{"id":1196,"date":"2020-04-08T13:51:48","date_gmt":"2020-04-08T13:51:48","guid":{"rendered":"https:\/\/partnernews.sophos.com\/en-us\/?p=1196"},"modified":"2020-04-15T12:01:52","modified_gmt":"2020-04-15T12:01:52","slug":"a-look-at-the-key-advantages-of-xg-firewall-v18","status":"publish","type":"post","link":"https:\/\/partnernews.sophos.com\/en-us\/2020\/04\/products\/a-look-at-the-key-advantages-of-xg-firewall-v18\/","title":{"rendered":"A Look at the Key Advantages of XG Firewall V18"},"content":{"rendered":"<h2>XG V18 is now available!<\/h2>\n<p>That\u2019s right folks, XG V18 is out! Let\u2019s talk about what this means at a practical level for your customers. Firstly, this is the most rigorously tested release ever, and this really shows from the feedback we\u2019ve had from the 200,000+ appliances in the field that have already upgraded. Secondly this release unifies our approach to public cloud security on both AWS and Azure platforms. Now that XG can run in both, all those great stories we have been telling customers about Synchronized Security in their office and Azure environments also apply to AWS too! That said, however, the biggest news is the new XStream architecture and how it can be used to solve real-world challenges network managers face. Shall we have a look at a few of those challenges?<\/p>\n<h2>Is encryption rendering my Firewall useless?<\/h2>\n<p>Traffic visibility has always been a challenge in a world where the number of applications continues to grow, and those applications constantly change and evolve. When you add encryption to the mix, this hides the traffic from the firewall in a private connection and it becomes almost impossible to keep on top of things. In a recent survey, we found that on average 43% of traffic on a network is unclassified and Google estimate that upwards of 80% of global internet traffic is encrypted. Now, allow me to be transparent and state that that ability to inspect SSL traffic on a firewall is nothing new. We\u2019ve been doing it for years, and so have our competition. And yet in 97% of cases where SSL decryption could be enabled, it isn\u2019t leading to massive potential blind spots.<\/p>\n<p>You might be asking \u201cnow why is this?\u201d And rightly so. The reasons come down to two factors: performance and usability. The new XStream architecture is specifically designed to maximize firewall throughput by intelligently passing traffic to the areas of scanning that need to be used, while bypassing unnecessary scans. This boosts performance, but also critically it frees up resources that allow the XG Firewall to undertake the heavy lift required to inspect more SSL connections, solving the performance challenge. The next battle is usability, which again is solved by the new architecture. We have decoupled the SSL inspection engine from the web proxy, so we can inspect SSL traffic regardless of what port is in use and the latest TLS 1.3 standard is supported to boost compatibility. Even with these changes though, some applications simply cannot support SSL inspection. This might be because of techniques, like for example certificate pinning. This tends to lead admins to simply turn off SSL inspection wholesale rather than risk the wrath of their users when applications start breaking. XG V18 changes things, because we can quickly show an admin what SSL connections are failing, and why, as well as offering simple one-click remediation of these issues. This allows an admin to enable SSL inspection with confidence, knowing the XG can handle the performance demands and reliably inform when things go wrong and config changes need to be implemented.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-1197 size-large\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/xstream-ssl-inspection.png?w=640\" alt=\"\" width=\"640\" height=\"362\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/xstream-ssl-inspection.png 827w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/xstream-ssl-inspection.png?resize=300,170 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/xstream-ssl-inspection.png?resize=768,435 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<h2>The threat landscape is evolving and my protection can\u2019t keep up.<\/h2>\n<p>Sophos has long been at the forefront in the battle against new and unknown threats, and this is most clearly demonstrated through the innovative features in our Intercept X endpoint protection. XG V18 brings the best of this technology and incorporates into the network layer, making the XG a more compelling purchase, either standalone or as part of a layered defense strategy. We\u2019re calling this addition \u2018Threat Intelligence\u2019 and it will run in parallel with our already proven Sandstorm runtime analysis sandboxing service. The Threat Intelligence Analysis utilizes multiple threat modeling techniques, using deep learning and artificial intelligence to analyze various characteristics and genetics of the file compared to millions of known good and bad files. It provides a very accurate assessment of any new file in just seconds. Sandstorm and Threat Intelligence make a formidable pair when analyzing previously unseen files for evidence they are malicious in order to keep the latest threats off the network.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-1198 size-large\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/xstream-threat-intelligence.png?w=640\" alt=\"\" width=\"640\" height=\"364\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/xstream-threat-intelligence.png 874w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/xstream-threat-intelligence.png?resize=300,171 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/xstream-threat-intelligence.png?resize=768,437 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>Sandstorm has also gone through significant enhancements. Firstly, remember that the virtual endpoints are covered with our award-winning Intercept \u2018X\u201d protection suite, leading to a high rate of conviction. In addition, we have incorporated technologies from our EDR platform to expose the machine learning decision tree in an overhauled Sandstorm threat report. This allows an admin to look at the decision coming from Sandstorm and what has influenced it. For example: a file lacking an icon or packed in a particular way. Finally, in an industry first, Sandstorm reports show actual screenshots of the sandbox environment as the malware carries out its nefarious deeds, shining a spotlight into a previous black box process.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-1199 size-large\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/sophoslabs.png?w=640\" alt=\"\" width=\"640\" height=\"361\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/sophoslabs.png 893w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/sophoslabs.png?resize=300,169 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/sophoslabs.png?resize=768,433 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<h2>My business relies on cloud-applications, efficient bandwidth usage and constant uptime.