Overview:
Note: XGS 87/87w and XGS 88/88w don't support on-appliance reporting.
Much More Than a Firewall
Sophos Firewall and XGS Series appliances are at the heart of the world’s best network security platform. Consolidate your network protection with our integrated and extensible platform to secure your hybrid networked world. Unlock supreme desktop performance, improved energy efficiency, and a wealth of new high-speed connectivity options.
Sophos second-generation XGS Series desktop appliances deliver double the performance of our first-generation models while cutting power consumption in half. All these desktop firewalls include 2.5 GE interfaces, allowing traffic to flow freely and without bottlenecks, from your firewall to your 2.5 GE switch to your Wi-Fi 6 access point.
Customers with noise-sensitive environments such as healthcare, education, and retail will love the whisper-quiet operation of the fanless XGS 88 and XGS 108 models. Using the expansion bay, an optional 5G module adds either redundant cellular connectivity or cost-effective 5G fixed wireless access (FWA).
The XGS 88 to XGS 128 models feature a streamlined, single-CPU architecture that utilizes virtual FastPath technology for traffic acceleration (in combination with Sophos Firewall OS v21 and higher). As our gateway model to the distributed edge, the XGS 138 boasts a dedicated Xstream Flow processor for hardware acceleration and two 10 GE SFP+ interfaces for high-speed fiber connectivity. All models except the XGS 138 are optionally available with built-in Wi-Fi.
Product highlights
- All protection features are supported on every XGS 1xx desktop model and most are available on XGS 88 and XGS 88w.
- Accelerated performance: Up to double the throughput of Gen.1 models plus Xstream virtual FastPath acceleration for IPsec VPN (XGS 88 to XGS 128) in combination with SFOS v21 and higher
- High-speed connectivity built in: 2.5 GE interfaces on everymodel,two built-in 10 GE SFP+ interfaces on the XGS 138, and Wi-Fi 6 (802.11ax) integrated on all w-models with concurrent use of the 2.4 and 5 GHz bands for better performance
- Power and environment: Up to 50% lower power consumption, fanless XGS 88 and 108 models for whisper-quiet operation, optimized thermal design for XGS 118 and above, and redundant power option for all XGS 1xx models
- Optional connectivity: New 5G module available exclusively for Gen.2 models for more cost-effective redundant connectivity
- Streamlined hardware architecture: The XGS 88 to XGS 128 models boast a new single-CPU architecture while the XGS 138 has a refreshed dual-processor architecture
Powerful Protection and Performance
Sophos Firewall includes the latest advanced protection technologies and threat intelligence, including:
- Streaming DPI engine with web protection and IPS
- Accelerated TLS 1.3 encrypted traffic inspection
- Zero-day AI and machine learning analysis
- Real-time cloud sandboxing
- DNS Protection
The best part is, you don' t need to compromise on performance. This is thanks to our programmable Xstream architecture. It offloads benign traffic flows and crypto operations as well as VPN and select application routing to accelerate these network traffic flows and create performance headroom for traffic that actually needs deep packet inspection.
Sophos Firewall leverages the Sophos Cloud to ensure that your organization is protected from the latest threats and further maximize your performance. You get the latest AI and machine learning technology from SophosLabs working to identify previously unseen threats and malicious URLs. Using a common cloud, any new threat attacking a single Sophos customer is instantly shared across all our customers, blocking it everywhere. In addition, offloading this analysis from your firewall to the cloud boosts your performance even further.
Sophos XGS Series Appliances
All XGS Series firewall appliances are built upon a dual-processor architecture, combining a high-performance, multi-core CPU with a dedicated Xstream Flow Processor for targeted acceleration at the hardware level. This gives you all the flexibility and adaptability of an x86 based firewall plus a significant performance boost over legacy firewall designs.
| Model |
Tech Specs |
Throughput |
| XGS 88(w) |
Gen.2 Desktop* |
4/- (4) |
Wi-Fi 6 |
n/a |
9,900 |
6,000 |
2,000 |
600 |
| XGS 108(w) |
Gen.2 Desktop* |
7/-(7) |
Wi-Fi 6 |
Optional: 2nd power supply, 5G module |
12,500 |
8,250 |
2,500 |
800 |
| XGS 118(w) |
Gen.2 Desktop* |
10/1(10) |
Wi-Fi 6 |
Optional: 2nd power supply, 5G module |
15,500 |
13,000 |
3,250 |
1,100 |
| XGS 128(w) |
Gen.2 Desktop* |
10/1(10) |
Wi-Fi 6 |
Optional: 2nd power supply, 5G module |
19,100 |
15,050 |
4,000 |
1,450 |
| XGS 138(w) |
Gen.2 Desktop* |
8/1(8) |
n/a |
Optional: 2nd power supply, 5G module |
19,100 |
6,600 |
4,750 |
1,700 |
| XGS 87(w) |
Gen.1 Desktop |
5/- (5) |
Wi-Fi 5 |
n/a |
3,850 |
3,000 |
850 |
375 |
| XGS 107(w) |
Gen.1 Desktop |
9/- (9) |
Wi-Fi 5 |
Optional: 2nd power supply |
7,000 |
4,000 |
1,110 |
420 |
| XGS 116(w) |
Gen.1 Desktop |
9/1 (9) |
Wi-Fi 5 |
Optional: 2nd power supply, 3G/4G, 5G, Wi-Fi** |
7,700 |
4,800 |
2,160 |
650 |
| XGS 126(w) |
Gen.1 Desktop |
14/1 (14) |
Wi-Fi 5 |
Optional: 2nd power supply, 3G/4G, 5G, Wi-Fi** |
10,500 |
5,500 |
2,700 |
800 |
| XGS 136(w) |
Gen.1 Desktop |
14/1 (14) |
Wi-Fi 5 |
Optional: 2nd power supply, 3G/4G, 5G, Wi-Fi** |
11,500 |
6,350 |
3,000 |
950 |
| XGS 2100 |
1U Short |
10/1 (18) |
n/a |
Optional: external power supply |
30,000 |
17,000 |
5,000 |
1,100 |
| XGS 2300 |
1U Short |
10/1 (18) |
n/a |
Optional: external power supply |
39,000 |
20,500 |
5,550 |
1,450 |
| XGS 3100 |
1U Short |
12/1 (20) |
n/a |
Optional: external power supply |
47,000 |
25,000 |
7,400 |
2,470 |
| XGS 3300 |
1U Short |
12/1 (20) |
n/a |
Optional: external power supply |
58,000 |
31,100 |
10,000 |
3,130 |
| XGS 4300 |
1U Long |
12/2 (28) |
n/a |
Optional: external power supply |
75,000 |
62,500 |
25,200 |
8,000 |
| XGS 4500 |
1U Long |
12/2 (28) |
n/a |
Optional: internal power supply |
80,000 |
75,550 |
31,850 |
10,600 |
| XGS 5500 |
2U |
16/3 (48) |
n/a |
Built in: redundant power, SSDs, fans |
100,000 |
92,500 |
46,000 |
13,500 |
| XGS 6500 |
2U |
20/4 (68) |
n/a |
Built in: redundant power, SSDs, fans |
120,000 |
109,800 |
53,500 |
16,000 |
| XGS 7500 |
2U |
22/4 (70) |
n/a |
Built in: redundant power, SSDs, fans |
160,000 |
117,000 |
70,000 |
19,500 |
| XGS 8500 |
2U |
22/4 (70) |
n/a |
Built in: redundant power, SSDs, fans |
190,000 |
141,000 |
92,500 |
24,000 |
* All Gen.2 Desktop models include two or more 2.5 GE ports
** 2nd Wi-Fi module option for XGS 116w, 126w and 136w only
Performance Test Methodology
- General: Maximum throughput measured under ideal test conditions using industry standard Keysight-Ixia BreakingPoint test tools. Actual performance may vary depending on network conditions and activated services.
- Firewall: Measured using HTTP traffic and 512 KB response size.
- Firewall IMIX: UDP throughput based on a combination of 66 byte, 570 byte and 1518 byte packet sizes.
- IPS: Measured with IPS with HTTP traffic using default IPS ruleset and 512 KB object size.
- IPsec VPN: HTTP throughput using multiple tunnels and 512 KB HTTP response size.
- TLS inspection: Performance measured with IPS with HTTPS sessions and different cipher suites.
- Threat Protection: Measured with Firewall, IPS, Application Control, and malware prevention enabled using HTTP 200 KB response size.
Xstream
All the next-gen protection, performance and value you need to power even the most demanding networks. Also available with the XGS Series model of your choice included.
