Sophos Cloud UTM 9 (Auto Scaling BYOL)
Sophos | 9.719Linux/Unix, Other 9.719 - 64-bit Amazon Machine Image (AMI)
SImplicity in Security
By implementing Sophos we were able to centrally control all security policies governing ingress traffic, and ensure that proper protection policies are in place for each application VPC. They are also able to easily gather logging data in a central location which can then be used for Administration, troubleshooting, and auditors.
- Leave a Comment |
- Mark review as helpful
Used in production for 4 months
We are using the Auto-Scaling solution with the WAF feature to protect 3 of our customer's web applications as part of a "shared security tier" model, split over multiple peered VPCs, and so far the UTM has been great. It has done most of what has been asked of it with no failures. Even on the minimum recommended size of m4.large for the controller and c4.large for the workers, it has not needed to scale up once yet.
We also use it for support users dialling in to AWS via the SSL VPN, and it is intuitive and easy to support via the User Portal, even with 2FA turned on.
The only criticism is that Sophos Support have not been great at supporting the Auto-Scaling model in AWS, it is almost as if they have had little to no training on it and several times I have had to explain it to them in full before any sort of support is necessary. I did however have great support from the After-Sales team which more than made up for it.
So far we have not updated the firmware on the solution for fear of it falling over, the documentation on this (updating the CF template to get the latest Up2Date) is pretty basic and doesn't fill me with confidence.
Bottom line is: The UTM auto-scaling does its job and it does it well, however the Support (and we are paying for Premium support) leaves much to be desired.
eaglefree
I'm new to this site im just looking and checking it out and see how it works........................................
.................................................I'm new in this but I hope to know better and to get to.know the program first........................
.
.
........