I'm looking for advice on selecting a firewall for a small company with about 10 to 20 employees. Currently, we're using a Sophos firewall running on the same server as all our other software. Is this a common setup? I feel like we should have a dedicated hardware firewall to ensure that if the server goes down, we'll still have protection. Am I right in thinking that if a company hosts its software on-site, it should use a separate hardware firewall?
5 Answers
If you're also considering your future expansions, Ubiquiti could be a great fit for their ecosystem, especially if you want to incorporate Wi-Fi, camera systems, and door access without ongoing fees. Fortinet is recognized as a more established brand but does come with its own annual costs.
I'd recommend going with a Fortigate. It has some annual licensing fees, but even without an active subscription, it remains functional. You're correct in your assessment about not using a software firewall on the same server as other services. That's definitely a risky setup.
Just be careful about putting all your functionalities on one system like your server. It can lead to misconfigurations. If you have remote access needs, you'll definitely want a proper VPN setup as well. What other network devices do you use, and are they managed centrally?
I've had a great experience with Sophos over the years. We use their solutions for endpoint protection and firewalls without issues. The cloud management's convenient, too. Just keep in mind that a reliable solution like Sophos XGS can be pricier upfront, but worth it for the features it offers.
Sophos can be a solid choice, especially if it's licensed and up-to-date. It's just like running a virtual firewall which might not be ideal, but if it's working, there's no immediate need to switch. If it's integrated well with other Sophos products, such as their Antivirus and AD, you might just want to get a dedicated Sophos XGS hardware unit instead.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures