Stronger Cyber Defense with Advanced CISO-Level Protection

Products

Sophos Firewall for Microsoft Azure

Sophos Firewall for Microsoft Azure

Sophos Firewall for Microsoft Azure provides a virtual network security platform for protecting workloads and traffic within Microsoft Azure environments. Sophos offers the firewall as a pre-configured virtual machine that can be deployed in Azure and sized according to the requirements of the environment.

Product Specifications

Capability Specification / Option Typical Use / Context
Deployment & Platform Azure VM inside Azure VNet Cloud firewall & network traffic protection
Licensing PAYG / BYOL Flexible consumption or existing license reuse
Networking & Routing IPsec VPN & BGP Secure connectivity & dynamic hybrid routing
Identity & Security Microsoft Entra ID (Azure AD) SSO authentication & user identity integration
High Availability & Scale Azure Load Balancer Active-active traffic distribution
Management Sophos Fusion / Central Centralized administration & policy control
Category: Virtual Firewalls

Description

Sophos Firewall for Microsoft Azure

Sophos Firewall for Microsoft Azure

 

Sophos Firewall for Microsoft Azure extends Sophos network security into Microsoft’s public cloud platform. It is available as a pre-configured virtual machine that can be deployed within Azure and configured according to the organization’s network architecture.

The solution is suitable for organizations protecting Azure workloads, connecting cloud and on-premises environments, or building hybrid network security architectures.

Azure Deployment

Sophos Firewall can be deployed within Microsoft Azure using supported deployment methods and Azure networking resources. The firewall operates as a virtual machine, allowing organizations to select an appropriate Azure VM size for the deployment.

Sophos also provides deployment templates for supported Azure architectures, including an active-active configuration using Azure Standard Load Balancer.

Licensing Category

Sophos Firewall for Azure supports two primary licensing models.

PAYG: The firewall software is billed hourly through Microsoft Azure. Sophos states that PAYG includes the features and functionality of the Xstream protection bundle, subject to the licensing terms. PAYG availability is limited to Microsoft remittance countries.

BYOL: Organizations can use a Sophos Firewall software license purchased from an authorized Sophos reseller. BYOL supports Sophos software subscriptions and support options according to the applicable license.

Network Connectivity

Sophos Firewall can connect Azure networks with on-premises environments through route-based IPsec VPN. Supported deployments can also use BGP for dynamic route exchange between the on-premises Sophos Firewall and Azure network infrastructure.

Identity Integration

Sophos Firewall supports Microsoft Entra ID integration for SSO authentication. This can be used for supported administrator, captive portal, VPN portal, and remote-access authentication scenarios.

High-Availability Architecture

Sophos provides an active-active Azure deployment architecture using two Sophos Firewall instances and Azure Standard Load Balancer. Azure load balancers distribute inbound and outbound traffic between the firewall instances. Active-passive deployment is not supported in this architecture.

Selection Guide

For Azure Deployment

Identify the required Azure region, virtual network architecture, number of network interfaces, expected traffic volume, and appropriate Azure VM size before deployment.

For Licensing

Choose PAYG when Azure-based consumption billing is preferred and available in the deployment country.

Choose BYOL when the organization already has or plans to purchase a Sophos Firewall software license through an authorized reseller.

For Hybrid Connectivity

Select a route-based IPsec VPN architecture when connecting an on-premises Sophos Firewall to Azure. For environments requiring dynamic routing, evaluate the BGP-supported architecture.

For High Availability

For an active-active Azure deployment, use the Sophos-supported architecture with two firewall instances and Azure Standard Load Balancers. Active-passive deployments are not supported.

Always Verify

Check the latest Sophos Azure deployment documentation, supported Azure VM sizes, licensing availability, Azure region availability, and network architecture requirements before purchasing or deploying.

Installation Notes

Sophos Firewall for Azure is deployed as a virtual machine through supported Azure deployment methods. The deployment process requires an Azure subscription, resource configuration, network configuration, VM sizing, administrative credentials, and the selected Sophos licensing model.

