
Install, configure, and manage Sophos XG firewall from scratch using hands-on labs. Cover basic configuration, network zones, firewall policies, web and application control, SSL and IPsec VPN, captive portal, antivirus.
Discover firewall technology, its types—packet filtering, stateful and stateless, web application, cloud, and next-generation firewalls—and how IPS, DPI, and threat intelligence prevent breaches.
Explore Sophos XG firewall, building on UTM and Cyberoam, to deliver next-gen protection, with synchronized security, centralized management, and features like IPS, web, email, and application controls.
Explore the Sophos XG firewall's features and licensing tiers. Understand the base firewall, free licensing, and key subscriptions such as Sandstorm, network protection, web protection, and email protection.
Explore the five Sophos XG firewall models from desktop to enterprise, detailing hardware and virtual appliances, throughput types (raw, ip, ngfw), and scalable wireless and expansion options.
Navigate Sophos XG licensing and subscriptions, comparing enterprise guard, full guard, and total protect with base and enhanced support, including 8x5 and 24x7, for hardware or virtual appliances.
Discover how to obtain the Sophos XG virtual serial number from the Sophos website, activate a 30-day trial, and use it for lab setup with VMware.
Install Sophos XG in VMware Workstation by importing the OVF, configuring LAN, server, and WAN networks, then access the web console at https://172.16.16.16:4444 with admin/admin.
Configure the Sophos XG firewall with a basic setup via the LAN IP 192.168.2.254, log in with admin credentials, and set hostname, timezone, gateway mode, and license registration.
Upgrade the Sophos firewall firmware from 17.5 to the latest maintenance release, covering how to check for updates, configure WAN connectivity, and apply the upgrade safely.
Register the Sophos XG firewall using its serial number, sign in with a Sophos ID, and synchronize or upgrade licenses to enable base, web, email, and Sandstorm protections.
Learn the Sophos firewall overview, from the dashboard and control center to monitor, analyze, protect, and configure firewall rules, VPNs, filtering, logs, and central management.
Explore the Sophos XG firewall control center dashboard, showing hardware model, OS version, serial number, logs, health, and admin access, plus live system performance and VPN status.
Learn to implement zone based firewall by creating custom zones, binding interfaces, and enforcing rules between LAN, DMZ, van, VPN, and Wi-Fi to protect servers.
Understand physical and virtual Sophos XG interfaces, including port naming, VLANs, aliases, and gateways. Build bridges and LAGs, configure RED devices, and enable inter-VLAN routing and DHCP options.
Configure and optimize two-ISP setups on Sophos XG with link manager to achieve gateway load balancing and active-backup failover, using weighted round robin and proportional traffic calculated by weights.
Configure dns on the Sophos firewall, set static and dhcp dns servers, test name lookup, define forwarders and dns request out to an ad server, and manage host entries.
Explore how to configure the Sophos firewall DHCP server, assign IPv4 scopes, default gateways, and DNS, and map static IPs by MAC for LAN devices; DHCP relay is discussed.
Configure dhcp relay on the firewall to forward dhcp requests from a lan segment to a Windows DHCP server, providing ip addresses, gateway, and dns settings.
Explore dynamic dns service to reach the Sophos firewall from anywhere despite changing public IP. Configure providers, hostnames, WAN port, and optional port forwarding or DMZ to access internal resources.
Explore firewall routing fundamentals, including kernel routing, locally connected networks, static and dynamic routes (BGP, OSPF), policy sd-wan routing and default routes, with hands-on configuration and viewing routing tables.
Master static routing with a Sophos firewall and an L3 switch in a practical lab, configuring default routes and static routes to enable internet access on 10.10.0.0/24 and 172.16.0.0/24.
Master creating firewall objects—IP hosts, MAC hosts, FQDN, host groups, country groups, and services—and applying them in Sophos XG firewall rules, web policies, and testing.
Configure Sophos XG firewall system profiles with schedules, access time, surfing and network traffic quotas, NAT and device access, and apply these to users, groups, and policies.
Create and manage local users and groups on Sophos XG firewall, set quotas and traffic shaping, and configure remote access options such as clientless and SSL VPN with captive portal.
Explore how to configure and manage Sophos XG firewall rules for networks and users, including rule types, zones, source and destination criteria, grouping, order, and common actions.
Perform Sophos XG firewall rules lab, creating LAN to LAN, LAN to servers, and servers to LAN rules to grant internet access for IT and account staff, with DNS/DHCP controls.
Configure captive portal settings in Sophos XG, including authentication options, https usage, logo and color customization, login URL, page header, and an optional custom HTML template.