Base Firewall Features
- Networking and SD-WAN: Wireless, SD-WAN, application aware routing, traffic shaping
- Protection and Performance: Xstream Architecture with Network Flow FastPath, TLS 1.3 inspection, Deep-Packet Inspection
- SD-WAN and VPN: Xstream SD-WAN, IPsec/SSL site-to-site and remote access VPN (unlimited), SD-RED site-to-site
- Reporting: Historical on-box logging and reporting, Sophos Fusion cloud reporting (seven-day data retention)
Network Protection
- Xstream TLS Inspection: TLS 1.3 inspection with prepackaged exceptions
- Xstream DPI engine: streaming deep-packet inspection
- IPS: Next-gen Intrusion Prevention
- ATP: Advanced Threat Protection
- Synchronized Security Heartbeat: integration with Sophos Endpoints to identify and isolate threats
- Clientless VPN: HTML5
- SD-RED VPN: Manage SD-RED devices
- Reporting: Extensive network and threat reporting
Web Protection
- Xstream TLS Inspection: TLS 1.3 inspection with prepackaged exceptions
- Xstream DPI engine: streaming deep-packet inspection
- Web Control: by user, group, category, URL, keyword
- Web Threat Protection: malware, PUA, malicious JavaScript, pharming
- App Control: by user, group, category, risk, and more
- Synchronized App Control: integration with Sophos endpoints to identify unknown apps
- Synchronized SD-WAN: utilizing Synchronized App Control to route unknown apps
- Reporting: Extensive web and app reporting
Zero-Day Protection
- Xstream TLS Inspection: TLS 1.3 inspection with prepackaged exceptions
- Xstream DPI engine: streaming deep-packet inspection
- Zero-Day Threat Protection: analyze all unknown files using AI, ML, and sandboxing
- Powered by SophosLabs Intelix: cloud-based intelligence and analysis
- Machine Learning: using multiple deep learning models
- Cloud Sandboxing: dynamic runtime analysis of unknown files
- Reporting: Extensive threat intelligence analysis reporting
DNS Protection and Xstream Protection Bundle-Only Features
- Domain name resolution service: Backed by SophosLabs and powered by AI to block malicious or unwanted URLs
- Active Threat Response: For Sophos MDR/XDR threat feeds
- Active Threat Response: For third-party regional/vertical threat feeds
Sophos Fusion Management
- Group Firewall Management: Synchronized policy across firewall groups
- Backup and firmware updates: storage and scheduling
- Zero-touch deployment: for new firewalls from the cloud
Sophos Orchestration
- SD-WAN Orchestration: Point and click Site-to-Site VPN Orchestration
- Cloud Firewall Reporting: Multi-firewall reporting with save, schedule and export reports (30-day data retention)
- XDR and MDR Connector: Support for XDR and MDR services
Licensing and Deployment
We recommend the Xstream Protection bundle for the ultimate in security, but if you prefer to customize your protection, all subscriptions are also available for individual purchase.
| Xstream Protection Bundle: |
| Base License |
Networking, wireless, Xstream Architecture, unlimited remote access VPN, site-to-site VPN, reporting |
| Network Protection |
Xstream TLS/DPI, IPS, Active Threat Response with Sophos X-Ops threat feeds, Heartbeat, SD-RED, reporting |
| Web Protection |
Xstream TLS and DPI engine, Web Security and Control, Application Control, reporting |
| Zero-Day Protection |
Machine Learning and Sandboxing File Analysis, reporting |
| Orchestration |
SD-WAN VPN Orchestration, Firewall Advanced Reporting (30-days), MDR/XDR Connector |
| DNS Protection (not sold separately) |
Cloud-based DNS service for web security and compliance |
| Bundle-only Features (not sold separately) |
Active Threat Response with MDR/XDR threat feeds and third-party threat feeds |
| Enhanced Support |
24/7 support, feature updates, advanced replacement hardware warranty for term |
Custom Protection
You can choose the Standard Protection Bundle or purchase any of the protection modules separately.
