Sophos, a global leader in cybersecurity, has announced the release of Sophos Firewall v21.5, a major software update that enhances both protection and incident response across its firewall platform.
The update introduces Sophos Network Detection and Response (NDR) Essential, along with a suite of upgrades designed to simplify administration and boost performance.
Advanced Threat Detection with AI
At the heart of the update is the integration of Sophos NDR Essential, now available at no additional cost to all customers with an XStream Protection license.
This enhancement empowers Sophos Firewall with two dedicated artificial intelligence engines capable of detecting malware communications, including those using algorithmically generated domain names (DGAs)—even if they’ve never been seen before.
“NDR traffic analysis requires substantial processing power,” said Chris McCormack, Senior Product Marketing Manager at Sophos.
“To address this, we’ve deployed the NDR solution in Sophos Cloud, offloading heavy tasks from the firewall itself while maintaining rapid detection capabilities.”
This integration builds upon Sophos’s Active Threat Response system, offering organizations stronger defenses against advanced and unknown threats.
Enhanced VPN and Identity Integration
Sophos Connect, the company’s VPN client, now supports Microsoft Entra ID (formerly Azure AD) for single sign-on (SSO) and multi-factor authentication (MFA). This improvement applies to both SSL and IPsec VPN connections, streamlining secure access for remote users.
Other VPN enhancements include:
- Simplified interface terminology: “Site-to-site” VPNs are now labeled “policy-based,” while “tunnel interfaces” are termed “route-based” for clarity.
- Dynamic IP pool validation: Reduces conflicts in IP assignments across various VPN types.
- Stricter IPsec profile enforcement: Ensures algorithm compatibility, preventing connection issues.
- Improved scalability: Now supports 3,000 VPN tunnels, 1,000 SD-RED site-to-site tunnels, and up to 650 concurrent SD-RED devices.
Streamlined Administration
Sophos Firewall v21.5 introduces a range of quality-of-life improvements for administrators:
- Flexible DHCP-PD (IPv6): Expanded support for /48 to /64 prefixes.
- Default activation of RA and DHCPv6 servers.
- Resizable columns and a more responsive web admin interface for ultra-wide screens.
- Smarter object search: Broader criteria for SD-WAN routing and ACL rule configuration.
- Simplified default setup: Fewer preconfigured firewall rules for a cleaner initial configuration.
Secure by Design
Sophos reaffirms its commitment to a secure-by-design architecture. The firewall now uses containerization to isolate critical functions and implements integrity checks using mathematical checksums. If a checksum mismatch is detected, it triggers an alert, enabling security teams to respond rapidly to potential compromises of the operating system.
Availability
Sophos Firewall v21.5 is now available for manual download to all customers with a valid license. The update reflects Sophos’s ongoing mission to deliver proactive, AI-powered cybersecurity solutions tailored to modern enterprise challenges.