Stronger Cyber Defense with Advanced CISO-Level Protection

1ST GENERATION · XSTREAM FLOW ARCHITECTURE

Sophos XGS Series Desktop Firewalls (1st Gen)

Enterprise-grade threat prevention in a compact, quiet desktop form factor. Tailored for small offices, remote branch locations, and expanding SMBs, delivered, supported, and cloud-managed by Netmate IT.

  • TLS 1.3 Inspection
  • Built-in SD-WAN Capabilities
  • Zero-Touch Deployment
  • Sophos Central Cloud Ready
Category Overview

A New Class of Edge Security

What it is

Compact next-generation firewalls purpose-built for silent, desktop deployment.

Who it's for

SMBs, branch offices, retail outlets, and distributed enterprise locations.

Main use cases

Perimeter defense, secure remote access, SD-WAN routing, and ZTNA integration.

In the ecosystem

Fully synchronized with Sophos Central, Endpoint, MDR, and Wireless via Netmate IT.

Key Features

Comprehensive protection built for modern workloads

Engineered around nine core security capabilities, driven by dedicated Xstream hardware acceleration and Sophos X-Ops intelligence, deployed and optimized for your business by Netmate IT. 

Advanced Threat Protection

AI-powered defense against ransomware, zero-day exploits, and known malware.

Deep Packet Inspection

Single-pass streaming engine inspects every packet with negligible latency.

SSL / TLS Inspection

Decrypt and scan TLS 1.3 traffic without breaking application performance.

Application Control

Granular visibility and policy across thousands of cloud and SaaS apps.

Web Filtering

Category, URL, and content-based filtering with safe-search enforcement.

IPS & IDS

Signature, behavior, and exploit-based intrusion prevention at the edge.

VPN Connectivity

Site-to-site IPsec, SSL VPN, and Zero Trust Network Access (ZTNA).

SD-WAN Support

Application-aware routing, link bonding, and automatic failover.

Cloud Management

Provision, monitor, and orchestrate from Sophos Central — anywhere.

Product Range

Available Models

WHY CHOOSE XGS

Designed for impact, built beyond bandwidth specs

From boardroom security compliance to remote site operations, the Sophos XGS Desktop 1st Gen series delivers real operational efficiency, fewer active threats, optimized network speed, and zero management friction provided by Netmate IT.

Business Value

Optimized total cost of ownership, predictable subscription models, and single-pane management provided by Netmate IT.

Security Edge

Dual-engine artificial intelligence for zero-day defense paired with instant synchronized threat response.

Silicon Performance

Onboard Xstream Flow processors handle SSL decryption, IPS scanning, and app routing directly in hardware.

Seamless Scalability

Effortlessly roll out new branch offices or scale remote locations through Sophos Central with Netmate IT's guidance.

Sophos Ecosystem

One vendor. One console. Synchronized everywhere.

Sophos Firewall

Synchronized Security deployed at the network perimeter.

Sophos Central

Single-pane cloud management for your entire IT infrastructure.

Sophos Switch

Hardened, secure LAN access layer connecting local devices.

Sophos Wireless

Cloud-managed Wi-Fi access points for secure office connectivity.

Sophos Endpoint

Intercept X featuring advanced EDR protection for all user devices.

Sophos MDR

24/7 fully managed threat detection, hunting, and incident response.

DEPLOYMENT SCENARIOS

Tailored network security for every work environment

Retail & Distributed Outlets

Ultra-reliable edge protection featuring seamless cellular failover and PCI-DSS compliance, managed end-to-end by Netmate IT.

See Solution

Hybrid & Remote Hubs

Secure encrypted tunnels linking distributed workforce devices directly to core cloud apps with ZTNA and Sophos Central.

See Solution

High-Density Branch Offices

High-speed encrypted traffic inspection paired with Dual-Engine High Availability (HA) to eliminate single points of failure.

See Solution
Technical Specifications

At-a-glance capabilities

Core hardware specifications across the Sophos XGS 1st Gen Desktop lineup, configured, supplied, and deployed by Netmate IT.

Throughput

3.85 – 11.5 Gbps

Firewall throughput scaled across the XGS 1st Gen desktop family.

Port Options

5 – 12 Interfaces

High-speed GE copper and SFP fiber connectivity tailored to your model.

Wireless

Wi-Fi 5 (802.11ac)

Integrated wireless capabilities on select w models, with optional second Wi-Fi module expansion.

Form Factor

Desktop / Rackmount

Ultra-quiet, compact desktop form factor with optional 1U rackmount mounting kits.

Management

Sophos Central

Cloud-first centralized orchestration managed directly by Netmate IT, with local GUI fallback.