| Standard Protection Bundle: |
| Base License |
Networking, wireless, Xstream Architecture, Xstream SD-WAN, unlimited remote access VPN, site-to-site VPN |
| Network Protection |
Xstream TLS and DPI engine, IPS, ATP, Security Heartbeat, manage SD-RED, reporting |
| Web Protection |
Xstream TLS and DPI engine, Web Security and Control, Application Control, reporting |
| Enhanced Support |
24/7 support, feature updates, advanced replacement hardware warranty for term |
| Additional Protection Modules: |
| Email Protection |
On-box antispam, AV, DLP, encryption |
| Web Server Protection |
Web Application Firewall |
Sophos Fusion Management and Reporting:
| Sophos Fusion Management and Reporting (included at no charge): |
| Sophos Fusion Management |
Group firewall management, backup management, firmware update scheduling |
| Sophos Firewall Reporting |
Prepackaged and custom report tools with seven days cloud storage for no extra charge |
Additional Protection:
| Additional Protection Services, Products and Modules: |
| Managed Detection and Response |
24/7 threat hunting, detection and response delivered by an expert team |
| Sophos Intercept X Endpoint with XDR |
Sophos Fusion managed next-gen endpoint protection with EDR |
| Zero Trust Network Access |
A ZTNA gateway is integrated into your firewall |
| Sophos Email |
Sophos Fusion managed antispam, AV, DLP, encryption |
| Sophos Switch |
Cloud-managed access layer switches |
| Sophos Wireless |
Scalable, cloud-managed Wi-Fi |
Support
A support subscription is required to receive firmware upgrades. Enhanced support is included in all protection bundles, but you can enhance your support experience further by upgrading.
| Additional Support Options: |
| Enhanced Plus Support Upgrade |
Upgrade your support with VIP support, hardware warranty for add-ons, TAM option (extra cost) In Active/Passive HA scenarios, Enhanced Plus support is required in the primary device to be eligible for Advanced RMA on the passive device |
Cloud, Virtual and Software Appliance Licensing Options
If you’re deploying Sophos Firewall in the cloud, in a virtual environment, or as software on your own hardware, the licensing guide below can help you find the right option.
| Model |
Equivalent AWS instance |
Equivalent Azure VM |
Software/Virtual License* |
| XGS 88(w)/87(w) |
t3.medium |
- |
2C4 |
| XGS 108(w)/107(w) |
c5.large |
Standard_F2s_v2 |
- |
| XGS 118(w)/116(w) |
- |
- |
4C6 |
| XGS 2100 |
c5.xlarge |
- |
- |
| XGS 2300 |
m5.xlarge |
Standard_F4s_v2 |
6C8 |
| XGS 3100 |
c5.2xlarge |
Standard_F8s_v2 |
8C16 |
| XGS 4300 |
c5.4xlarge |
Standard_F16s_v2 |
16C24 |
| XGS 5500 |
c5.9xlarge |
Standard_F32s_v2 |
Unlimited |
* Based upon CPU cores and RAM
Deployment Options
XGS Series
Purpose-built devices to provide the ultimate in performance.
AWS/Azure
Protect your network infrastructure in the AWS or Azure cloud.
Virtual
Install on VMware, Citrix, Microsoft Hyper-V, and KVM.
Software
Install the Sophos Firewall OS image on your own Intel hardware or server.
Cloud
Sophos Firewall offers the very best network visibility, protection, and response to secure your public, private, and hybrid cloud environments.
As an AWS Advanced Technology Partner, Sophos is a validated AWS Security Competency vendor, AWS marketplace seller, and AWS Public Sector Partner.
Sophos Firewall is now available in the AWS marketplace with autoscaling support with either a pay-as-you-go (PAYG) license model, or bring your own license (BYOL) to best fit your needs.
Sophos Firewall is certified and optimized for Azure and is available in the Microsoft Azure Marketplace. Take advantage of the free test drive or the flexible PAYG or BYOL licensing options.
Sophos Firewall is Nutanix AHV and Nutanix Flow Ready, bringing the world’s best next-gen firewall visibility, protection, and response to the industry’s leading Hyper Convergence Infrastructure (HCI) platform. Take advantage of a 30-day free trial using our KVM image and flexible licensing
Virtual and Software
Sophos Firewall supports a broad range of virtualization platforms and can also be deployed as a software appliance on your own x86 Intel hardware:
Protection Modules
You can choose from a number of modules to customize the protection offered by your firewall to your individual needs and deployment scenario.
Base Firewall
The Sophos Firewall Base License includes the Xstream Architecture, networking, wireless, SD-WAN, VPN, and reporting.
Xstream SD-WAN and Networking
Includes all networking, routing, and SD-WAN capabilities including zone-based stateful firewall, NAT, VLAN, SDWAN profiles, performance-based WAN link selection and monitoring, load balancing, zero-impact WAN link transitions, and Xstream FastPath acceleration of trusted application traffic.
VPN
Provides standards-based site-to-site and remote access VPN (free up to the capacity of the firewall) with support for IPsec and SSL. Sophos Connect remote access VPN client for Windows and Macs offers seamless and easy deployment and configuration options. SD-RED layer 2 siteto-site tunnels offers a light-weight robust VPN alternative.
