Quick Information
Sophos XGS 118 wired appliance
SMBs and branch offices
9 Ă— 2.5 GE plus 1 Ă— SFP
Contact FourTeck for current options
Overview of the Sophos XGS 118
The Sophos XGS 118 is positioned within the second-generation XGS desktop family for small and medium businesses and branch-office environments. It is built for organizations that have outgrown basic routers but do not require a large rackmount firewall. The appliance provides nine fixed 2.5 Gigabit Ethernet copper ports, one SFP fiber port, an expansion bay for an optional second-generation 5G module, an optional second power supply and support for the security capabilities available through Sophos Firewall and the chosen protection subscription.
This combination makes the appliance relevant for companies modernizing from 1 Gigabit access networks, adopting 2.5 Gigabit switches or Wi-Fi 6 access points, consolidating multiple WAN links, or replacing a legacy unified threat management device. It can serve as the security gateway between users, servers, cloud services, branch links, guest networks and internet connections while applying policy controls and generating operational visibility.
The XGS 118 is the wired model. It does not include built-in wireless. Organizations that specifically require integrated Wi-Fi should consider the XGS 118w or use separate managed wireless access points. A separate access-point design is often preferred where coverage, capacity, roaming or placement requirements extend beyond the firewall room. FourTeck can review the floor plan, switching topology, internet circuits and user profile before recommending the more suitable approach.
Why This Appliance Matters for Business Security
Business networks now carry far more than web browsing and email. Cloud accounting platforms, customer databases, video meetings, remote-desktop sessions, voice traffic, SaaS applications, backups and encrypted connections all share the same perimeter. A firewall must therefore do more than allow or deny ports. It must identify applications, inspect traffic where policy permits, enforce access rules, segment systems, support reliable remote connectivity and help administrators understand what is happening across the network.
The XGS 118 gives smaller organizations a platform with substantial throughput headroom and multi-gigabit interfaces. That does not mean every environment will achieve headline laboratory rates. Real performance depends on packet size, enabled security services, TLS inspection, rule complexity, VPN use, firmware version and the traffic mix. Correct sizing should be based on protected throughput and real workloads rather than only the raw firewall number. FourTeck assists buyers in translating internet speed, user count, branch count, VPN requirements and inspection policies into a practical appliance and license recommendation.
Key Business Benefits
Multi-Gigabit LAN Readiness
Nine 2.5 GE ports help reduce internal bottlenecks when connecting suitable switches, servers, access points or high-speed internet services.
Layered Threat Controls
With the appropriate subscription, the platform can apply IPS, application control, malware prevention, web controls and other Sophos Firewall services.
Secure Remote Connectivity
Support for site-to-site and remote-access VPN designs helps connect branches, mobile workers and approved third parties.
Flexible WAN Resilience
Multiple Ethernet interfaces, SFP connectivity and an optional 5G module can support diverse internet and failover designs.
Product Highlights
- 15.5 Gbps published firewall throughput under vendor test conditions
- 11 Gbps firewall IMIX throughput
- 3.5 Gbps published IPS throughput
- 3.95 Gbps published NGFW throughput
- 3.25 Gbps published threat-protection throughput
- 13 Gbps published IPsec VPN throughput
- 1.1 Gbps TLS inspection throughput
- Nine fixed 2.5 GE copper interfaces
- One SFP fiber interface; transceiver sold separately
- Optional second power supply
- Optional Gen.2 5G expansion module
- Wall, rack or DIN-rail mounting options with suitable accessories
Published performance is measured under controlled test conditions. Actual results vary by configuration, enabled services and network traffic.
Sophos XGS 118 Technical Specifications
| Specification | Details |
|---|---|
| Brand | Sophos |
| Model | XGS 118, second-generation wired model |
| Product Type | Next-generation desktop firewall appliance |
| Firewall Throughput | 15.5 Gbps |
| Firewall IMIX | 11 Gbps |
| IPS Throughput | 3.5 Gbps |
| NGFW Throughput | 3.95 Gbps |
| Threat Protection Throughput | 3.25 Gbps |
| IPsec VPN Throughput | 13 Gbps |
| TLS Inspection | 1.1 Gbps |
| Concurrent Connections | 5,500,000 |
| New Connections per Second | 62,650 |
| Fixed Ethernet Interfaces | 9 Ă— 2.5 GE copper, 1 Ă— 1 Gbps SFP fiber |
| PoE Support | No fixed PoE ports |
| Wireless Support | No built-in Wi-Fi on XGS 118; review XGS 118w or separate access points |
| Expansion | 1 expansion bay; optional Gen.2 5G module |
| Management Interfaces | 1 Ă— COM RJ45, 1 Ă— COM Micro-USB |
| Other I/O | 1 Ă— USB 2.0 front, 1 Ă— USB 3.0 rear |
| Memory and Storage | 8 GB LPDDR5 and 64 GB UFS 2.1 |
| Power Supply | External 65 W adapter; optional second redundant supply |
| Dimensions | 320 Ă— 212 Ă— 44 mm |
| Weight | 2.4 kg unpacked; 3.9 kg packed |
| Mounting | Desktop, wall, rack or DIN rail with suitable mounting option |
| High Availability | Configuration and licensing dependent; confirm design requirements |
| Security Services | Subscription dependent |
| Warranty Guidance | Terms depend on hardware purchase and support subscription; confirm with FourTeck |
| Availability | Contact FourTeck for current UAE options |
Configuration and Buyer Guidance
Size for protected traffic, not only internet speed
A 1 Gbps internet service does not automatically mean that any firewall with more than 1 Gbps raw throughput will be suitable. IPS, malware scanning, application control, TLS inspection, VPN encryption, reporting and concurrent sessions all consume resources. Buyers should estimate peak internet utilization, east-west segmentation traffic, remote-access demand, site-to-site tunnels, cloud backup windows and projected growth. FourTeck can map these factors against the published protected-throughput figures and recommend whether the XGS 118 provides enough operational headroom.