For a standard deployment, administrators configure the Azure virtual network and required subnets, select the Sophos Firewall image and VM size, configure networking, and complete the deployment.

For active-active deployment, Sophos provides an Azure template that creates the firewall instances together with the required load-balancing architecture. The current template can deploy two firewall instances and uses Azure Standard Load Balancer for inbound and outbound traffic distribution.

After deployment, the firewall can be accessed through its management interface and registered with Sophos Fusion. BYOL deployments require the applicable Sophos license, while PAYG deployments use the Azure-based licensing model.

Best Practices

  • Select an Azure VM size based on the expected workload and firewall requirements.
  • Plan Azure subnets and routing before deploying the firewall.
  • Use route tables to ensure required traffic passes through the firewall.
  • Restrict administrative access to trusted networks.
  • Use strong administrative credentials.
  • Choose PAYG or BYOL based on the organization’s licensing requirements.
  • Use route-based IPsec VPN for supported hybrid Azure connectivity.
  • Consider BGP when dynamic routing is required and supported.
  • Use Microsoft Entra ID SSO where it fits the organization’s authentication architecture.
  • For active-active deployments, follow Sophos’ supported Azure load-balancing architecture.
  • Review the latest Sophos compatibility and Azure deployment documentation before production deployment.

Benefits for IT Teams

Simplified deployment of a Sophos virtual firewall inside Microsoft Azure.

Flexible licensing through PAYG or BYOL.

Centralized firewall security for Azure workloads and network traffic.

Secure hybrid connectivity between Azure and on-premises environments.

Integration with Microsoft Entra ID for supported SSO scenarios.

Support for active-active Azure deployment architectures using load balancing.

Centralized management through the Sophos management ecosystem.

Main Benefits

Flexible Cloud Deployment

Deploy Sophos Firewall directly as an Azure virtual machine.

Benefit: Extend firewall security into Microsoft Azure without requiring a physical firewall appliance.

Flexible Licensing

Choose PAYG or BYOL according to the organization’s purchasing and deployment model.

Benefit: Align firewall licensing with cloud consumption or existing Sophos licensing.

Hybrid Network Connectivity

Connect Azure environments with on-premises networks using route-based IPsec VPN and supported BGP configurations.

Benefit: Build secure hybrid network architectures with dynamic routing where required.

Azure Identity Integration

Integrate Sophos Firewall with Microsoft Entra ID for supported SSO authentication scenarios.

Benefit: Connect firewall access and authentication workflows with an existing Microsoft identity environment.

Scalable Cloud Architecture

Select Azure VM sizes based on deployment requirements and use Azure networking services as part of the firewall architecture.

Benefit: Adapt the virtual firewall deployment to the needs of different Azure environments.

High-Availability Architecture

Use Sophos’ active-active Azure deployment architecture with Azure Standard Load Balancer and two firewall instances.

Benefit: Distribute inbound and outbound traffic across firewall instances while using Azure load-balancing capabilities.

Typical Use Cases

1. Azure Workload Protection

Deploy Sophos Firewall within an Azure virtual network to control and inspect traffic associated with cloud workloads.

2. Hybrid Cloud Security

Connect on-premises infrastructure to Microsoft Azure using route-based IPsec VPN and secure traffic between environments.

3. Azure Internet Traffic Routing

Route internet-bound traffic from Azure workloads through Sophos Firewall for centralized firewall policy enforcement.

4. Multi-Network Azure Environments

Use Sophos Firewall within Azure architectures containing multiple network segments that require controlled traffic flows.

5. Active-Active Cloud Firewall Deployment

Deploy two Sophos Firewall instances behind Azure Standard Load Balancers for an active-active architecture.

The current Sophos deployment template uses load balancing for inbound and outbound traffic and supports a maximum of two firewall instances through the template.

6. Cloud and On-Premises Identity Integration

Integrate Sophos Firewall with Microsoft Entra ID when organizations want supported SSO-based authentication for administrators or users.

Who Should Buy Sophos Firewall for Microsoft Azure?

Sophos Firewall for Microsoft Azure is designed for organizations that need dedicated network security within Azure-based environments.

It is suitable for:

  • Businesses running production workloads in Microsoft Azure.
  • Organizations building hybrid cloud and on-premises networks.
  • IT teams requiring firewall control within Azure virtual networks.
  • Enterprises connecting Azure workloads with branch or data-center infrastructure.
  • Organizations looking for PAYG cloud firewall licensing.
  • Existing Sophos customers extending network security into Azure.
  • Managed service providers deploying standardized cloud security architectures.

Sophos describes its Azure firewall deployment as certified and optimized for Microsoft Azure and makes it available through the Microsoft Azure Marketplace.

Related Categories

Explore related Sophos and cloud security solutions for deeper product information:

  • Sophos Firewalls
  • Sophos Firewall Virtual
  • Sophos Firewall for AWS
  • Sophos Firewall Software Appliance
  • Sophos Firewall Virtual for VMware
  • Sophos Firewall Virtual for Hyper-V
  • Sophos Firewall Virtual for KVM
  • Sophos Firewall Virtual for Nutanix
  • Sophos Firewall Virtual for Citrix Hypervisor
  • Sophos Cloud Security
  • Microsoft Azure Security

Frequently Asked Questions

What is Sophos Firewall for Microsoft Azure?

Sophos Firewall for Microsoft Azure is a virtual firewall deployment that runs as a pre-configured virtual machine within Microsoft Azure. It provides Sophos network security capabilities for Azure and hybrid cloud environments.

Can Sophos Firewall run on Microsoft Azure?

Yes. Sophos Firewall can be deployed as a virtual machine on Microsoft Azure, with Azure VM types and sizes selected according to the deployment requirements.

Is Sophos Firewall available in the Azure Marketplace?

Yes. Sophos states that Sophos Firewall is available in the Microsoft Azure Marketplace and supports flexible PAYG and BYOL licensing options.

What licensing options are available for Sophos Firewall on Azure?

Sophos Firewall on Azure supports Pay-As-You-Go (PAYG) and Bring-Your-Own-License (BYOL). PAYG is billed through Azure, while BYOL uses a Sophos software license purchased through an authorized reseller.

Can Sophos Firewall connect Azure to an on-premises network?

Yes. Sophos provides documentation for connecting an on-premises Sophos Firewall to Microsoft Azure using route-based IPsec VPN. BGP can also be used for supported dynamic-routing deployments.

Does Sophos Firewall support Microsoft Entra ID?

Yes. Sophos Firewall can integrate with Microsoft Entra ID for supported SSO authentication scenarios, including supported administrator and user-access services.

Does Sophos Firewall on Azure support high availability?

Sophos Firewall on Azure does not provide native HA. However, Sophos provides an active-active deployment architecture using two firewall instances with Azure Standard Load Balancers. Active-passive deployments are not supported.

Can I use PAYG or BYOL for an Azure HA deployment?

Yes. Sophos’ active-active Azure deployment documentation lists both BYOL and PAYG as supported licensing options. A valid license is required for each firewall in a BYOL deployment.

How do I choose the Azure VM size for Sophos Firewall?

Choose the Azure VM size based on the expected traffic, network configuration, and firewall workload. Check the latest Sophos documentation for supported and recommended Azure VM sizes before deployment.

Can Sophos Firewall protect Azure internet traffic?

Yes. Sophos provides Azure deployment architectures where internet traffic from internal Azure networks is routed through Sophos Firewall for inspection and policy enforcement.

Where can I find Azure compatibility information?

Check the latest Sophos Firewall documentation for Microsoft Azure deployment requirements, supported VM sizes, licensing information, networking requirements, and deployment templates.

Reviews

There are no reviews yet.

Be the first to review “Sophos Firewall for Microsoft Azure”

Your email address will not be published. Required fields are marked *