGS wiederum irgendwie nutzlos macht.
@christianlempa
@christianlempa Жыл бұрын
Für den Home User würde ich so ein System auch nicht empfehlen. Die Software kann auch auf einem normalen PC installiert werden. Dort hast du alle Funktionen komplett kostenlos!
@Lacsap3366
@Lacsap3366 Жыл бұрын
@@christianlempa Das ist gut zu wissen. Warum sollte man dann überhaupt noch zur Sophos XG als Hardware appliance greifen, wenn man die Software komplett kostenlos auf eigener Hardware nutzen kann?
@christianlempa
@christianlempa Жыл бұрын
@@Lacsap3366 ich bekomm die Testgeräte samt Lizenz umsonst, ansonsten hät ich das auch anders gemacht ;)
@Lacsap3366
@Lacsap3366 Жыл бұрын
@@christianlempa Ah alles klar. Danke für die Info !
@TheOnlyEpsilonAlpha
@TheOnlyEpsilonAlpha 2 жыл бұрын
Looks like an impressive product, but the price tag is completely off the charts 2.5k Euros is way too much for one device
@psycl0ptic
@psycl0ptic 2 жыл бұрын
now you can upgrade it to make it better - install pfsenes on it.
@christianlempa
@christianlempa 2 жыл бұрын
Why would I do that? 🤣
@Stopinvadingmyhardware
@Stopinvadingmyhardware 2 жыл бұрын
Needs integration with a UPS system
@ikpeessien7399
@ikpeessien7399 6 ай бұрын
iam using one
@balla2172
@balla2172 2 жыл бұрын
2100 msrp not bad but fear it's gonna be a pay to operate license I'll watch and hold my breath
@roelpluijmen
@roelpluijmen 2 жыл бұрын
great, a 2k firewall for homeuse
@christianlempa
@christianlempa 2 жыл бұрын
Anything below is a no go 🤣
@MichaelSmith-fg8xh
@MichaelSmith-fg8xh 2 жыл бұрын
He works for them
@roelpluijmen
@roelpluijmen 2 жыл бұрын
@@MichaelSmith-fg8xh Jacket included!
@tmydosh1
@tmydosh1 2 жыл бұрын
I tried installing Sophos Free Home Firewall on a spare PC, but there is no documentation for this product on the Sophos website. I even asked around several times on their support forum and nobody knew what I was talking about, even a tech support person. Not impressed.
@renehoehle
@renehoehle Жыл бұрын
I have migrated now some Sophos UTM to XGS. I found so many bugs and UI problems. It's like a cultural shock you search the whole time some parts in the menue that is really not intuitive. The performance of the UI is very slow and sometimes you won't get a return and you stuck on that loading screen. So this is version 19.5 now and this is the product from years of development sorry but this is very sad. The whole system looks to me that someone started building a green gras project and then oh wait we forgot IPv6 and we have so make a second area for it. Ok but then the customers has to make duplicate rules. OK thats no problem. In most cases the whole structure makes no sense. I had a call with the support. And they had the same problems and mentioned the same. And he told me that most customers have the same problems. So why is Sophos not hearing to the community and take 2 people to fix all the small problems? The answer is money. Sophos changed the prices 3 times in one year and they don't lowering the prices. But the product won't get better. But your video is great it's only my option to the XGS systems.
@VolkerHett
@VolkerHett 2 жыл бұрын
Somewhat expensive, even with all the goodies a Platinum Partner with Sophos get's for demo equipment.
@christianlempa
@christianlempa 2 жыл бұрын
Yeah it's a bit overkill :D But the home license is also a nice option!
@Wahinies
@Wahinies 5 ай бұрын
*laughs in Meraki*
@BillyOfTea
@BillyOfTea 2 жыл бұрын
I'm just a minute into this video wondering, "What group of Russian hackers did this guy piss off? "
@christianlempa
@christianlempa 2 жыл бұрын
What?
@SGTxD00mixHDx
@SGTxD00mixHDx 2 ай бұрын
Install OPNsense or PFsense for a usable environment. SFOS is the worst firewall os i've ever touched :)
@christianlempa
@christianlempa 2 ай бұрын
Well, that's... your opinion man
@SGTxD00mixHDx
@SGTxD00mixHDx 2 ай бұрын
@@christianlempa if you've got the tools, try to measure the performance of the firewall and compare it to the datasheet :)
@SGTxD00mixHDx
@SGTxD00mixHDx 2 ай бұрын
@@christianlempa PS.: cheap Marvell chips, slow performance in the UI, outdated software packages ... i've to work with sophos, but every other vendor i get my hands on is better in every way. It's not only me, check gartner aswell.
@bogy5259
@bogy5259 Жыл бұрын
so now you pay thousend of dollars yearly for licencing? xD
@adambrown3918
@adambrown3918 2 жыл бұрын
$2000.00 dollars for a HOME firewall? That probably doesn't include the subscription either? NO!
@christianlempa
@christianlempa 2 жыл бұрын
The firewall comes with a base license, but some features cost extra.
