DAXS · Sophos Security
Security that brings together the network, locations, and the cloud.
Sophos is more than just a firewall appliance. DAXS plans the appropriate operating model, integrates the network and applications, adopts existing rules, and ensures the solution remains transparent during operation.

What Sophos Covers Today
One security portfolio, multiple levels.
Sophos combines network and cloud security, centralized management, and optional security services. For DAXS customers, the focus is on firewalls, site connectivity, cloud and hybrid architectures, and a well-maintained set of policies.
Endpoint, Email, Workspace, and Identity can complement one another. We add these components where they strengthen the security strategy.
Network Security
Sophos Firewall, XGS, segmentation, VPN, SD-WAN, and secure site-to-site connections.
Cloud & Hybrid
Virtual firewalls and appropriate deployment strategies for cloud networks, workloads, and hybrid environments.
Locations & Remote
Connect branch offices, project offices, home offices, and mobile access points with clear rules.
Central Administration
Sophos Central provides centralized management and visibility for supported components and services.
Email, Workspace, Identity
Additional layers of protection for communication, identities, and cloud-based collaboration.
Security Services
MDR, XDR, and other manufacturer services can be added. DAXS coordinates implementation and support; vendor services can add monitoring and response.
How can Sophos be used?
Choose a deployment that fits your sites and infrastructure.
Dedicated hardware in the office, equipment room, or server cabinet.
As a virtual instance in a suitable and tested virtualization environment.
For suitable networks and workloads in Azure, AWS, or similar environments.
Local firewall, cloud, remote offices, and mobile access as an integrated system.
Technically, Proxmox can be part of a virtualization architecture. Whether a specific Sophos configuration is appropriate and officially supported in that context is evaluated prior to the project and documented transparently.
Firewall & XGS
Size the firewall to the real workload.
A small office, multiple locations, a central office, or a virtualized environment each present different requirements. Key factors include users, bandwidth, encrypted traffic, VPN, network segments, security services, high availability, and growth.
The XGS Appliance is one component of this. The actual project includes Internet connectivity, network zones, rules, users, applications, logging, updates, monitoring, and recovery.
Small Office
Clear Internet connectivity, secure segmentation, and manageable remote access.
SMEs and Headquarters
Multiple network segments, applications, VPNs, guests, servers, and ongoing administration.
Multiple locations
Standardized rules, site-to-site connectivity, SD-RED, or other suitable SD-WAN components.
SD-RED and Branch Offices
Securely connect small locations to headquarters.
SD-RED is suitable for branch offices, satellite offices, construction sites, and project locations, among other locations. The device provides a secure connection, while policies and protection can be managed on the central Sophos firewall.
Applications, Servers, and Central Responsibility
Rules, VPN, Segmentation, and Logging
Secure, centrally managed connection
Workstations, equipment, project operations, or branch operations
Licensing, Protection, and Operation
Licensing and ongoing operations work together.
Depending on the package you choose, protection features, manufacturer updates, security intelligence, support, and centralized management may be included in the subscription. The specific license you need depends on your platform, the features you want, and your risk profile.
DAXS reviews existing licenses, assists with procurement and renewal, and documents which features are used technically and where. Once a subscription expires, the scope of protection and support may change. This is specifically evaluated before any renewal or migration.
Vendor services
Software, updates, intelligence, support options, and optional managed services.
DAXS services
Architecture, selection, installation, policies, migration, documentation, and ongoing technical support.
Customer Decision
Scope of coverage, term, risk, budget, and preferred response channels.
Ongoing Operations
Changes, reviews, updates, tests, and traceable approvals.
Migration
Understand the rules and dependencies before making the switch.
Record
Record interfaces, networks, NAT, rules, VPNs, certificates, DNS, and special cases.
Clean Up
Identify outdated approvals, determine who is responsible, and create a clear set of approval guidelines.
Test
Check the configuration, accesses, tunnels, and critical applications before the switchover date.
Switch
Plan maintenance windows, fallback procedures, availability and follow-up checks before cutover.
Security in Everyday Life
A firewall is not a one-time project.
Users, applications, locations, cloud services, and threats are constantly changing. That is why rules, firmware, VPNs, certificates, logging, and administrative access must be reviewed regularly.
In the case of ransomware and compromised devices, Sophos components can support detection, containment, and coordinated responses. Resilient security combines segmentation, patch management, backup, identity management, sound administration and documented response procedures.
Cyber Insurance
DAXS provides support with technical assessments and implementation. The specific terms and conditions of the insurer remain decisive.
NIS2 and Audits
We plan technical measures for NIS2 and audits alongside organisational processes and legal assessment.
Protection Outside of Office Hours
Suitable vendor and managed services can support detection and response outside office hours.
