pfSense vs. Sophos Firewall

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
pfSense
Score 9.9 out of 10
N/A
pfSense is a firewall and load management product available through the open source pfSense Community Edition, as well as a the licensed edition, pfSense Plus (formerly known as pfSense Enterprise). The solution provides combined firewall, VPN, and router functionality, and can be deployed through the cloud (AWS or Azure), or on-premises with a Netgate appliance. It as scalable capacities, with functionality for SMBs. As a firewall, pfSense offers Stateful packet inspection, concurrent…
$179
per appliance
Sophos Firewall
Score 9.6 out of 10
N/A
Sophos XG Firewall provides comprehensive next-generation firewall protection powered by deep learning and Synchronized Security. Sophos Firewall supplies insights and exposes hidden user, application, and threat risks on the network, and say the product is differentiated by its ability to respond automatically to security incidents by isolating compromised systems, with Security Heartbeat™.N/A
Pricing
pfSenseSophos Firewall
Editions & Modules
SG-1100
$179
per appliance
SG-2100
$229
per appliance
SG-3100
$399
per appliance
SG-5100
$699
per appliance
XG-7100-DT
$899
per appliance
XG-7100-1U
$999
per appliance
XG-1537
$1,949
per appliance
XG-1541
$2,649
per appliance
No answers on this topic
Offerings
Pricing Offerings
pfSenseSophos Firewall
Free Trial
NoYes
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
pfSenseSophos Firewall
Considered Both Products
pfSense
Chose pfSense
PFSense is not a fully featured and supported enterprise-grade solution; however, it does offer a lot of similar functionality at a fraction of the cost for more minor requirements.
Chose pfSense
Fortigate offers an extensive set of features including the Unified Threat Management and a lot of FortiGuard services . pfSense is extremely modular, probably because of its open source "flavour"m but relies on community support. Fortinet ROI depends on the reduced …
Chose pfSense
PfSense beats all other solutions at its price point, hands-down. You can get more features with far less performance, or same performance for much higher cost.
Chose pfSense
pfSense does almost all what the other brands do and the CE Edition is free even if complete.
Chose pfSense
Meraki has a unified management login for all devices, which is nice. It also has decent content filtering, both areas where pfSense is weaker.

Where pfSense far ouclasses Meraki is in the ease of use and the other width of features. These include features such as better VPN …
Chose pfSense
Overall, pfSense is the most complete solution in terms of features included even though it currently lack of a centralised management interface.The Ubiquiti firewall offering is often appealing being well integrated within the Ubiquiti dashboard and it is often a solution of …
Chose pfSense
We were using Sophos XG Firewall in our environment before but we need a product that is customizable & provides low cost high security features. pfSense provided us high security features with customizable options as it's kernel is based on freeBSD.
Chose pfSense
We were using Sophos XG firewall in our environment but when it comes to cost it's more expensive with limited features. After using [pfSense] we are getting more security features at less cost. After pfSense provides a bundle of security features such as anti-spamming, …
Chose pfSense
pfSense offers more options and scales very easily.
Chose pfSense
pfSense is just a more flexible, lower-cost solution—it can be installed (if you wish) on just about any x86 hardware or even virtual machines - the community edition is free and so enables rapid prototyping and low-cost prototyping and lab build out—something that isn't …
Chose pfSense
pfSense is a lot cheaper and has higher firewall throughput per dollar than "enterprise" network appliances. It's also significantly easier to configure and learn. It may not have some of the "enterprise" features or the support level that someone like Cisco has, but for small …
Chose pfSense
pfSense itself is free and can be installed on just about any hardware so from a hardware cost perspective it can beat out anybody. In terms of features it's above many pro-sumer/small business solutions like Ubiquiti. It can't really stand against high-end gear like Cisco but …
Chose pfSense
First of all, I don't need to be a Cisco professional to manage VPN, load balance, multiple WAN/LAN, Firewall and etc. pfSense has an easy-to-use web interface and I can do everything and add packaged add-on services. Moreover, for Small & Medium Enterprise, IT budget is …
Chose pfSense
Pfsense seemed to always be cheaper and just as good as its competitors.
Chose pfSense
I have not seen a single thing that these other products do that pfSense does not. In fact, the performance/throughput of pfSense is better in my opinion.
Chose pfSense
While you can get the performance out of other products, pfSense offers the unique ability to put other services on the same device. Products such as Untagle's NG Firewall and SonicWall's TZ series offer cost effective options for firewall and VPN services, having incoming load …
Chose pfSense
pfSense is a new and innovative platform that has learned from the errors of older systems, which helps it cover the needs that aren't covered by Smoothwall.

