
Sophos Firewall v21.5: New Standards in Network Security and User-Friendliness
NDR Essentials: Intelligent Detection of Network Threats
One of the standout new features is the integration of Network Detection and Response (NDR) Essentials directly into the firewall – a unique step across the industry. This function analyzes metadata from TLS-encrypted traffic and DNS queries using AI engines in the Sophos Cloud, without impacting firewall performance. This allows threats to be detected without having to decrypt the data traffic. This feature is available to all customers with XGS Series Firewalls and Xstream Protection license at no additional cost.
Entra ID SSO: Simple and Secure Remote Access
Sophos Firewall v21.5 now offers the long-awaited Single Sign-On (SSO) integration with Microsoft Entra ID (formerly Azure AD) for VPN remote access. Users can log in with their corporate credentials via the Sophos Connect Client or the VPN portal. This is done through standardized protocols such as OAuth 2.0 and OpenID Connect and supports multi-factor authentication for enhanced security.
Enhanced VPN and Network Features
The new version introduces significant improvements in VPN and network management:
- Increased Scalability: Support for up to 3,000 Route-Based VPN tunnels and 1,000 Site-to-Site RED tunnels.
- Optimized IP Address Allocation: Improved validation of IP lease pools to avoid conflicts.
- Stricter Profile Controls: Ensuring successful IPsec handshakes through tighter profile checks.
- User-Friendly Terminology: Renaming "Site-to-Site" to "Policy-Based" and "Tunnel Interfaces" to "Route-Based" for better clarity.
Extended DNS Protection Features
Sophos DNS Protection has been further integrated into the firewall and now offers:
- New Dashboard Widget: Display of service status directly in the control center.
- Improved Troubleshooting: Detailed logs and notifications to assist in problem resolution.
- Guided Tutorials: Step-by-step instructions for easy DNS protection setup.
Enhanced User Interface and Management
Sophos has implemented numerous improvements to increase user-friendliness:
- Customizable Tables: Column widths in various management views can now be individually adjusted and saved.
- Advanced Search Functions: Free-text search in SD-WAN routes and local ACL rules by name, IP addresses, and other criteria.
- Optimized Default Configurations: Reduction of preset rules for a clearer starting point during setup.
- New Font: Introduction of a new, more readable font for improved display.
Conclusion
Sophos Firewall v21.5 offers a comprehensive set of new features and improvements that elevate both security and user experience to a new level. With the integration of NDR Essentials, expanded VPN and DNS capabilities, and an optimized user interface, this version marks a significant step toward a safer and more efficient network environment.
The key features of the new update can be downloaded here.