What it is
Compact next-generation firewalls purpose-built for silent, desktop deployment.
Compact next-generation firewalls purpose-built for silent, desktop deployment.
SMBs, branch offices, retail outlets, and distributed enterprise locations.
Perimeter defense, secure remote access, SD-WAN routing, and ZTNA integration.
Fully synchronized with Sophos Central, Endpoint, MDR, and Wireless via Netmate IT.
Engineered around nine core security capabilities, driven by dedicated Xstream hardware acceleration and Sophos X-Ops intelligence, deployed and optimized for your business by Netmate IT.
AI-powered defense against ransomware, zero-day exploits, and known malware.
Single-pass streaming engine inspects every packet with negligible latency.
Decrypt and scan TLS 1.3 traffic without breaking application performance.
Granular visibility and policy across thousands of cloud and SaaS apps.
Category, URL, and content-based filtering with safe-search enforcement.
Signature, behavior, and exploit-based intrusion prevention at the edge.
Site-to-site IPsec, SSL VPN, and Zero Trust Network Access (ZTNA).
Application-aware routing, link bonding, and automatic failover.
Provision, monitor, and orchestrate from Sophos Central — anywhere.
From boardroom security compliance to remote site operations, the Sophos XGS Desktop 1st Gen series delivers real operational efficiency, fewer active threats, optimized network speed, and zero management friction provided by Netmate IT.
Optimized total cost of ownership, predictable subscription models, and single-pane management provided by Netmate IT.
Dual-engine artificial intelligence for zero-day defense paired with instant synchronized threat response.
Onboard Xstream Flow processors handle SSL decryption, IPS scanning, and app routing directly in hardware.
Effortlessly roll out new branch offices or scale remote locations through Sophos Central with Netmate IT's guidance.
Synchronized Security deployed at the network perimeter.
Single-pane cloud management for your entire IT infrastructure.
Hardened, secure LAN access layer connecting local devices.
Cloud-managed Wi-Fi access points for secure office connectivity.
Intercept X featuring advanced EDR protection for all user devices.
24/7 fully managed threat detection, hunting, and incident response.
Ultra-reliable edge protection featuring seamless cellular failover and PCI-DSS compliance, managed end-to-end by Netmate IT.
See SolutionSecure encrypted tunnels linking distributed workforce devices directly to core cloud apps with ZTNA and Sophos Central.
See SolutionHigh-speed encrypted traffic inspection paired with Dual-Engine High Availability (HA) to eliminate single points of failure.
See SolutionCore hardware specifications across the Sophos XGS 1st Gen Desktop lineup, configured, supplied, and deployed by Netmate IT.
Firewall throughput scaled across the XGS 1st Gen desktop family.
High-speed GE copper and SFP fiber connectivity tailored to your model.
Integrated wireless capabilities on select w models, with optional second Wi-Fi module expansion.
Ultra-quiet, compact desktop form factor with optional 1U rackmount mounting kits.
Cloud-first centralized orchestration managed directly by Netmate IT, with local GUI fallback.
| Model | Users | Ports | Throughput | Best For | Redundancy | Modularity | Connectivity |
|---|---|---|---|---|---|---|---|
| XGS 87 / 87w | Up to 25 | 4× GE Copper + 1× SFP | 3.85 Gbps | Small/Micro Branch Office | Fixed / Single PSU | Fixed Architecture | Integrated Wi-Fi 5 Option (w models) |
| XGS 107 / 107w | Up to 50 | 8× GE Copper + 1× SFP | 7.0 Gbps | Small Business & Outlets | Optional 2nd PSU | Fixed Architecture | Integrated Wi-Fi 5 Option (w models) |
| XGS 116 / 116w | Up to 75 | 8× GE Copper + 1× SFP + 1× PoE | 7.7 Gbps | Growing SMBs & Regional Hubs | Optional 2nd PSU | 1× Modular Expansion Slot (3G/4G/5G) | Integrated Wi-Fi 5 Option (w models) |
| XGS 126 / 126w | Up to 100 | 10× GE Copper + 2× SFP + 2× PoE | 10.5 Gbps | Mid-Market Offices | Optional 2nd PSU | 1× Modular Expansion Slot (3G/4G/5G) | Integrated Wi-Fi 5 Option (w models) |
| XGS 136 / 136w | Up to 150 | 10× GE Copper + 2× SFP + 2× 2.5 GE PoE | 11.5 Gbps | High-Density Offices & Core Edge | Optional 2nd PSU | 1× Modular Expansion Slot (3G/4G/5G) | Integrated Wi-Fi 5 Option (w models) |
Buying security equipment is only step one. Netmate IT delivers the end-to-end technical expertise, strategic integration, and ongoing assistance required to maximize your Sophos investment and guarantee business continuity.
Dedicated security specialists evaluate your bandwidth needs, user density, and compliance needs to build the exact Sophos setup for your budget.
Custom network mapping, VLAN segmentation, and High-Availability (HA) failover setups optimized for uninterrupted workplace operations.
Flexible remote or hands-on installation using hardened configuration protocols, baseline policies, and vendor best practices.
Safe switch-over strategies from legacy security systems to Sophos XGS without service interruptions or network downtime.
Around-the-clock technical coverage featuring rapid SLA guarantees, proactive troubleshooting, and fast-track vendor escalation routes.
Hands-on admin coaching on Sophos Central orchestration, threat reporting tools, and custom policy creation for your IT team.
The primary upgrade in the XGS Series is the dual-processor Xstream Architecture. Unlike older units that relied solely on a single main CPU, XGS firewalls combine an x86 CPU with a dedicated hardware-based Xstream Flow Processor. This enables offloading and hardware acceleration for heavy tasks like TLS 1.3 decryption, IPS scanning, and application routing without slowing down your network.
Models with a “w” at the end (such as XGS 87w, 107w, 116w, 126w, and 136w) feature integrated Wi-Fi 5 (802.11ac) radios directly inside the firewall appliance. These are ideal for small branch offices, retail outlets, or remote clinics that require an all-in-one perimeter defense and wireless access point without buying extra Wi-Fi hardware.
Hardware selection depends on three main factors: your active user count, internet bandwidth speeds, and port connectivity needs (such as SFP fiber or PoE requirements).
Sophos Firewall protection licenses (such as Network Protection, Web Protection, and Zero-Day Protection bundles) are tied directly to the firewall appliance itself, not per user or per connected endpoint. This provides predictable subscription costs as your team grows within that firewall’s capacity limit.
As a certified Sophos Partner, Netmate IT provides complete deployment lifecycle support. Beyond supplying the hardware and official subscription licensing, we handle initial network topology design, zero-touch remote or on-site configuration, zero-downtime legacy migration, and ongoing 24/7 technical management through Sophos Central.