Reporting
Extensive on-box reporting provides valuable insights into threats, users, applications, web activity, and much more. Note that specific reporting functionality may be dependent on other protection modules to get the full benefits (for example, Web Protection or web and app reports).
Xstream Architecture
Enables high performance TLS 1.3 inspection, deep-packet inspection, and network flow FastPath to accelerate trusted SaaS, SD-WAN, and cloud application traffic. Note that Network and Web Protection are required to get the full benefits of the Xstream Architecture.
Secure Wireless
Built-in wireless controller for Sophos APX wireless access points. Plug-and-play access point discovery makes setup easy. Support for multiple SSIDs, hotspots, guest networks, and the diverse encryption and security standards.
Network Protection
All the protection you need to stop sophisticated attacks and advanced threats while providing secure network access to those you trust.
Next-Gen Intrusion Prevention System
Provides advanced protection from all types of modern attacks. It goes beyond traditional server and network resources to protect users and apps on the network as well.
Advanced Threat Protection
Instant identification and immediate response to today’s most sophisticated attacks. Multi-layered protection identifies threats instantly and Security Heartbeat provides an emergency response.
Security Heartbeat
Creates a link between your Sophos Fusion protected endpoints and your firewall to identify threats faster, simplify investigation, and minimize impact from attacks. Easily incorporate Heartbeat status into firewall policies to automatically isolate compromised systems.
Advanced VPN technologies
Adds unique and simple VPN technologies, including our clientless HTML5 self-service portal that makes remote access incredibly simple plus management for our exclusive light-weight secure SD-RED (Remote Ethernet Device) VPN technology.
Web Protection
Unmatched visibility and control over all your user’s web and application activity.
Powerful user and group web policy
Provides enterprise-level Secure Web Gateway policy controls to easily manage sophisticated user and group web controls. Apply policies based upon uploaded web keywords indicating inappropriate use or behavior.
High-performance traffic scanning
Optimized for top performance, our Xstream SSL inspection provides ultra-low latency inspection and HTTPS scanning while maintaining performance
Application Control and QoS
Enables user-aware visibility and control over thousands of applications with granular policy and traffic-shaping (QoS) options based on application category, risk, and other characteristics. Synchronized Application Control automatically identifies all the unknown, evasive, and custom applications on your network.
Advanced Web Threat Protection
Backed by SophosLabs, our advanced engine provides the ultimate protection from today’s polymorphic and obfuscated web threats. Innovative techniques like JavaScript emulation, behavioral analysis, and origin reputation help keep your network safe.
Zero-Day Protection
AI-driven static and dynamic file analysis techniques combine to bring unprecedented threat intelligence to your firewall and so effectively identify and block ransomware and other known and unknown threats.
Powered by SophosLabs
Powered by the industry-leading SophosLabs, the Zero-Day Protection subscription includes a fully cloud-based threat intelligence and threat analysis platform. This provides deep learning-based file analysis, detailed analysis reporting, and a threat meter to show the risk summary for a file
Threat Intelligence Analysis Reporting
Rich intelligence reports provide you with much more than just a ‘good,' ‘bad,' or ‘unknown’ verdict. Full insight into the nature and capabilities of a threat are delivered through the use of data science and SophosLabs research.
Dynamic File Analysis
Execute a file in a secure cloud-based sandbox to observe its behavior and intent. Screenshots provide added insight into any key events during the analysis.
Static File Analysis
By harnessing the power of multiple machine learning models, global reputation, deep file scanning, and more, you can quickly identify threats without the need to execute the files in real time.
Orchestration
Sophos Fusion cloud-managed VPN orchestration, firewall reporting, and MDR/XDR integration.
Sophos SD-WAN Orchestration
Makes VPN orchestration easy. Wizard-based tunnel configuration helps create full mesh networks, hub-andspoke models, or complex tunnel setups between multiple firewalls a quick point-and-click exercise. Seamlessly integrates multiple WAN link and SD-WAN functionality and routing optimizations to improve resilience and performance.
Firewall Reporting Advanced (30-day)
Cloud-based reporting with several pre-packaged common reports for threats, compliance, and user activity. Includes advanced options for creating custom reports and views with the option to save, schedule or export your custom reports. Includes 30 days of log data retention with the option to add additional storage for additional historical reporting needs.