Choose the protection subscription deliberately
The appliance hardware and the security subscription are separate buying considerations. Features such as advanced threat protection, web security, application control, reporting or enhanced support may depend on the selected bundle and term. A lower initial license cost may not cover the controls the organization expects. FourTeck reviews required features, renewal period and support expectations before preparing the quote.
Plan every interface before deployment
Nine 2.5 GE ports provide useful flexibility, but a port map should still be created. Typical assignments include primary WAN, backup WAN, corporate LAN, server VLAN trunk, guest network, voice network, management segment and dedicated branch links. The SFP interface can support fiber connectivity when used with a compatible transceiver, which is sold separately. Cable category, switch capability and VLAN design should also be confirmed.
Ideal Business Use Cases
Growing Head Office
A growing office can use the XGS 118 to control internet access, segment departments, protect servers and provide secure remote connectivity without moving immediately to a rackmount enterprise platform.
Branch and Retail Site
Branches can use SD-WAN and VPN capabilities to connect to headquarters, cloud platforms and central services while maintaining local internet security and failover options.
Clinic or Professional Practice
Organizations handling sensitive records can separate staff, guest, voice, camera and server networks and apply more precise access policies between them.
Multi-Site SME
Businesses with several UAE or regional offices can centralize visibility, standardize rules and coordinate VPN connectivity through Sophos management tools, subject to configuration and licensing.
Application Visibility and Policy Control
Traditional firewall rules based only on IP addresses and ports can struggle with modern applications that use shared cloud infrastructure and encrypted connections. Sophos Firewall can identify applications and help administrators apply policies based on business need. This can support controls for streaming, remote-access tools, file sharing, social platforms and unsanctioned services. The purpose is not simply to block applications; it is to classify risk, protect productivity and permit approved services with the correct restrictions.
A practical rollout begins with visibility. FourTeck can help administrators review traffic reports, identify critical applications, create sensible categories and introduce controls gradually. Overly aggressive blocking can interrupt legitimate workflows, while overly broad rules can expose the network. Policy design should reflect departments, user roles, device types and business hours. Where directory integration is appropriate, user-aware policies can provide more useful control than network-address rules alone.
VPN, SD-WAN and Branch Connectivity
The XGS 118 can support IPsec VPN, SSL VPN and SD-WAN designs according to the deployed firmware, policy and license. Site-to-site VPNs are commonly used to connect branch offices, data centers, hosted applications and cloud environments. Remote-access VPNs provide authorized staff with encrypted access to internal resources. SD-WAN policies can select links based on availability, quality or business priority, improving resilience where multiple internet services are present.
Good VPN design includes more than creating a tunnel. Encryption settings, route ownership, overlap checks, DNS behavior, user authentication, split tunneling, logging, failover and bandwidth allocation must all be considered. FourTeck can review the existing topology and migration constraints before implementation. For organizations considering optional 5G, the module can be used as a backup or fixed wireless path, but coverage, carrier service, antenna location and data-plan terms should be validated at the deployment site.
Encrypted Traffic and Threat Inspection
A large share of modern internet traffic is encrypted. Encryption protects confidentiality, but it can also conceal malicious downloads, command traffic and policy violations. TLS inspection enables the firewall to decrypt eligible sessions, apply security controls and then re-encrypt the traffic. This capability should be implemented selectively because it affects performance, privacy, certificate management and application compatibility.
The published XGS 118 TLS inspection figure is 1.1 Gbps under Sophos test conditions with IPS enabled. Actual performance depends on cipher suites, session behavior and policy. Organizations should decide which user groups and destinations require inspection, which categories should be excluded, how certificates will be distributed and how regulated or privacy-sensitive services will be handled. FourTeck can develop a staged inspection policy and test key applications before broader enforcement.
Buyer Checklist
- Confirm current and planned internet bandwidth.
- Count local users, remote users, servers and connected devices.
- List required security services and reporting needs.
- Document site-to-site and remote-access VPN requirements.
