Email us at sales@ocgl.net

Managed Business Solutions

Sophos Firewall

Why Does Your Firewall Choice Matter?

The firewall at the edge of your network is the one device every packet has to pass through. It decides what gets in, what gets out, and what happens when something inside has already been compromised. It is also, in most small and mid-sized businesses, a single appliance that was sized years ago against traffic patterns that no longer exist — and when it fails, nobody works.

OPUS designs, deploys and manages Sophos firewalls for businesses across Canada. We are a Sophos Platinum Solution Partner, one of a limited group in Canada to hold that tier, which gives us direct engineering escalation and pricing that a reseller badge does not. What that means for you is that the person specifying your firewall has deployed a great many of them, and can tell you when you do not need the model you were about to buy.

One Stop Shop

Access to diverse expertise

Round-the-clock support

Sophos XGS firewalls, sized and deployed for your network.

Sophos

What we deploy: Sophos XGS

Sophos XGS is the firewall platform we standardise on. It does the work you would expect at the perimeter — traffic inspection, intrusion prevention, web and application control, and VPN for both remote workers and site-to-site links — with reporting that a human being can actually read.

The part that matters more in practice is that it does not work alone. A Sophos firewall exchanges information with Sophos endpoint protection, so a machine that has been compromised can be identified and isolated at the network level instead of being left to spread sideways. That coordination is the reason we recommend the platform, rather than assembling a perimeter out of products that have no idea the others exist.

High availability, and why a second unit is not an extravagance

A single firewall is a single point of failure. Most businesses know this and accept it anyway, because the second unit looks like an expense with nothing to show for it — right up to the afternoon the first one dies and the entire company stops.

Where the business case supports it, we deploy Sophos XGS in a high-availability pair: two units configured as a failover cluster, so that if one fails the other carries the traffic. Put two internet service providers behind that and the loss of a single circuit or a single appliance stops being an outage and becomes something somebody looks at in the morning.

Whether you need that is a real question rather than a foregone conclusion, and the answer depends on what an hour of downtime actually costs you. We will tell you when one unit with a support contract and a sensible replacement plan is the better value.

What we establish before recommending a model

Firewall sizing done from a price list is how a business ends up with an appliance that throttles its own internet connection eighteen months later. Before we quote anything, we establish:

Your real bandwidth, including what you are contracted to grow into rather than what you use today. Users and devices behind the firewall, and how that number moves. Which inspection features you intend to run, because deep packet inspection and TLS inspection both cost throughput and the headline figure on a datasheet assumes you have turned most of it off. VPN load — how many tunnels, how many remote users, how much traffic across them. What your switching and wireless can support, since a firewall is only as useful as the network behind it.

Then we size for the environment you will have in three years. If that is the same as the one you have now, we will say so and quote accordingly.

How a firewall project runs

Assess. We document what is at your edge now, what it is configured to do, and which of those rules anyone can still explain. Firewall rulebases accumulate; a surprising proportion of what we find is left over from a system that was decommissioned years ago.

Design. You get a proposed configuration, a bill of materials, and the reasoning behind the sizing decisions, including the trade-offs we made and what we deliberately left out.

Migrate. Cutovers are scheduled around your business, not ours. Rules are rebuilt deliberately rather than imported wholesale, because a migration is the one good opportunity to stop carrying forward a decade of exceptions.

Manage. A firewall that nobody maintains is a firewall that quietly stops protecting you.

Ongoing management

Left alone, edge security decays in predictable ways: firmware falls behind, rules accumulate, certificates expire on a Sunday, and alerts arrive somewhere nobody is looking. Under our managed IT solutions the firewall is maintained on a defined cycle — firmware currency, rule review, log and alert monitoring, and licence and certificate expiry tracked before they bite. Our support desk is open 6:00 am to 11:00 pm Pacific, seven days a week.

Sophos beyond the perimeter

A next-generation firewall is necessary and it is not sufficient. It sees traffic crossing your edge; it does not see a credential used from a legitimate device, and it cannot investigate on your behalf at two in the morning. That is what detection and response is for, which is why Sophos MDR is included as standard with OPUSCare rather than sold as an upgrade. The full picture of how we use the Sophos platform sits on our cyber security page, and we have written more about the vendor relationship in our overview of Sophos cybersecurity. Sophos’s own current product portfolio is also syndicated on our Sophos solutions page.

Selected engagements

A new cold-storage facility

Anonymised, as all our case studies are. A cold-storage operator building a new facility brought us in during the design stage. Edge security was not on their list — they had approached us about wireless capable of running continuously at around -20°C. The firewall came up because we raised it.

What we delivered was a pair of Sophos XGS firewalls in a high-availability failover configuration behind two internet service providers, commissioned alongside the wired and wireless networks we had designed into the building with their architect. Planning ran about five weeks with site visits throughout construction. The go-live date was met, and activation completed without issues.

The full engagement, including the wireless design for the freezer environment, is described on our IT consulting page.

Why businesses buy Sophos through OPUS

The Platinum Solution Partner tier is the short answer: direct escalation into Sophos engineering when something is genuinely wrong, and commercial terms that let us include things other providers charge for. The longer answer is that we have been building and running networks for over twenty years, so the firewall arrives as part of a design that accounts for your switching, your wireless and your IT infrastructure rather than as a box bolted onto whatever was already there.

We are vendor-aligned, not vendor-captive. Sophos is what we recommend and it is not the only thing we will discuss. We are on site across Metro Vancouver and we support clients across Canada, coast to coast.

Common questions

Do we have to replace our current firewall to work with you? No. If what you have is adequately sized and still supported, the useful work is usually a configuration and rule review rather than a purchase. We will tell you if that is the case.

Can you take over a Sophos firewall someone else installed? Yes, and it is a common starting point. We audit the existing configuration first, because inheriting a rulebase without reading it is how problems get adopted rather than solved.

Do we need a high-availability pair? It depends entirely on what downtime costs you. For a single office that can tolerate a few hours, probably not. For a facility where operations stop without connectivity, the second unit is cheaper than the outage.

Who applies firmware updates? We do, on a defined maintenance cycle, in a scheduled window — not whenever an update happens to appear.

Firewall replacement inside a provider transition

A shipping company of 80-plus users came to us to take over their managed services from an incumbent provider. Discovery found their firewalls approaching end of life, and we replaced them with Sophos XGS firewalls in high-availability pairs during a managed transition, improving throughput and availability without a disruptive cutover. That engagement also replaced an unmanaged EDR product with Sophos MDR Complete; it is described in full on our managed IT solutions page.

Where Will Your Business Go Tomorrow?

Talk to Our Vancouver Team