Chose pfSense
Before pfSense we were using consumer and small business rated network appliances from Linksys, Cisco, Buffalo and Netgear. We were replacing them on average of every 6-12 months because they'd fail or would offer poor wifi availability.

Switching to pfSense allowed us to use …
Chose pfSense
It's an open source solution can support from 50 to 700 user without sweating and with the half of the standard bundle investment that will take to deploy a Fortigate UTM, or a Cisco ASA, also a Sophos UTM that are quite remarkable units but to pFSense saves you money and will …
Chose pfSense
Real competition was between Pfsense and OpnSense that integrates first the bootstrap Twitter framework. But with OpSense there are configurations that create some problems with a specific client (we've experienced that by creating an IPSec tunnel both with OpSense and …
Chose pfSense
I've used a number of routers like Cisco, Sonicwall, Juniper, Home based routers, etc. pfSense is like most routers but with the benefit of load balancing and multi-wan. Well many support multi-wan but load balancing is usually a separate device like an BIGiP F5 or Cisco CSS.
Chose pfSense
Both products listed above, are very great solutions, but payed ones. If you are looking for open source firewall solution, pfSense is the one. Based on FreeBSD, it has strong security features and is very easy to deploy, configure and manage. pfSense also plays network simple …
Sophos Firewall
Chose Sophos Firewall
Since we already utilize the Sophos Endpoint and its tight integration into their firewall, it was a no brainer to go with it.
Chose Sophos Firewall
Very simple to manage, several features, and a report included.
Chose Sophos Firewall
We decided to use Sophos XG Firewall because it is a reliable and reputed cybersecurity product.
Chose Sophos Firewall
We selected the Sophos Firewall because of its comprehensive security, ease of use, Scalability and increase the productivity.
Chose Sophos Firewall
We have been a Sophos customer for the most part but i have seen some other offerings from SonicWall, Barracuda, and Cisco. While they all offer nice products, we've always been content with our Sophos XG firewalls, especially as they release more and more features/etc.
Chose Sophos Firewall
I was a big fan of Cisco ASA products, but when I saw all of the security feature differences between both firewalls, I moved to Sophos devices. Its sandbox, IPS, and many more features are really advanced. Cisco does not provide features like this.
Chose Sophos Firewall
Cisco ASA is not [a] true next generation firewall if you want to protect from 7 layers and malware attacks then you need firepower services but this service is very costly. In Sophos all the advanced security features are [less] cost[ly].
Chose Sophos Firewall
Sophos XG Firewall provides easy integration with Active directory & LDAP Servers so that we can implement single sign on (SSO) for users. Also the content filtering & inspection feature protect us from bad actors.
Chose Sophos Firewall
The firewall that was in use at the first location before expanding was a cheaply made open source box that couldn't do much even as a basic firewall. We had looked at various companies but came to the conclusion that Sophos was the right fit for us and it has been that way for …
Chose Sophos Firewall
It is to very little surprise that we selected Sophos UTM at our first use. Then, we upgraded to XG Firewall and the operation is very smoothly done.
TrustRadius Insights
pfSenseSophos Firewall
Highlights

TrustRadius
Research Team Insight
Published

pfSense, from Netgate and Sophos XG Firewall serve as entry level firewalls or options for small and midsize businesses. The Sophos XG Firewall is a full-featured firewall bundling Sophos’ security software and appliances. pfSense is an open source software solution based on the FreeBSD OS. It can run on Netgate’s own SG & XG appliances, as well as deploy virtually on AWS or Azure or on commodity computers, transforming the machine into a small or home office firewall, for an almost no-cost solution.

