Sophos Enhances Protection and Incident Response

Sophos announces an update to its Sophos Firewall, now including Sophos NDR Essential, which is free for all customers with an XStream Protection license for Sophos Firewall.

With this integration, Sophos Firewall leverages two dedicated artificial intelligence engines to detect malware communications and communications using algorithmically generated domain names. This new feature, stemming from the Sophos Network Detection and Response probe, aims to identify malware communications even when they are previously unknown or not yet indexed. It complements the Active Threat Response capabilities already implemented in Sophos firewalls.

According to Chris McCormack, Senior Product Marketing Manager at Sophos, “NDR traffic analysis requires substantial processing power. That’s why we’ve adopted a new approach by deploying an NDR solution in Sophos Cloud to offload the heaviest tasks from the firewall.”

Sophos Connect now integrates EntraID for SSO.
This new feature of the VPN client bundled with Sophos Firewall enhances both security and user experience for SSL and IPSEC VPN connections. It is now possible to use EntraID (Azure AD) to authenticate users and implement multi-factor authentication for Sophos Connect and access to the user portal hosted by the firewall.

Other VPN-related improvements include:

  • Improved user interface and usability: Connection types have been renamed from “site-to-site” to “policy-based”, and tunnel interfaces have been renamed “route-based” to make them more intuitive.
  • Dynamic validation of the IP address pool allocated to VPN connections (SSL VPN, IPsec, L2TP, and PPTP) to better resolve potential IP address conflicts.
  • Strict profile enforcement: In IPsec profiles, default values are now excluded to ensure algorithm synchronization, thereby eliminating possible fragmentation of session negotiation packets that could otherwise prevent site-to-site VPN tunnels from being established.
  • Route-based VPN and SD-RED scalability: The system now supports up to 3,000 simultaneously established tunnels. Sophos Firewall solutions can now handle up to 1,000 SD-RED site-to-site tunnels and up to 650 concurrent SD-RED devices.

Additional management improvements include:

  • More flexible DHCP Prefix Delegation (IPv6 DHCP-PD): Now supports /48 to /64 prefixes, improving compatibility with certain internet service providers.
  • Router Advertisement (RA) and DHCPv6 server: Now enabled by default.
  • Resizable table columns: The web admin interface continues to adapt to ultra-wide screens, and many configuration pages now allow column resizing as needed.
  • Enhanced object search functionality: The search field in the SD-WAN routing configuration screen now supports more criteria (route name, ID, objects, object values such as IP addresses and domains, among others). Local ACL rules now also support object name and value searches, including content-based searches.
  • Default configuration changes: Default firewall rules and rule groups previously created during new firewall setups have been removed. Only the default network rule and MTA rules are now provided in the initial configuration. The default firewall rule group and the default gateway probe for custom gateways are both now set to “None” by default.

Secure by Design
Sophos continues to enhance the intrinsic design of its firewalls. The secure-by-design approach includes containerization of specific features and integrity checks on critical operating system files using mathematical checksums. Any checksum mismatch triggers a potential compromise alert, allowing monitoring teams to proactively identify possible security incidents affecting the firewall OS integrity. Incident response and development teams are then able to react swiftly to critical incidents.

Customers can now manually download and deploy this update on any Sophos Firewall equipped with a valid license.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne picture 2025

Rebecca Spayne

Managing
EDITOR

Georgina Turner image

Georgina Turner

Sales
Manager

Afua Akoto image - Security Buyer

Afua Akoto

Marketing Manager

Read the Latest Issue

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Follow us on X

Follow us on X

Click Here

Related News

cyber - securitybuyer.com

The latest trends, challenges and expectations in cyber

Kaseya has released its 2026 Kaseya Cybersecurity Outlook and its 2025 Global IT Trends and Priorities Report. Based on surveys of Managed…
HKC Security - securitybuyer.com

HKC accelerates connected security with SecureHub

HKC Security recently brought together professional security installers from across the UK for a day of innovation and adrenaline…
BioStar X - securitybuyer.com

Suprema Unveils BioStar X

Suprema announced the launch of BioStar X, its most advanced unified security platform. BioStar X unifies world-leading biometric…
Toshiba Innovator - securitybuyer.com

HDDs in the Age of AI

Rainer Kaese of Toshiba Electronics Europe speaks with Rebecca Spayne about HDD dominance in surveillance, technical trade-offs..
IFPO Column - securitybuyer.com

The Hidden Trails of Digital Exhaust

Digital exhaust leaves hidden trails of personal data. Deb Andersen of IMWI Direct, and Yolanda Hamblen, IFPO, explore its risks…
OPSWAT - securitybuyer.com

OPSWAT Collaborates with NetApp

OPSWAT has announced the integration of its MetaDefender Storage Security™ with NetApp® ONTAP®.This solution brings…
Intersec Awards - securitybuyer.com

Intersec Awards 2026 to celebrate the leaders

The Intersec Awards 2026 has officially revealed its shortlist of companies, products, and individuals who will compete for the industry’s..
Dallmeier - securitybuyer.com

Dallmeier: A matter of resilience

Juergen Seiler, CRITIS, Dallmeier introduces video surveillance optimisation in the critical infrastructure space 
Videx - securitybuyer.com

Exhibitor Spotlight – Videx at Sicurezza

Videx Electronics S.p.A., a leading Italian manufacturer of intercom and access control systems since 1986, is set to showcase …
Paxton -securitybuyer.com

Paxton: 40 years of evolution

As Paxton marks 40 years, CEO Adam Stroud reflects on milestones, innovation, and how simplicity, scalability and user experience …
Scroll to Top