Sophos XGS 108 Firewall (2nd Gen)
Sophos XGS 108 is the lower-mid segment of the 2nd Gen XGS SMB lineup. Fanless design ideal for healthcare, education and retail. 12.5 Gbps firewall throughput, 2.5 Gbps IPS, 800 Mbps TLS 1.3 inspection. 8x 2.5 GbE ports + 1x SFP fibre slot for multi-WAN / DMZ setups. Sophos Central management + Synchronized Security + Xstream Threat Protection. XGS 108w variant includes integrated Wi-Fi 6.
12.5 Gbps NGFW + 2.5 Gbps IPS
Lower-mid throughput for SMBs; signature + behaviour IPS.
TLS Inspection 800 Mbps
Encrypted traffic inspection for modern HTTPS threats.
Fanless Design
For healthcare, education, retail environments needing quiet operation.
8x 2.5 GbE + SFP Fibre
Multi-WAN, DMZ and VLAN segmentation port count.
Who is XGS 108 for?
25–50 user SMB offices, healthcare centres, education institutions, retail chains. Step up from XGS 88 when fibre uplink or multi-WAN is needed.
- 25–50 user SMB
- Healthcare/education/retail
- Fibre uplink or multi-WAN
- 500 Mbps – 1 Gbps internet bandwidth
Synchronized Security full stack
XGS 108 + Sophos Intercept X Advanced + Sophos MDR Complete = the most cost-effective enterprise-grade security architecture at SMB scale.
Licensing
Hardware + Annual Subscription (Xstream Protection)
- 1 year
- 3 years (recommended)
- 5 years
2nd Gen hardware. Premium Support + 24h RMA included.
Who is this for?
Frequently Asked Questions
XGS 108: 12.5 Gbps fw / 2.5 Gbps IPS / 800 Mbps TLS — 25–50 user sweet spot. XGS 118: 15.5 Gbps fw / 3.5 Gbps IPS / 1.1 Gbps TLS + 5G module slot — 50–100 users.
108w integrates Wi-Fi 6 (802.11ax). If you don't need a separate AP, choose 108w.
2nd Gen hardware; 8x 2.5 GbE (was 1 GbE), Wi-Fi 6, higher throughput. From 2025 XGS 108 is the standard.
Yes, two XGS 108 in Active-Passive HA cluster.
Used for fibre internet or HQ-branch fibre links.
Xen Bilişim Deployment Process
- 1. Discovery & sizing: Current environment, user count, OS/cloud distribution and compliance requirements analysed; correct SKU and licence count proposed.
- 2. Pilot deployment: A 10-25 device subset goes live; integration with existing security stack tested; alerting + reporting configured.
- 3. Full rollout: Phased rollout across all endpoints; policy templates applied; user training and IT runbook delivered.
- 4. Optimisation & follow-up: 90-day post-launch tuning: false-positive triage, policy hardening, KPI review and quarterly health-checks.
Typical end-to-end timeline: 2-4 weeks (varies by user count and integration scope).