Replacement for Sophos UTM9 Home Edition

  • DNS Benchmark v2 Release 5 with Consultant License
    Guest:
    If you own any earlier release of our DNS Benchmark you may immediately download its release #5 replacement. Running an earlier release will detect the new release and help you upgrade.

    Although this release is cosmetic, appearance matters and affects ease of use. The biggest change, as seen in the image above, is that the DNS Benchmark now has a traditional Windows application menu to more fully expose its many features. This release is also "Consultant License Aware" and GRC will now issue a Consultant version when owners have previously purchased four "Personal Use" licenses. If you have previously purchased four DNSB licenses, or if you wish to upgrade your "Personal Use" license to Consultant, GRC's purchase process will direct you through that process.
    /Steve.
  • Be sure to checkout “Tips & Tricks”
    Dear Guest Visitor → Once you register and log-in please checkout the “Tips & Tricks” page for some very handy tips!

    /Steve.
  • BootAble – FreeDOS boot testing freeware

    To obtain direct, low-level access to a system's mass storage drives, SpinRite runs under a GRC-customized version of FreeDOS which has been modified to add compatibility with all file systems. In order to run SpinRite it must first be possible to boot FreeDOS.

    GRC's “BootAble” freeware allows anyone to easily create BIOS-bootable media in order to workout and confirm the details of getting a machine to boot FreeDOS through a BIOS. Once the means of doing that has been determined, the media created by SpinRite can be booted and run in the same way.

    The participants here, who have taken the time to share their knowledge and experience, their successes and some frustrations with booting their computers into FreeDOS, have created a valuable knowledgebase which will benefit everyone who follows.

    You may click on the image to the right to obtain your own copy of BootAble. Then use the knowledge and experience documented here to boot your computer(s) into FreeDOS. And please do not hesitate to ask questions – nowhere else can better answers be found.

    (You may permanently close this reminder with the 'X' in the upper right.)

Pilgrim22

New member
Apr 7, 2025
2
0
Hello everyone,

I've been running Sophos UTM 9 on an old grey box for about 10 years. Now its 'End of Life' I’m looking for a replacement.

I’m not an IT professional but I have a reasonable idea of what I’m doing.

What replacements can you recommend?

Regards

Pilgrim
 
Last edited:
Sophos UTM 9 is a mature, comprehensive security solution that consolidates firewall, IPS Intrusion Prevention System, WAF Web Application Firewall, VPN Virtual Private Network, and web filtering into one appliance.

Key features include Advanced Threat Protection, Sandstorm sandboxing for ransomware protection, and extensive reporting.

Note that Sophos UTM 9 is nearing end-of-life, with support ending on June 30, 2026, and Sophos recommends migrating to Sophos Firewall. Sophos +1

Key Aspects of Sophos UTM 9
  • Capabilities: It acts as a Next-Gen Firewall, offering Web Application Firewall (WAF), pre-tuned Intrusion Prevention System (IPS), VPN Gateway, and advanced threat protection.
  • Deployment Options:
    Available as a dedicated hardware appliance (SG Series), virtual appliance, or software installation on custom hardware.
    • Management: Features a web-based administration interface that allows for customization of dashboard widgets, navigation, and user preferences.
    • Firmware Updates: Updates are handled via an "Up2Date" process that can be managed directly through the admin interface, enabling easy upgrades to the latest 9.7x versions.
    • Licensing & Support: The UTM 9 Premium license includes 24/7 technical support, automatic updates, and Advanced RMA replacements.
    • Home Use License: A free "Home Edition" is available for non-commercial use, which features non-blocking IP limits, though it lacks some premium support features.
    • Lifecycle Status: Sophos UTM 9 will not be supported after June 30, 2026, and users are encouraged to migrate to Sophos Firewall for ongoing security.
      Sophos +7
Installation and Setup
  • Installation Method: It can be installed from an ISO image written to a USB drive using tools like Rufus.
  • Hardware Requirements: The installation requires a 64-bit system and will fully erase the hard drive during installation. It supports at least two network ports for WAN and LAN connectivity.
  • Configuration: During initial setup, users configure the WAN/LAN interfaces, time zone, and language settings.
    YouTube
    YouTube +1
Maintenance
  • Backups: It is recommended to create and download configuration backups before performing firmware updates, which can be done through the "backup and restore" tab.
  • System Integrity: Regular updates are released by Sophos to address security vulnerabilities.
    Sophos Community +3