Learn how to deploy the authentication client and configure clientless users on a Sophos XG Firewall, enabling seamless internet access via a user portal and targeted firewall rules.
Configure Sophos XG firewall web policies with licenses, default and custom rules, URL groups, user activities, and categories to block social media and video hosting, plus https decryption and scanning.
Master configuring Sophos XG Firewall application control policies, licensing, categories, risk levels, and traffic shaping to block P2P, VPN, and proxy apps while decrypting HTTPS.
Learn how Sophos XG's intrusion prevention system analyzes traffic, applies IPS policies across land to land and DMZ, blocks signatures, and handles DDoS and spoof protections.
Explore traffic shaping policies on Sophos XG, applying user-based, rule-based, web category, and application-based controls; configure bandwidth limits, priorities, and guarantees for networks and user groups.
Learn to avoid certificate warnings in Sophos XG Firewall by generating and installing a self-signed default certificate, configuring a certificate authority, and applying it to admin and user portals.
Configure and test Active Directory integration with Sophos XG Firewall by adding an AD server, enabling SSL/TLS, importing AD groups, and testing authentication via captive portal for AD users.
Enable single sign-on for Sophos XG Firewall by configuring Sophos Transparent Authentication Suite with agent and collector, integrating with Active Directory, and mapping Windows logon events to firewall users.
Configure business application rules on the Sophos XG firewall, enabling wan-to-lan DNAT, web server protection templates, DMZ routing, and controlled external RDP access.
Learn how to configure SSL VPN remote access on Sophos XG Firewall, covering SSL portal and SSL tunnel VPN, authentication, and firewall rules.
Learn how to configure IPsec site-to-site VPN on a Sophos firewall for IPv6 between two sites, covering phase one and phase two, encryption, authentication, and NAT traversal.
Configure a site-to-site ipsec tunnel between two sophos firewalls, using static ips, nat port forwarding for ipsec ports, with pre-shared keys, two lan networks, vpn rules, pin, and connectivity verification.
Learn to configure high availability for Sophos XG firewalls (active-passive) using two identical devices with same model and revision, including prerequisites, DMZ zone, and failover testing.
Configure active-active high availability on Sophos XG firewall by pairing primary and auxiliary devices, ensuring equal licenses, dedicated links, and synchronized settings to load balance traffic.
Enable Sophos central management to control Sophos firewall from a cloud-based console, register devices, manage backups, approvals, and alerts from a single centralized location.
Master built-in Sophos XG firewall reports by viewing, downloading, scheduling, and filtering traffic, security, and executive dashboards across apps, risk levels, and policies.
Configure and automate backups for the Sophos XG firewall using local, FTP, or email options with encryption passwords, scheduled frequencies, and secure restoration from backups.
Learn to monitor Sophos XG firewall with PRTG using SNMP, configure SNMP v2, set up traffic sensors and bandwidth monitoring, and enable alarms for port and interface performance.
Learn to configure Sophos XG NetFlow sensors (version 5) and a syslog receiver in PRTG, including NetFlow server port 2055, 514 syslog, and monitoring top talkers, connections, and protocols.
Learn to use Sophos XG's diagnostics tools, including the log viewer, policy tester, packet capture, traceroute, dns lookup, and consolidated reports, to analyze firewall rules and traffic.
Sophos XG Firewall provides comprehensive next-generation firewall protection that exposes hidden risks, blocks unknown threats, and automatically responds to incidents by isolating compromised systems, and exposes hidden user, application and threat risks on the network. Sophos also includes synchronized security (links endpoints and firewalls to enable them to communicate and share information, identify compromised systems and isolate them until cleaned up), a web application firewall, email protection, ransomware protection, phishing prevention, all firewall rules unified on a single screen, and a secure web gateway.
Why Sophos XG Firewall ?
Next-generation network protection
Unified user, application and network control
Blocks unknown threats
More-in-one protection
On-box reports included as standard
Patented Layer-8 Identity control
Potent, powerful & fast
In this courses, feature lecture and hands-on labs, you will learn to install, configure, manage and Sophos XG Firewall from scratch. You will gaining the skills and expertise needed to protect your organization from security threats. The student will get hands-on experience of Sophos XG Firewall in a lab environment.
This course dives deeper into Sophos XG Firewall Configuration to give the students a clear understanding on several topics. Topics covered include Sophos XG Firewall Basic Configuration, Network Zones & Interface Configuration, Firewall Polices, Web Control & Application Control, WAN Load Balancing, SSL VPN & IPsec VPN, Captive Portal &User Authentication, Synchronized Security, Traffic Shaping, SSO Configuration, High Availability ,IPS & Anti –Virus, NAT more.