MDR/XDR Connector
Sophos MDR provides optional 24/7 threat hunting, detection and response delivered by an expert team as a fully-managed service. Sophos XDR powered by Secureworks offers extended detection and response managed by your own team. Regardless of whether you manage it yourself, or Sophos manages it for you, your Sophos Firewall is ready to share the necessary threat intelligence and data to the cloud.
Email Protection
Consolidate your email protection with anti-spam, DLP, and encryption. We recommend Sophos Sophos Email for the best cloud-based email protection solution. If you require on-box email protection, this module offers essential anti-spam, DLP and encryption.
Integrated Message Transfer Agent
Ensures always-on business continuity for your email, allowing the firewall to automatically queue mail in the event servers become unavailable.
SPX Email Encryption
Unique to Sophos, SPX makes it easy to send encrypted email to anyone, even those without any kind of trust infrastructure, using our patent-pending password-based encryption technology.
Data Loss Prevention
Policy-based DLP can automatically trigger encryption or block/notify based on the presence of sensitive data in emails leaving the organization
Live Anti-Spam
Provides protection from the latest spam campaigns, phishing attacks, and malicious attachments.
Self-serve Quarantine
Gives employees direct control over their spam quarantine, saving you time and effort.
Web Server Protection
Harden your web servers and business applications against hacking attempts while providing secure access.
Business Application Policy Templates
Pre-defined policy templates let you protect common applications like Microsoft Exchange Outlook Anywhere or SharePoint quickly and easily.
Protection from the latest hacks and attacksn
With a variety of advanced protection technologies including URL and form hardening, deep-linking and directory traversal prevention, SQL injection and cross-site scripting protection, cookie signing and more.
Reverse proxy
With authentication options, SSL offloading, and server load balancing ensure maximum protection and performance for your servers being accessed from the internet.
Specifications:
Note: The XGS 88 and 88w do not support some advanced features like on-box reporting, dual AV scanning, WAF AV scanning, and the email message transfer agent (MTA) functionality. If you need these capabilities, the XGS 108(w) is recommended.
| Front View |
 |
| Rear View |
 |
| Performance |
XGS 88(w) |
| Firewall throughput |
9,900 Mbps |
| Firewall IMIX |
6,500 Mbps |
| IPS throughput |
2,000 Mbps |
| Threat Protection throughput |
2,000 Mbps |
| NGFW |
2,000 Mbps |
| Concurrent connections |
1,600,000 |
| New connections/sec |
40,500 |
| IPsec VPN throughput |
6,000 Mbps |
| IPsec VPN concurrent tunnels |
500 |
| SSL VPN concurrent tunnels |
500 |
| Xstream SSL/TLS Inspection |
600 Mbps |
| Xstream SSL/TLS Concurrent connections |
8,192 |
| Physical Specifications |
| Mounting |
Rackmount kit available (to be ordered separately) |
Dimensions W x H x D |
200 x 44 x 180 mm |
| Weight |
1.4 kg/3.08 lbs (unpacked) 2 kg/4.41 lbs (packed) (w-model minimally more) |
| Power supply |
| Power supply |
External auto-ranging AC-DC 100-240VAC, 1.7A@50-60 Hz 12VDC, 3.33A, 40W |
| Power consumption |
12.5 W/42.65 BTU/hr (88 idle) 14.5 W/49.48 BTU/hr (88w idle) 18 W/61.42 BTU/hr (88 max.) 22 W/75.07 BTU/hr (88w max.) |
| Noise level (avg.) |
0 dBA - fanless |
| Operating temperature |
0°C to 40°C (operating) -20°C to +70°C (storage) |
| Humidity |
10% to 90%, non-condensing |
| Product Certifications |
| Certifications |
CB, CE, UKCA, UL, FCC, ISED, VCCI, CCC, KC*, BSMI, RCM, NOM, Anatel*, TEC |
| Wireless Specification (XGS 88w only) |
| No. of antennas |
2 external |
| MIMO capabilities |
2 x 2:2 |
| Wireless interface |
Wi-Fi 6 (802.11ax) 2.4 GHz/5 GHz concurrent |
| Physical interfaces |
| Storage |
16 GB eMMC |
| Ethernet interfaces (fixed) |
4 x 2.5 GE copper |
| Management ports |
1 x COM RJ45 1 x Micro-USB (cable incl.) |
| Other I/O ports |
1 x USB 2.0 (front) 1 x USB 3.0 (rear) |
| Number of expansion slots |
0 |
| Optional add-on connectivity |
n/a |
* XGS 88 only
Documentation:
Download the Sophos XGS Series Data Sheet (PDF).