- Identify VLANs, WAN links, fiber needs and interface assignments.
- Decide whether built-in Wi-Fi is required; XGS 118 is wired.
- Review high-availability and second-power-supply requirements.
- Check whether optional 5G fallback is commercially and technically suitable.
- Plan migration windows, rollback and existing rule cleanup.
- Confirm license term, support coverage and renewal ownership.
UAE Availability and Service Support
FourTeck assists UAE buyers with product selection, current availability checks, subscription comparisons, accessory review and quotation. Availability can change by hardware revision, bundle, license term and regional supply, so the page does not claim fixed stock. The quotation should clearly state the appliance, selected protection bundle, subscription duration, support level, optional power supply, rackmount option, SFP transceiver, 5G module and any professional services.
Deployment support can include pre-configuration planning, interface mapping, VLAN creation, firewall rule design, NAT, VPN setup, web and application policies, administrative access controls, logging, backup and handover. Scope depends on the agreed project. Visit the FourTeck firewall services page or contact the team with your network details.
Dubai, Abu Dhabi, Sharjah and Ajman Coverage
FourTeck coordinates firewall consultation, supply enquiries and service planning for businesses across Dubai, Abu Dhabi, Sharjah and Ajman. The exact delivery, installation or onsite-visit arrangement is confirmed during quotation and depends on project scope, engineer scheduling and product availability. Remote planning may be used before a site visit to collect internet details, current configuration, IP addressing, VLAN requirements and migration objectives.
GCC and Africa Availability
Organizations managing branches beyond the UAE can ask FourTeck about regional coordination for GCC and African locations. Commercial terms, licenses, logistics and service delivery vary by destination. Relevant regional resources include FourTeck Kuwait, FourTeck Africa, FourTeck Kenya and FourTeck Uganda. A multi-site project should standardize firmware, templates, VPN naming, monitoring and renewal records while respecting local connectivity and compliance requirements.
Related FourTeck Products and Services
Firewall Installation
Planning, staging, migration and policy implementation for new or replacement gateways.
Firewall Product Range
Compare suitable desktop, rackmount, virtual and branch-security solutions.
License Renewal Guidance
Review protection features, expiry dates, support levels and renewal terms before purchase.
Network Security Consultation
Assess firewall sizing, segmentation, VPN, SD-WAN and migration requirements.
Why Buyers Choose FourTeck
Recommendations based on traffic, users, services and growth.
Help comparing hardware, licenses, terms and accessories.
Interface, VLAN, VPN, policy and migration preparation.
Practical assistance for UAE and regional environments.
FourTeck does not treat firewall selection as a model-number exercise. The correct outcome depends on security policy, traffic inspection, network architecture, operational ownership and the organization’s tolerance for downtime. Buyers receive guidance designed to reduce specification gaps and avoid purchasing a bundle that does not match the intended deployment.
Frequently Asked Questions
Is the Sophos XGS 118 suitable for a small or medium business?
Yes, it is designed for SMB and branch-office use, but suitability depends on protected throughput, user count, VPN demand, inspection policies and projected growth. FourTeck can perform a sizing review.
Does the XGS 118 include Wi-Fi?
No. The XGS 118 is the wired version. The XGS 118w includes built-in Wi-Fi 6, while separate Sophos access points may be more suitable for larger coverage areas.
Which license bundle should I purchase?
The correct bundle depends on the required firewall, web, application, malware, IPS, reporting and support capabilities. FourTeck can compare current bundle options and terms.
Can it support a 1 Gbps internet connection?
Its published protected-throughput figures exceed 1 Gbps in several test categories, but actual performance varies with enabled services and traffic. A workload-based sizing check is recommended.
Does the appliance support site-to-site and remote-access VPN?
Sophos Firewall supports IPsec and SSL VPN capabilities. The final design, client method, authentication and performance depend on configuration and software version.
Can I add 5G connectivity?
The XGS 118 has an expansion bay for the optional second-generation Sophos 5G module. Carrier coverage, data plan and regional module availability must be confirmed.
Is an SFP transceiver included?
The appliance has one SFP interface, but the transceiver is sold separately. FourTeck can help identify a compatible optic according to the fiber type and link requirement.
Can FourTeck migrate my existing firewall rules?
Migration assistance can be scoped after reviewing the existing platform, rule base, objects, NAT, VPNs, authentication, certificates and downtime requirements. Some elements may need redesign rather than direct conversion.
What warranty applies to the XGS 118?
Warranty and replacement terms depend on the purchased hardware and support coverage. Confirm the exact entitlement, duration and process in the FourTeck quotation.
How do I check current Dubai availability and price?
Send FourTeck the required model, license term, protection bundle, accessories and installation scope. The team will confirm current UAE options and prepare a tailored quotation.
Get the Right XGS 118 Configuration
Share your user count, internet speed, VPN requirement, number of sites, preferred license term and existing firewall model. FourTeck will help identify the appliance, subscription and deployment scope that best match your environment.