Sophos XG Firewall appears most in the middle-market, while pfSense appears most in budget constrained small businesses. They are competing solutions, however it is possible to use the Sophos XG Firewall for security with pfSense for other features like VPN, load balancing, etc.

Sophos XG Firewall has a free “home” edition which may be useful for single branch businesses or home offices as a basic firewall on commodity hardware; this option presents a direct alternative to the open source pfSense.

Features

There are some advantages to using pfSense and Sophos XG Firewall.

It is pfSense’s ease of use for ancillary firewall features where the solution shines. It has an effective and reliable VPN, and presents great NAT functionality. Its traffic control and load balancing are also excellent for the price point.

For the middle market Sophos XG Firewalls present little downside. They are easy to set up with antivirus to lockdown malware. The UI is attractive, clear, and easy to navigate. Product users describe Sophos as a security leader that frequently updates and supports its products well. These updates  make the Sophos XG Firewall an easy to use solution.

Limitations

pfSense and Sophos XG Firewall might not be the right choice for a network, as these are both mid-tier or entry level solutions.

Additionally, pfSense is almost DIY, which can leave the administrator struggling to configure the security product as needed. There is little support aside from the open source community, and without enterprise grade support users are stuck with trial and error for complex set up and tasks. A sophisticated, patient user is a requirement to get the most out of pfSense.

In contrast, Sophos XG Firewalls have complex licensing varying by feature and region, which may be difficult to track, but it may help keep overall costs down. Sophos XG Firewall users surface more specific complaints in complex use cases and deployments. For instance, reviewers cite  lack of clear diagnostics, confusing configuration workflows, inadequate bandwidth throttling, and other general breakdown of administrator confidence. There may be a network complexity ceiling beyond which the Sophos XG Firewall is not ideal.

Pricing

pfSense is open source and doesn’t cost anything on its own. The only related costs are from associated hardware, or paying a little extra to find a sophisticated admin to get it to do what is required.

Sophos provides pricing on request but their XG Firewalls are available from VARs and online resellers, and can run a small business about $300. Most models through the 200 and 300 product lines vary in cost from about $2k to $3k, while the high end XG 750 with 3-year fully featured UTM license (3-year) can be started now for about $90k. A license of some kind is required for NGFW features. Sophos’ associated EnterpriseGuard Plus license can be started for under $2000 (3-year license, XG135), to $21.5k (3-year, for the XG-430).

For a home office, Sophos XG Firewall software can be installed on an Intel-compatible machine at no cost (it will overwrite any existing Operating System). This may be an option for small, single branch locations that want to set up basic firewall capabilities on commodity hardware, and provides a free trial to familiarize users with the product.