I learn something new every day no matter how hard I try. ;-) Thanks.
 
What replacements can you recommend?
I guess it would depend on what your needs are. A simple router running OpenWRT (the Flint3 from GLinet seems nice) could be perfect for someone with minor needs, or maybe you need something like pfSense running on a Netgate box with 8 multi-gig ports (https://www.netgate.com/appliances). Or maybe you want to run OpnSense on your own hardware.
 
Thanks for the replies.
The Sophos UTM is a compehensive security suite not just a firewall. Thats my dilemma. Im not sure if there is a comparable alternative.
I believe pfsense, opnsense and sophos are just firewalls and lack a lot of the features of the UTM.
Maybe these three products satisfy modern security need and thats why the UTM is being discontinued, Im not sure.
What are you guys using?
 
What are you guys using?
Well based on the feature set of the UTM 9 I am not its target audience. I just want a working [NAT] Router. It's a low effort firewall in that nothing gets in unless a connection out was established first. I don't need fancy firewall rules, nor a VPN. I don't want blocking getting in my way, nor some half-assed "anti-malware" breaking things for me (Windows is bad enough at doing that.) But I doubt I am a typical user either... I don't go to places online where I fear I'll encounter malware, I don't download much software at all, so not worried about that vector. I don't really use email, so I don't have to worry about getting phished. I'm also probably way too boring to be much of a target. (Not using crypto-cash or even using a credit card online.) So for me, I just run a GLinet Flint 2 router with most of the fancy features not yet enabled. It does offer VPN and other related features, I think it might even have some filtering, but I've never checked into it. The one feature I do use is its ability to force override UDP DNS queries to the server of my choice, and I use Quad9 for whatever protection it provides. (That's mostly for the couple of IoT devices I have, as I use Quad9 DoH on my browsers.)

In any case, I'd try OPNsense first, if you have a box to install it on and see how you like it. (I presume you could technically run it in parallel to get some experience, but you may not have the spare host box.) If you were up to buying new hardware, I'd maybe try the Flint 3 and see if you like the packaged UI, or switch to OpenWRT if you don't.
 
"... What are you guys using? ..."
"... I don't go to places online where I fear I'll encounter malware, I
don't download much software at all, so not worried about that
vector. I don't really use email, so I don't have to worry about
getting phished. I'm also probably way too boring to be much of a
target ..."

I "go to" risky places all the time, and I copiously use multiple free
webmail POP and IMAP accounts through my PCs and phones, and
I download a ton of stuff from anywhere.

Considering that visiting ANY website, such as the supposedly safe
The Wall Street Journal website, may inflict malware on us because
many websites sell advertising space that is filled with stuff from
servers outside the main website's control, outside their ability to
securely prevent those unrelated remote and subordinate servers
from being cracked, let alone ANY web page getting cracked, I use
browser-based adblockers, script blockers, and PrintFriendly ( that
harvests my behavior- doh ! ), to simplify web pages to the essential
articles and contents I seek, with a minimum of unintended invasive
uncontrolled content, and that somewhat reduces my exposure.

I use the free Tor Browser, Onion sites, and a paid-for proxy when
wanting to be fully anonymous.

I use free VirusTotal.com to scan any file downloaded, and then I
scrutinize that file's behavior, because even supposedly legitimate
software, like CCleaner, has been cracked at the source before even
leaving the vendor.

I manually scan with AdwCleaner, JRT Junk Removal Tool ( aging ),
Spybot Search & Destroy versions 1 ( ! ) and 2, Super Antispyware,
and even ( gulp ) Malwarebytes, plus web-based scans from
Kaspersky ( ! ), Eset, Trend Micro, and so on, just to see how I'm
doing, but otherwise, I have no memory-resident anti-malware
program, though the free Kerish Doctor does a good job of warning
me when stuff wants access to autorun on boot, install in my browser,
and so on.

And I keep a copy of every malware I find in
\Backup\- Malware\
as a test for the qualities of on-demand scanners to see what they
find compared to VirusTotal.

I leave Microsoft's built-in anti-malware running on computers I
support that other people use.

I have the in-built "security" and firewall from my ISP, router, and
Windows EXCEPT any memory-resident anti-malware.

That said, the only "invasions" I've experienced are out there, not in
here, that is, cracking our accounts at the other end, such as at the
government ( ! ) or at a service or facility such as Yahoo Email or
Target stores - the crackers know that an hour of their time at the
other end will get them thousands, if not millions of credentials,
versus a mere single credential for the same work at my end, though
once our credentials are obtained either way, we are at risk
individually, and have to deal with that.

The only compromises I've seen for other folks are the same as the
ones I see myself, plus they tend to believe errant on-screen messages,
they panic, they call the 1-800 numbers, and they whip out their credit
cards to solve imaginary problems, some even maintain long-term
relationships with supposed remote support.

More?

What is a comprehensive list of all web and online security
compromises stealing end user's credentials?
https://share.google/aimode/Y510gnF2jM5OyoXO7


What is a comprehensive list of specific incidents of massive
credentials harvesting?
https://share.google/aimode/f94zGea4rm0rsNkE0


I have stacks of security devices unplugged, sitting on shelves,
someday, I'm going to try to understand their implementation, or
maybe just put them on eBay for anyone interested in antiquity.

That's what I do.

So, I'm grateful for the opportunity to learn about yet another
security solution, such as the Sophos UTM9, even though such
mini-exposure and mini-education for me only reinforces the
validity and simplicity - and low-budget, low-effort - preventative
energies that I throw at the problem.

Thanks.
 
Last edited:
Windows built-in Defender has come a long way for 10 and 11. That being said, even as a free solution, I found it was heavy on system resources.

The only AV programs I use, and have used for decades, are ESET and MalwareBytes. As a beta tester of MalwareBytes in 2008 and onwards I was the go-between for a massive 2GB virus etc trade between MalwareBytes and Counteryspy (now VIPRE). 2GB was huge in 2008.

Once ESET is installed, it takes charge of firewall and AV duties. So Defender is disabled. I found my system was more responsive with ESET installed and Defender disabled.

If you want a free version, then I'd recommend Bitdefender - ( https://www.bitdefender.com )

Keep well away from the following as they will bring your system to a crawl.

Norton/Symantic
McAfee,
Avast
AVG
Kaspersky.

If you want the best AV, then go with ESET. If you want the best free option, go with Bitdefender.

The most important actions you can do is to keep you Windows OS and all programs updated.

One other cool program that doesn't require activation is:

0patch - ( https://0patch.com )

0Patch uses micro code updates to fix vulnerabilities. It'os able to patch for zero-day vulnerabilities that Microsoft hasn't updated in months and sometimes years. Plus, these 0patch micro codes also help keep other programs you run on your system patched too.

There is a free version and a fully functioning trial version of 0patch. It cost $20 per year. The free version is better than nothing but the full version is much better.

I only use ESET, MalwareBytes (I have a 2008 perpetual and lifetime free updates license) with 0patch nowadays and all active/online with no real impact on system resources and system responsiveness.

TIP: Install ESET trial and half-way through the trial they will offer you a 50% discount. Can't be bad :)