Stronger Cyber Defense with Advanced CISO-Level Protection

Products

Sophos XGS 116

Sophos XGS 116

The Sophos XGS 116 is a next-generation firewall appliance designed for small and medium-sized businesses, branch offices, and distributed network environments. It combines firewall security, intrusion prevention, VPN connectivity, SSL/TLS inspection, and advanced threat protection in a compact desktop form factor.

Product Specifications

Technical Specifications

 

Specification / Feature Details
Model & Series Sophos XGS 116 (Desktop NGFW)
Throughput 7.7 Gbps Firewall / 4.8 Gbps IPsec VPN / 2.5 Gbps IPS
Threat & TLS 2.0 Gbps NGFW / 650 Mbps TLS Inspection
Connections 1,600,000 Concurrent / 61,500 New per sec
Interfaces 8 × GbE (1 × 30W PoE+), 1 × 1G SFP
Expansion & System 1 expansion slot, 4-Core CPU, 8 GB total RAM, 64 GB SSD
Power & Mounting External 150W (Optional 2nd PSU), Wall / Rack / DIN-Rail

Description

Sophos XGS 116 Firewall — Next-Generation Firewall

Sophos XGS116 Firewall firewall
Sophos XGS116 Firewall — Next-Generation Firewall

Introduction

The Sophos XGS 116 is a compact next-generation firewall designed for SMB and branch office environments. It combines high-speed firewall processing with network security, VPN connectivity, traffic inspection, and flexible interface options.

Sophos rates the XGS 116 at up to 7.7 Gbps firewall throughput, with 2.5 Gbps IPS throughput, 2.0 Gbps NGFW throughput, and 4.8 Gbps IPsec VPN throughput.

 

Network Connectivity

The appliance provides eight Gigabit Ethernet copper interfaces and one 1Gbps SFP interface. One of the Ethernet ports supports 802.3at PoE with up to 30W, providing power to compatible network devices directly through Ethernet.

 

Expansion Options

The XGS 116 includes one expansion slot for supported connectivity modules. Sophos lists optional 3G/4G and 5G connectivity options for the XGS 116 family, subject to model generation, hardware compatibility, and regional availability.

 

Deployment

The XGS 116 measures 320 × 213 × 44 mm and weighs approximately 2.2 kg unpacked. It supports wall, rack, and DIN-rail mounting, while the rackmount kit can be ordered separately.

 

Why Choose Sophos XGS 116?

The XGS 116 brings together firewall security, VPN connectivity, fiber support, PoE, and modular expansion in a compact appliance. It is designed for organizations that need a flexible security platform without moving to a larger rackmount firewall chassis.

Selection Guide

For SMB Networks

Consider the XGS 116 when the network requires multiple Gigabit Ethernet interfaces, integrated security services, VPN connectivity, and room for future expansion.

 

For PoE Deployments

Use the integrated PoE interface when powering a compatible device such as an access point, IP phone, or IP camera. The port supports up to 30W under 802.3at.

 

For Fiber Connectivity

The XGS 116 includes one 1Gbps SFP interface. Select the appropriate compatible SFP transceiver according to the fiber type, distance, and network requirements.

 

For Cellular Connectivity

The expansion bay can support compatible cellular connectivity modules. Verify the specific hardware generation, module compatibility, and regional requirements before ordering.

 

For Rack Installation

Use the appropriate Sophos rackmount accessory. The uploaded Sophos Accessories reference identifies RM-SR-T12 for XGS 116/126/136 appliances.

 

Always Verify

Check the current Sophos compatibility documentation and the specific appliance datasheet before purchasing modules, transceivers, rackmount accessories, or other optional components. The reference material also recommends model-specific compatibility verification.

 

Installation Notes

Place the Sophos XGS 116 on a suitable surface or install it using the supported mounting method. For rack deployment, use the appropriate rackmount kit rather than a generic shelf.

Connect the WAN, LAN, SFP, and management interfaces according to the intended network design. If using the PoE interface, ensure the connected device complies with the supported PoE standard and power requirements.

For SFP connectivity, install a compatible transceiver and use the appropriate fiber or copper connection. Sophos documentation specifies that SFP transceivers are sold separately.

When installing optional expansion modules, follow the applicable Sophos hardware installation instructions and verify compatibility with the specific appliance revision.

 

Best Practices

  • Use supported Sophos accessories and modules. 
  • Verify compatibility before purchasing expansion modules. 
  • Select SFP transceivers according to the required media, speed, and distance. 
  • Keep adequate ventilation around the appliance. 
  • Use the correct rackmount solution for rack installations. 
  • Document WAN, LAN, SFP, and PoE connections. 
  • Keep firmware and security configurations maintained according to the organization’s security policy. 
  • Use the optional redundant power supply where higher availability requirements justify it. 