Features
pfSenseSophos Firewall
Firewall
Comparison of Firewall features of Product A and Product B
pfSense
7.6
Ratings
13% below category average
Sophos Firewall
9.5
Ratings
10% above category average
Identification Technologies5.00 Ratings9.50 Ratings
Visualization Tools7.00 Ratings9.60 Ratings
Content Inspection4.00 Ratings9.50 Ratings
Policy-based Controls10.00 Ratings9.70 Ratings
Active Directory and LDAP7.00 Ratings9.60 Ratings
Firewall Management Console9.50 Ratings9.70 Ratings
Reporting and Logging8.00 Ratings9.60 Ratings
VPN10.00 Ratings9.70 Ratings
High Availability10.00 Ratings9.70 Ratings
Stateful Inspection7.00 Ratings9.60 Ratings
Proxy Server6.10 Ratings8.00 Ratings
Best Alternatives
pfSenseSophos Firewall
Small Businesses
Sophos UTM
Sophos UTM
Score 8.1 out of 10
pfSense
pfSense
Score 9.9 out of 10
Medium-sized Companies
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.6 out of 10
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.6 out of 10
Enterprises
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 10.0 out of 10
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 10.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
pfSenseSophos Firewall
Likelihood to Recommend
9.6
(0 ratings)
9.5
(0 ratings)
Usability
10.0
(0 ratings)
10.0
(0 ratings)
Support Rating
-
(0 ratings)
9.1
(0 ratings)
User Testimonials
pfSenseSophos Firewall
Likelihood to Recommend
pfSense is incredibly budget friendly and capable for organizations of all sizes. My specific scenario, working for a non-profit organization, requires budget consciences decisions without compromising security and function. pfSense has helped tremendously in accomplishing this. It specifically tackles advanced routing, static routing, remote access, intrusion prevention, in a single platform, mostly available for free.
Read full review
It is well-suited for small, medium, and large organizations looking for comprehensive cybersecurity protection. It will not only safeguard their network from cyberattacks but also provide them with many advanced features like deep packet inspection, centralized management, web filtering, application control, etc. in one place. It will help them optimize bandwidth and ensure continued connectivity.
Read full review
Pros
  • Easy to use. Good user interface design! Easy to understand and easy to set up.
  • Lower hardware requirement. 3 years ago, we used an old PC to run it. Now, we have changed to a router device with Celeron CPU and 8GB RAM. It runs smoothly with a 1000G commercial broadband.
Read full review
  • Web filtering. This allows us to monitor web usage and block certain categories from being access at the perimeter.
  • Application Control. With application control we can block certain applications that get categorized from working accessing the Internet.
  • Synchronized Security. When utilizing the Sophos Endpoint product you can use Synchronized Security to minimize Lateral Movement in a network. If a machine is shows a Red status you can auto-isolate it and it is unable to communicate with anything else on the network.
Read full review
Cons
  • There is no API for making changes. This can be a hindrance in environments where auto-deploying something needs firewall rules or HAProxy configs updated. Since all settings are stored in an XML file and then configs are generated from that, even manually updating config files cannot be done.
  • Beware that some network cards can have issues. pfSense is based on FreeBSD, so it's best to look on their compatibility list before deploying.
Read full review
  • If using Endpoint security and the Firewall it would be nice to have an easier back and forth between the portals rather than have two separate tabs open. Especially if using more than one in multiple locations.
  • If dealing with different revisions options are moved around and sometimes in places that doesn't normally seem like they should be there.
Read full review
Usability
pfSense can be a very elementary firewall but can also be as comples as you want, according your needs. I'd always reccomend a HA solution when used in a company and, for bigger companies, commercial license is recommended. It's also very adptable to everyone's needs.
Read full review
Because this is a user-friendly interface, and anyone can use it there are multiple articles and guidelines available, it has advanced-level security features. they provide VPN solutions all the features are very practical, SSID MAC-based authentications web control, Firewall rules segregation of the rules and policies, On-premises Active directory single sign-on feature is also available.
Read full review
Support Rating
pfSense+ basic provides "As Available" email support. pfSense+ Pro offers 24 hr turn around email support. pfSense+ Enterprise offers 24/7 phone support.
Read full review
As we are all addicted to graphics-oriented interfaces for all our life products. Easy to manage and access as a good way of using anything
Read full review
Alternatives Considered
PFSense is not a fully featured and supported enterprise-grade solution; however, it does offer a lot of similar functionality at a fraction of the cost for more minor requirements.
Read full review
I was a big fan of Cisco ASA products, but when I saw all of the security feature differences between both firewalls, I moved to Sophos devices. Its sandbox, IPS, and many more features are really advanced. Cisco does not provide features like this.
Read full review
Return on Investment
  • pfSense has only had positive impacts on our company. We are not a huge company so not having to buy licenses to get all these features have been excellent.
  • I was not around when our current sysadmin decided to use pfSense, but I am assuming from day one it was probably a 100% return on investment since it does everything we need it to and it was open source software.
Read full review
  • True UTM device.
  • Very Active customer help for any help.
  • Easy license and cost effective.
  • Should [do] more work on logging and reporting.
Read full review
ScreenShots

Sophos Firewall Screenshots

Screenshot of Sophos Firewall v17.5 Control Center