How to Choose

Pick the right XGS model in 60 seconds

Data not Found Data not Found Data not Found Data not Found
COMPARISON TABLE

Compare every XGS 1st Gen Desktop Firewall

ModelUsersPortsThroughput Best ForRedundancyModularityConnectivity
XGS 87 / 87w Up to 25 4× GE Copper + 1× SFP 3.85 Gbps Small/Micro Branch Office Fixed / Single PSU Fixed Architecture Integrated Wi-Fi 5 Option (w models)
XGS 107 / 107w Up to 50 8× GE Copper + 1× SFP 7.0 Gbps Small Business & Outlets Optional 2nd PSU Fixed Architecture Integrated Wi-Fi 5 Option (w models)
XGS 116 / 116w Up to 75 8× GE Copper + 1× SFP + 1× PoE 7.7 Gbps Growing SMBs & Regional Hubs Optional 2nd PSU 1× Modular Expansion Slot (3G/4G/5G) Integrated Wi-Fi 5 Option (w models)
XGS 126 / 126w Up to 100 10× GE Copper + 2× SFP + 2× PoE 10.5 Gbps Mid-Market Offices Optional 2nd PSU 1× Modular Expansion Slot (3G/4G/5G) Integrated Wi-Fi 5 Option (w models)
XGS 136 / 136w Up to 150 10× GE Copper + 2× SFP + 2× 2.5 GE PoE 11.5 Gbps High-Density Offices & Core Edge Optional 2nd PSU 1× Modular Expansion Slot (3G/4G/5G) Integrated Wi-Fi 5 Option (w models)
WHY PARTNER WITH NETMATE IT

Superior hardware needs expert execution. We bridge the gap.

Buying security equipment is only step one. Netmate IT delivers the end-to-end technical expertise, strategic integration, and ongoing assistance required to maximize your Sophos investment and guarantee business continuity.

Strategic Discovery

Dedicated security specialists evaluate your bandwidth needs, user density, and compliance needs to build the exact Sophos setup for your budget.

Architecture Engineering

Custom network mapping, VLAN segmentation, and High-Availability (HA) failover setups optimized for uninterrupted workplace operations.

Precision Rollout

Flexible remote or hands-on installation using hardened configuration protocols, baseline policies, and vendor best practices.

Frictionless Transition

Safe switch-over strategies from legacy security systems to Sophos XGS without service interruptions or network downtime.

Continuous Monitoring

Around-the-clock technical coverage featuring rapid SLA guarantees, proactive troubleshooting, and fast-track vendor escalation routes.

Team Enablement

Hands-on admin coaching on Sophos Central orchestration, threat reporting tools, and custom policy creation for your IT team.

FREQUENTLY ASKED QUESTIONS

Everything you need to know about Sophos XGS Desktop Firewalls

What is the main difference between the Sophos XGS 1st Gen Desktop models and older XG series firewalls?

 The primary upgrade in the XGS Series is the dual-processor Xstream Architecture. Unlike older units that relied solely on a single main CPU, XGS firewalls combine an x86 CPU with a dedicated hardware-based Xstream Flow Processor. This enables offloading and hardware acceleration for heavy tasks like TLS 1.3 decryption, IPS scanning, and application routing without slowing down your network.

What do the "w" suffix variants (e.g., XGS 107w vs. XGS 107) signify?

Models with a “w” at the end (such as XGS 87w, 107w, 116w, 126w, and 136w) feature integrated Wi-Fi 5 (802.11ac) radios directly inside the firewall appliance. These are ideal for small branch offices, retail outlets, or remote clinics that require an all-in-one perimeter defense and wireless access point without buying extra Wi-Fi hardware.

How do I know which XGS model (87, 107, 116, 126, or 136) is right for my business?

Hardware selection depends on three main factors: your active user count, internet bandwidth speeds, and port connectivity needs (such as SFP fiber or PoE requirements).

  • For micro-offices up to 25 users, the XGS 87 is a great entry point.
  • For growing SMBs requiring 3G/4G/5G expansion modules or Power over Ethernet (PoE) for access points and IP phones, models like the XGS 116, 126, or 136 are recommended.
  • Netmate IT provides a free pre-sales architectural assessment to accurately size your firewall before purchase.
Are Sophos Firewall licenses based on user counts or per-device?

Sophos Firewall protection licenses (such as Network Protection, Web Protection, and Zero-Day Protection bundles) are tied directly to the firewall appliance itself, not per user or per connected endpoint. This provides predictable subscription costs as your team grows within that firewall’s capacity limit.

Why should I purchase and deploy my Sophos XGS Firewall through Netmate IT instead of buying raw hardware elsewhere?

As a certified Sophos Partner, Netmate IT provides complete deployment lifecycle support. Beyond supplying the hardware and official subscription licensing, we handle initial network topology design, zero-touch remote or on-site configuration, zero-downtime legacy migration, and ongoing 24/7 technical management through Sophos Central.