<\/h2>\n<p>We have looked at software-defined networking or SD-WAN in previous articles. But with V18 all of those great capabilities gain their own configuration page, making our intentions in this space crystal clear. The capabilities of traffic routing are incredibly comprehensive, empowering admins to throttle and route traffic based on source, application, and destination and defining how to handle failure states. An enterprise may leverage an array of internet connectivity modes including leased-line, MPLS, DSL, and cellular services knowing they will be utilized with maximum efficiency. And, being aware that in the event of outages, the highest priority traffic will always take precedence on whatever connection methods remain functional.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-1201 size-large\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/sd-wan-policy-routing.png?w=640\" alt=\"\" width=\"640\" height=\"539\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/sd-wan-policy-routing.png 979w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/sd-wan-policy-routing.png?resize=300,253 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/sd-wan-policy-routing.png?resize=768,646 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Multiple site enterprises are also well catered to. Remember the XG is replete with site-to-site connectivity options such as SSL and IPSec VPN, as well as our unique RED technology, which can be used to link multiple XGs together or employed as a hardware solution for smaller branch offices. All of which are compelling alternatives to costly leased line or MPLS connectivity.<\/p>\n<p>Finally, although not a new feature, Synchronized Application Control, whereby unknown applications are classified through endpoint to firewall collaboration, gains increased significance in light of the release of XG V18. Clearly any attempt to route or control traffic relies entirely on the ability to classify the application in question. Our unique power in this area to dynamically classify unknown apps means that even if an end user wants to control a bespoke application, this can be achieved when Sophos endpoint and firewall are brought together.<\/p>\n<p>&nbsp;<\/p>\n<h2>One more thing:<\/h2>\n<p>Although not strictly a part of the V18 release, it&#8217;s worth taking a moment to look at how Sophos Central and its links to XG are being strengthened. Since we first launched XG in Central, the team has added some great new features, such as backup and firmware management, the light-touch deployment option, and group firewall management. This feature in particular is great of multi-site customers or MSPs as it allows admins to manage an estate of firewalls as one, unifying policy, firmware updates, and more. And the best bit it that this service is free!<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-1202 size-large\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/firewall-groups.png?w=640\" alt=\"\" width=\"640\" height=\"219\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/firewall-groups.png 979w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/firewall-groups.png?resize=300,103 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/firewall-groups.png?resize=768,263 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>We have also launched Sophos Central reporting, bringing the power of the cloud and big-data analytics to bear on network activity and reporting with a full suite of powerful new reporting tools in Sophos Central for XG Firewall.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-1203 size-large\" src=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/bandwidth-usage.png?w=640\" alt=\"\" width=\"640\" height=\"262\" srcset=\"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/bandwidth-usage.png 962w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/bandwidth-usage.png?resize=300,123 300w, https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/bandwidth-usage.png?resize=768,315 768w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<p>Hopefully you\u2019ve found that article useful and it will enable you to position this exciting new release with your customers. I\u2019ll leave you with some feedback from some of our early adopters:<\/p>\n<p style=\"padding-left: 40px;\"><span style=\"color: #000000;\"><em>\u201cBeing a part of the EAP was invaluable. Not only did we see the value in all of the enhancements, it gave us the confidence to upgrade 200 firewalls across our various customers immediately after it was available.\u201c<\/em><\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"color: #000000;\"><em>&#8220;All I can say is my goodness it&#8217;s fast \u2013 much better performance.&#8221;<\/em><\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"color: #000000;\"><em>&#8220;I like it. It is fast. You have delivered a good release.&#8221;<\/em><\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"color: #000000;\"><em>&#8220;Memory use and CPU utilization has gone down by 30%&#8221;<\/em><\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"color: #000000;\"><em>&#8220;Performance is so much faster and management activities take less time.&#8221;<\/em><\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"color: #000000;\"><em>&#8220;HA fail over is much faster.&#8221;<\/em><\/span><\/p>\n<p style=\"padding-left: 40px;\"><span style=\"color: #000000;\"><em>\u201cv18 gave us a significantly higher performance than I thought possible with our infrastructure. Teachers are now streaming 4K videos to their classes without issue. The changes to the management has greatly simplified our admin efforts making configuration and troubleshooting much easier.\u201d<\/em><\/span><\/p>\n<p>Thanks for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We\u2019ve been hyping up XG v18 for a while, and the good news is, the wait is over It\u2019s finally here, and it\u2019s the most significant release for XG ever. But what advantages if offers your customers? And how do you talk about those values? Read on to find out.<\/p>\n","protected":false},"author":11,"featured_media":1190,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[2],"tags":[38],"coauthors":[64],"class_list":["post-1196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-products","tag-xg-firewall"],"jetpack_featured_media_url":"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2020\/04\/featured-image-UKI-tech-update-Partner-app-icon-1600x960-1.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/1196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/comments?post=1196"}],"version-history":[{"count":5,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/1196\/revisions"}],"predecessor-version":[{"id":1208,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/1196\/revisions\/1208"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/media\/1190"}],"wp:attachment":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/media?parent=1196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/categories?post=1196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/tags?post=1196"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/coauthors?post=1196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}