Actually, we are using Tekton for creating CI/CD pipelines for building and deploying applications to different environments.
Sophos Cloud Firewall (PAYG)
SophosExternal reviews
External reviews are not included in the AWS star rating for the product.
Complex setup and modular cloud-native pipelines with good community resources
What is our primary use case?
How has it helped my organization?
It helped a lot in terms of automation. We sometimes use Tekton for purposes like sending emails, running batch jobs, and similar tasks.
What is most valuable?
The valuable features include cloud-native integration, which makes it highly available and efficient in modern containerized environments. Another feature is the modular pipeline that allows reusing CI/CD manifests for different purposes. This modularity helps in reducing redundancy and maintaining a streamlined process.
What needs improvement?
One area of improvement is the lack of cross-cluster capability, meaning you need different sets of tasks and pipelines for each Kubernetes cluster. Tekton also has an unstable API with frequent changes, making it challenging to maintain consistency across versions. Additionally, there's a need for a better dashboard and built-in authentication mechanisms.
For how long have I used the solution?
It's about one and a half years we have been working with Tekton.
What do I think about the stability of the solution?
Tekton is quite stable when used in a well-established Kubernetes cluster. The stability largely depends on the stability of the Kubernetes environment itself, which is designed for high availability.
What do I think about the scalability of the solution?
Tekton's scalability is one of its most advanced features. Since it uses the underlying Kubernetes infrastructure, it can scale easily if the Kubernetes cluster is sufficiently large. I would rate it eight out of ten for scalability.
How are customer service and support?
We primarily used community resources like Stack Overflow for addressing our issues and did not directly contact Tekton's customer service.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
How was the initial setup?
The initial setup was manageable but required extensive reading and understanding of documentation. If the Kubernetes cluster is already in place, the setup can be completed in less than ten minutes.
What about the implementation team?
The deployment of Tekton was done in-house with a team of six to seven people handling deployment, creating CI/CD pipelines, and maintaining the solution.
What's my experience with pricing, setup cost, and licensing?
Tekton is an open-source tool, meaning there are no setup costs associated with it. I would rate the cost at one, indicating it is free to use.
Which other solutions did I evaluate?
In my previous company, we used GitLab and Jenkins for similar purposes.
What other advice do I have?
My advice is to avoid using Tekton if possible due to its complex setup and lack of user-friendly features like a comprehensive dashboard and built-in authentication mechanisms.
I'd rate the solution eight out of ten.
Evaluating Sophos: Comprehensive Security Solutions for Modern Threats
Engineer Review
Identifies the threat and publishes the information across all endpoints and firewalls
What is our primary use case?
We use the product for traffic and security control.
What is most valuable?
We currently have multiple clients, and many users are working remotely. We need antivirus protection to guard against malware introduced from public networks. One of the most beneficial features of Sophos XG is its integration with Sophos Central. If any file is detected as malicious on any endpoint or firewall, Sophos Central immediately identifies the threat and publishes the information across all endpoints and firewalls. If a single system gets infected, the threat is communicated and addressed across the entire network, including all sites and remote users.
What needs improvement?
One drawback I've noticed with Sophos XG is that sometimes, the platform can become unresponsive. I've observed that it occasionally hangs, causing traffic to get stuck. During these times, users cannot access the internet or any services routed through the Sophos Firewall. This issue happens randomly and isn't something we've encountered with other firewalls like FortiGate, which we used in the past.
Dealing with licensing has been a big challenge for us. Despite our efforts to resolve issues through our sales contact, we've faced limitations. After confirming our purchase orders, we had to escalate the issue. We were ready to extend our licenses for two or three months.
For how long have I used the solution?
I have been working with the product for a year.
How are customer service and support?
We haven't seen any major issues with customer support from Sophos. We have faced some problems, but we understand that the support team can sometimes be unresponsive.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
When comparing FortiGate to Sophos XG, I would say that if I'm working on large-scale asset monitoring and security purposes, especially if I have a data center that requires firewall security, then FortiGate would be my choice. It's faster and more responsive than Sophos XG support.
How was the initial setup?
The tool's deployment takes two to three hours to complete. It doesn't require any maintenance. You would need one engineer to handle one application.
What was our ROI?
I can say there has been some return on investment. It's good, but I would still say it's higher by about 10-15 percent compared to other market products with similar configurations.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing and licensing are very complex. As a developing company, we need approvals from management to make a purchase, which can take time. We asked Sophos XG to renew our current firewall license for one or two months while we plan to accommodate our increasing IT assets.
What other advice do I have?
I rate the overall product an eight out of ten.
Sophos Firewall
Sophos XGS Comes with Xstream protection capabilities
2. The ZTNA feature that was just implemented is fantastic to have without the need to setup any more gateways.
3. SD-WAN routing capabilities allow us properly use the available gateways utilizing multiple Service Level Agreements.
2.Reporting should be more granular and configurable.
3.The OEM should provide a specialized on-premise reporting device to meet the needs of air gap network reporting/logging for an extended length of time.
High performance on-premise solution and easy management over Sophos central
No option to set specific Ipsec selectors in site-to-site configuration. The firewall accepts all selector combinations so the other endpint decides which selectors will be in use.
Limited options in routing protocols like BGP.
Sophos Firewall
Sophos
Offers visibility into network information, sources, destinations, and threats
What is most valuable?
The tool's most valuable feature is threat protection and DLP features. So far, basic DLP features like content protection and blocking. Furthermore, for remote users, features such as back filtering and application control are available, allowing for command and control from our side. It is very easy to understand policy applications.
It has multi-console features, where you can designate administrators or super admins. There's also a read-only feature available. Visibility features are included in XDR. This provides information on user impact, potential threats on specific machines, source and destination IPs, setup firewall details, and unique identifiers for each machine. Another notable feature is network isolation, ensuring that data remains secure by isolating affected machines from others.
Sophos XG offers visibility into network information, sources, destinations, and threats. Depending on the policies applied, users may monitor specific issues without blocking them. However, policies that block threats should be applied.
What needs improvement?
One feature I would like to add is remote wipeout capability. This would be useful in cases where a user leaves the organization and fails to return their laptop. Remote wipeout would allow for the deletion of data from the device with a single command. Regarding technical support from Sophos XG, it's generally satisfactory. However, the response time could be improved. It takes around one hour to receive assistance, but reducing this to 30-45 minutes would benefit us.
The tool has only a base DLP feature. It needs to have a full DLP feature with additional licensing.
For how long have I used the solution?
I have been working with the product for ten years.
What do I think about the stability of the solution?
I rate the tool's stability an eight point five out of ten.
What do I think about the scalability of the solution?
I rate the solution's scalability a seven point five out of ten.
How was the initial setup?
The tool's installment is easy.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing is cheaper compared to other alternative products.
What other advice do I have?
Sophos XG has a lab center where they analyze signatures and automatically update them on the product. This eliminates the need for manual updates on individual machines or centers. Additionally, it has features like MDR and management response features. So, Sophos XG seems to have a roadmap in place.
I would recommend the product based on the situation. Cortex, a next-generation antivirus for larger enterprises, would likely provide sufficient coverage. It's also known for its scalability and visibility features, including root cause analysis and terminology features.
I rate the overall solution an eight out of ten.