Frequently Asked Questions
Your Sophos questions, clearly answered.
What is Sophos Firewall?
A firewall platform for Internet access, network segmentation, VPN, site-to-site connectivity, logging, and additional security features. The specific impact depends on the architecture, license, and configuration.
What is an XGS appliance?
A dedicated hardware platform for Sophos Firewall. The appropriate size class depends on factors such as bandwidth, encrypted traffic, users, VPNs, and enabled protection features.
Do we absolutely need a hardware appliance?
No. Depending on the environment, a virtual or cloud-based deployment may be appropriate. Support, platform, performance, and disaster recovery plans are evaluated in advance.
Can Sophos be run in a virtualized environment?
Yes, Sophos offers virtual deployment options. The specific platform, resource planning, and vendor support must be appropriate for the project.
Can DAXS deploy Sophos in a Proxmox environment?
DAXS checks the technical setup and vendor support for the proposed platform before deployment.
Can Sophos be deployed in Azure or AWS?
Deployment options are available for suitable cloud networks and workloads. Network design, routing, costs, and operational responsibility must be planned together.
What is SD-RED?
A remote edge device for easily and securely connecting small locations to a central Sophos firewall, such as branch offices, project offices, or construction sites.
Can multiple locations be connected?
Yes. Depending on the size and requirements, traditional VPNs, SD-RED, SD-WAN features, or other suitable site-based solutions may be considered.
Can employees who work from home be included?
Yes. Remote access, MFA, device trust, and access rights are configured to suit specific applications and risk levels.
What is Sophos Central?
The cloud-based management platform for supported Sophos products and services. It can centrally consolidate administration, monitoring, and response.
What licenses do we need?
That depends on the firewall platform, the protection features required, support, and the operating model. DAXS assesses your needs rather than offering the largest package across the board.
What happens when a subscription expires?
Depending on the product and plan, protection features, updates, or support may be limited. The implications and renewal options will be reviewed before the expiration date.
Can DAXS take over existing Sophos licenses?
Existing contracts, contract terms, clients, partner assignments, and technical responsibilities will be clarified first. After that, further support can be planned.
Can DAXS take over an existing Sophos firewall?
Yes. First, we document access, version, licenses, rules, VPNs, certificates, documentation, and known issues.
Can older UTM or XG systems be migrated?
Yes. Before the migration, we review which rules should be carried over, updated, or rebuilt, and which functions have changed.
Do we need to rebuild our existing firewall rules?
We review the existing rules and dependencies first. Useful rules can be retained; outdated access and unclear dependencies are resolved before migration.
How often should a firewall be checked?
On a regular basis, and additionally whenever major changes are made. The specific frequency depends on risk, the rate of change, compliance, and the operating model.
Does Sophos help protect against ransomware?
Sophos technologies can support detection, network communication, isolation and response. Together with backups, patch management and clear processes, they form a stronger security approach.
What happens when a device is compromised?
Depending on the components used, signals exchanged between the endpoint, firewall, and central platform can support a coordinated response. The current technical implementation is evaluated on a project-by-project basis.
What measures does our cyber insurance require?
This is determined by the specific contract. Commonly relevant areas include MFA, segmentation, logging, patch management, backup, and network and endpoint protection. DAXS provides support for the technical implementation.
Does Sophos make our company NIS2-compliant?
No. Sophos solutions can support technical measures. Legal assessment, organization, processes, and documentation go well beyond that.
Is there a Sophos Email Security product?
Yes. Whether it makes sense for the existing email platform depends on the current security measures, the operating model, and the desired level of management.
Is there a Sophos Cloud Security?
Yes. Sophos offers protection modules for cloud workloads and cloud networks. DAXS integrates them into the existing infrastructure.
Is there Wi-Fi and access point management?
Sophos offers network and wireless components. Location, coverage, PoE, segmentation, and centralized management are planned together.
Is Sophos only suitable for Microsoft environments?
No. Sophos can be deployed in Microsoft, Google, AWS, and other cloud or SaaS environments, provided the module is suitable for the task.
For which industries is this solution suitable?
These include, among others, traditional SMEs, planning, manufacturing, retail, education, government, and healthcare. The industry is just one example; the key factors are security needs and building design.
Can DAXS procure and renew licenses?
Yes. DAXS can assess needs and inventory, procure the appropriate licenses, document license terms, and prepare renewals in a timely manner.
Who is responsible for managing rules and updates after installation?
This is specified in the operating model. DAXS can handle reviews, changes, updates, documentation, and technical coordination on an ongoing basis.
Next Step
Adopt the existing firewall or redesign the security infrastructure.
We'll start with access, rules, locations, applications, licenses, and the desired operational responsibilities.