@9954140801
@9954140801 2 жыл бұрын
Licensing for 3years xstream protection along with hardware xgs 2100 would cost around 6 to 7k
@rafaelpereiradias2567
@rafaelpereiradias2567 2 жыл бұрын
I use the ubiquiti solution.
@christianlempa
@christianlempa 2 жыл бұрын
Seems like a great solution for home networks!
@Voigt_Analytics
@Voigt_Analytics 7 ай бұрын
Nette Sache, das muss man sich erstmal leisten können als "Home Lab" Spielzeug. Wer mir welches schenken möchte darf sich gerne melden. Ich nehme High Tech Spenden gerne an :-)
@christianlempa
@christianlempa 7 ай бұрын
Stimmt :D ich würde auch niemandem dieses Gerät fürs HomeLab zu kaufen. Besser wäre die Sophos Firewall Home Edition in einer VM oder auf einem kleinen PC zu installieren :)
@Voigt_Analytics
@Voigt_Analytics 7 ай бұрын
@@christianlempa Habe mir mal eine XG 125(w) bestellt. Für schlappe 150€. Wenn die Home Lizenz funktioniert, werde ich das Abenteuer mal wagen. Allerdings tue ich mich gedanklich noch schwer damit sie in mein bestehendes Netzwerk zu integrieren. Habe eine FritzBox 7590 mit vier WLAN-APs als Mesh konfiguriert. Ich will sie unbedingt weiter als Modem, Router und Mesh-Controller nutzen. Da ist die FB einfach top. Was empfiehlst Du für die Sophos Firewall? Kann man sie sinnvoll hinter die Fritzbox nutzen? Oder irgendwie den Traffic als DNS-Server durchschleifen? Das 350€ teure DSL-SFP-Modul wäre ja auch ganz nett oder die 3G/4G(/5G) Erweiterungskarte für die Kiste. Doch wenn man mit VLANs später arbeiten will, bleibt einem wahrscheinlich nicht weiter übrig, als komplett neue APs zu kaufen, oder?
@Voigt_Analytics
@Voigt_Analytics 7 ай бұрын
Und dann ist sie noch meine Telefonanlage. Wird echt schwierig sie als Firewall "zu ersetzen." Kann mir im Moment nur eine Routerkaskade vorstellen. Oder hast Du zufällig eine bessere Idee? Vor allem auch um den IOT / Kamera / Smart Home Krams zu isolieren?
@richardjensen1744
@richardjensen1744 2 жыл бұрын
buying a firewall to pay a monthly fee, pass
@rpsmith
@rpsmith 2 жыл бұрын
$2,000 -- No Thanks !
@BadAssAdministrator
@BadAssAdministrator 10 ай бұрын
Sophos is garbage. It's over priced hardware and software that has changed hands too many times. It cannot reliably maintain site to site VPN connections. Perhaps it's usable enough for a simple home network. Ended up getting a Fortinet Fortigate 100F and haven't looked back.
@VideoGigs
@VideoGigs 2 жыл бұрын
Of course Sophos is good. It’s a sponsored segment. Did they ask you to wear their branding too? I do like your content but this video is a little Disappointing! Also overkill for home labs. I’m happy with PFSense.
@christianlempa
@christianlempa 2 жыл бұрын
No, they didn't ask me to do anything, (I'm working for this company btw). Also, I didn't ask you to shut off your PFsense did I? PFSense is a great firewall, too.
@VideoGigs
@VideoGigs 2 жыл бұрын
@@christianlempa All good. Understood. Apologies if my comment offended you in anyway. That wasn’t my intention. Didn’t know you worked for Sophos. :-)
@christianlempa
@christianlempa 2 жыл бұрын
@@VideoGigs no worries mate, it's all good! 😀
How to structure networks with VLANs
18:36
Christian Lempa
Рет қаралды 122 М.
Protect your home network! // Sophos XG Firewall on Proxmox Walkthrough
48:29
UFC 310 : Рахмонов VS Мачадо Гэрри
05:00
Setanta Sports UFC
Рет қаралды 1,2 МЛН
How Strong Is Tape?
00:24
Stokes Twins
Рет қаралды 96 МЛН
My NEW HomeLab storage server!
27:42
Christian Lempa
Рет қаралды 43 М.
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,4 МЛН
How to use Cloudflare Tunnel in your Homelab (even with Traefik)
23:34
Christian Lempa
Рет қаралды 169 М.
What's running in my Home Lab?
25:50
Christian Lempa
Рет қаралды 127 М.
Quick and Easy Local SSL Certificates for Your Homelab!
12:08
Wolfgang's Channel
Рет қаралды 879 М.
Basic Setup and Configuring pfsense Firewall Rules For Home
17:27
Lawrence Systems
Рет қаралды 389 М.
Self-Hosting Security Guide for your HomeLab
18:43
Techno Tim
Рет қаралды 424 М.
Secure your HomeLab for FREE // Wazuh
33:59
Christian Lempa
Рет қаралды 82 М.
How to protect Linux from Hackers // My server security strategy!
30:39
Christian Lempa
Рет қаралды 231 М.