Pfsense & Sophos in VM

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

modder man

Active Member
Jan 19, 2015
657
84
28
33
yeah, I cant Chane the default password if i cannot get into it. We are both talking about the XG correct?
 

sthsep

Member
Mar 7, 2016
72
10
8
yeah, I cant Chane the default password if i cannot get into it. We are both talking about the XG correct?
You try this to enter at http://172.16.16.16:4444 correct?
I used Sophos UTM long time and I just moved because it dont support openvpn clients. Tested the XG in the beta phase but its far away from the UTM. Even sophos says that the utm has more features.
 

sthsep

Member
Mar 7, 2016
72
10
8
Have you already done the inital setup on 172.16.16.16 ?
If not get in the 172.16.16.0/24 network and make the inital setup via the IP above.
 

sthsep

Member
Mar 7, 2016
72
10
8
can I not switch the ip before configuring?
I dont know what you mean but after the installation of the iso / ova you need first bring a networkadapter in the 172.16.16.0/24 Network and make the inital configuration (License and such thing). This is also a thing that I dislike on XG.

I didn't compare the products on all functions by myself but I moved because it was a resource hog and sometimes buggy. On process (I think it was the proxy) was everytime on 1.00 load and I got yellow warnings when I used about 100Mbit on both of my WANS. Also the reporting in UTM is in my opinion far better (Weekly reportings and bandwith usage Graph). Also I hated that I couldn't make static entries / mappings at the dhcp server. But as far I know it support this now. The only better thing was the WAN-LoadBalancing that works great on the XG.

But I dont think you will miss something on a home enviroment. But you dont like the XG if you have used the Sophos UTM before because it is far better.
 

mason736

Member
Mar 17, 2013
111
1
18
@modder man
Not that I know of, just add a second IP to your NIC in the 172.16.16.x range. I did find some quirks in the licensing/registration process but after a few tries I was able to get through it.

@mason736
Take a look at this: http://www.expert-zone.net/wp-content/uploads/sites/2/2015/11/sophos-sf-os-vs-utm-feature-list.pdf
The only thing missing from UTM that I would really like is "Authentication and filtering options by device type for iOS, Android, Mac, Windows and others - not available".

Hopefully they will include a lot of the missing functionality in successive releases.
 

Nnyan

Active Member
Mar 5, 2012
148
52
28
I would recommend that you spend some time on the Sophos XG forums, IMHO there is more to this then just a features list. I myself am running UTM9, XG and pfSense at home. While the XG has some cool features and looks great at this point I'm leaning towards UTM9. Suprisingly pfSense is growning on me. My biggest issues with UTM9 was the 50 IP limit but I've been playing around with a few methods of limiting your IP count (seperate DHCP server for any devices that do not need internet access, making sure there is no gateway, seperating as much of my network as I can into VLAN's behind a NAT router, and using the Sophos as a DNS forwarder).

Too early to tell but I've read a few articles about people using pfSense as their router and Sophos for the other UTM functions. I may end up doing that.
 

mason736

Member
Mar 17, 2013
111
1
18
I run quite a number of vms in my environment, with dhcp and dns running on Windows server essentials 2012. Plus a ton of connected devices, phones , tablets, Roku, etc.... I am at roughly 120 dhcp leases at any one time....
 

mason736

Member
Mar 17, 2013
111
1
18
On a side note, I tried pfSense, and simply couldn't get into it. Software engineering and IT Strategy are my thing.... a network engineer I'm not.....After trying to get pfSense to work, I finally gave up. I couldn't even manage to get traffic to leave my network on it to the web... I reverted back to my OpenWRT setup until I can get Sophos XG up and running.
 

sthsep

Member
Mar 7, 2016
72
10
8
On a side note, I tried pfSense, and simply couldn't get into it. Software engineering and IT Strategy are my thing.... a network engineer I'm not.....After trying to get pfSense to work, I finally gave up. I couldn't even manage to get traffic to leave my network on it to the web... I reverted back to my OpenWRT setup until I can get Sophos XG up and running.
I was in the same position. At start pfsense was also hard for me but after some time it works just great.

@Nnyan Do you have a good guide for setting up UTM behind pfsense without double NAT? My UTM didn't really work in Transparent Mode.
 

Nnyan

Active Member
Mar 5, 2012
148
52
28
I run quite a number of vms in my environment, with dhcp and dns running on Windows server essentials 2012. Plus a ton of connected devices, phones , tablets, Roku, etc.... I am at roughly 120 dhcp leases at any one time....
At my last count I'm just shy of 150 (with a techy wife and two young girls and their many devices, every streaming device, etc... ) I am also in the process of replacing all of our targeted light blubs with Hue's and I'm starting to build my wife a Smart Mirror (Xonay Labs | Michael Teeuw). This of course has led my 5 and 7yo to want one of their own (thankfully I have a few Pi's laying around).
 

Nnyan

Active Member
Mar 5, 2012
148
52
28
On a side note, I tried pfSense, and simply couldn't get into it. Software engineering and IT Strategy are my thing.... a network engineer I'm not.....After trying to get pfSense to work, I finally gave up. I couldn't even manage to get traffic to leave my network on it to the web... I reverted back to my OpenWRT setup until I can get Sophos XG up and running.
When did you last try it? I ask that b/c I tried pfSense several times with very little success. My last attempt was about 6 months ago when I tried installing it on some Barracuda Web Filters (210/310/410). I could not install it on 2 of the 3 appliances and on the one that it did install it was a nightmare (interestingly enough SUTM installed very nicely on all three and worked very well).

Anyway I installed the latest version a few weeks ago into an ESXi 6 VM and I was really impressed. It was up and running faster then SUTM (which doesn't have the most intuitive menu or structure either). I'm not a big fan of some of the UTM features (anti-virus, etc...) on pfSense and the Sophos stuff has been impressive so far so that's why I'm leaning towards a mix-n-match.
 

mason736

Member
Mar 17, 2013
111
1
18
I tried running it last week, and simply got frustrated. I had all the same settings as my firewall in OpenWRT, and no communication would come in or out of the firewall, plus I wasn't a fan of the interface.