Benefits for IT Teams

The Sophos XGS 116 gives IT teams a compact platform for combining firewall security, VPN connectivity, fiber connectivity, PoE, and optional expansion.

Its eight Gigabit Ethernet ports simplify connectivity for SMB networks, while the SFP interface provides an option for fiber links. The expansion slot allows supported connectivity modules to be added when deployment requirements change.

For rack-based environments, the availability of a dedicated rackmount solution also helps standardize physical installation. The reference material recommends purpose-built rackmount solutions to improve installation consistency and serviceability.

 

Main Benefits

High-Speed Network Security

The XGS 116 provides up to 7.7 Gbps firewall throughput.

Benefit: Handle business network traffic while maintaining integrated security controls.

 

Flexible Connectivity

The firewall combines eight Gigabit Ethernet ports with a 1Gbps SFP interface.

Benefit: Connect copper-based devices while supporting fiber network links.

 

Built-In PoE

One Gigabit Ethernet interface supports up to 30W of 802.3at PoE.

Benefit: Power compatible access points, IP phones, cameras, and other PoE devices without a separate power connection.

 

Expandable Connectivity

One expansion slot allows supported connectivity modules to be added.

Benefit: Adapt the firewall to changing connectivity requirements.

 

VPN and Remote Connectivity

The XGS 116 supports IPsec and SSL VPN capabilities.

Benefit: Connect branch offices, remote users, and distributed business networks securely.

 

Flexible Deployment

The appliance supports wall, rack, and DIN-rail mounting, with a separate rackmount option available.

Benefit: Deploy the firewall in offices, network cabinets, branch locations, or rack environments.

 

 Typical Use Cases

1. SMB Network Security

Deploy the XGS 116 as the central firewall for small and medium-sized business networks requiring integrated security and connectivity.

 

2. Branch Office Security

Use the appliance to protect branch offices while providing firewall, VPN, and traffic inspection capabilities.

 

3. PoE Network Deployment

Connect compatible PoE devices such as wireless access points, IP cameras, and IP phones through the integrated PoE port.

 

4. Fiber Network Connectivity

Use the built-in 1Gbps SFP interface for compatible fiber network connections. SFP transceivers are sold separately.

 

5. Remote Connectivity

Use IPsec and SSL VPN functionality to support secure connections between distributed offices and remote users.

 

6. Rack-Based Firewall Deployment

Install the XGS 116 into a standard network rack using the appropriate rackmount accessory when centralized rack deployment is required.

 

Who Should Buy Sophos XGS 116?

The Sophos XGS 116 is designed for:

  • Small and medium-sized businesses 
  • Branch offices 
  • Retail locations 
  • Distributed organizations 
  • Businesses requiring secure VPN connectivity 
  • Organizations using PoE network devices 
  • IT teams requiring fiber connectivity through SFP 
  • Businesses that need an expandable firewall platform 

It is particularly suited to deployments that need more connectivity and expansion flexibility than entry-level desktop firewall models.

 

Frequently Asked Questions

What is Sophos XGS 116?

The Sophos XGS 116 is a next-generation firewall appliance designed for SMB and branch office networks. It provides firewall security, VPN connectivity, IPS, SSL/TLS inspection, SFP connectivity, PoE, and expansion capabilities.

 

How fast is Sophos XGS 116?

The XGS 116 provides up to 7.7 Gbps firewall throughput, 4.5 Gbps firewall IMIX throughput, 2.5 Gbps IPS throughput, and 2.0 Gbps NGFW throughput according to Sophos’ XGS Series specifications.

 

How many Ethernet ports does Sophos XGS 116 have?

The XGS 116 has 8 Gigabit Ethernet copper ports and 1 × 1Gbps SFP fiber interface.

 

Does Sophos XGS 116 support PoE?

Yes. One Gigabit Ethernet port supports 802.3at PoE with up to 30W, allowing compatible network devices to be powered through Ethernet.

 

Does Sophos XGS 116 support SFP?

Yes. The XGS 116 includes one 1Gbps SFP interface. SFP transceivers are sold separately.

 

Does Sophos XGS 116 support expansion modules?

Yes. The XGS 116 has one expansion slot for supported optional connectivity modules. Sophos lists 3G/4G and 5G connectivity options for the XGS 116 family, subject to applicable hardware and availability.

 

Can Sophos XGS 116 be rack mounted?

Yes. Sophos lists a rackmount kit as available for the XGS 116. The provided Sophos Accessories reference identifies the RM-SR-T12 rackmount series for XGS 116/126/136 models.

 

Does Sophos XGS 116 have redundant power?

An optional second redundant power supply is supported for the XGS 116.

 

Who is Sophos XGS 116 suitable for?

The XGS 116 is intended for SMB and branch office environments that need integrated network security, VPN connectivity, Gigabit Ethernet, SFP connectivity, PoE, and optional expansion.