Choose your language
Sophos Firewall Training
More than 2 million students worldwide

Sophos Firewall Training

4.5

Master Sophos Firewall from the ground up and gain the hands-on skills to deploy, configure, and manage enterprise-grade network security. This course covers everything from firewall fundamentals and VPN setup to advanced threat protection and compliance reporting. Whether you're securing a single site or a distributed enterprise, you'll finish ready to protect real networks with confidence.

Dedika for businesses

What you'll learn:

This course takes you through every critical layer of Sophos Firewall administration. You will configure network interfaces, zones, routing, and NAT to build a solid network foundation. From there, you will enforce access control with firewall rules, web filtering, and application control policies. You will deploy IPS, ATP, and synchronised security to detect and contain advanced threats. VPN chapters cover IPsec, SSL, and SD-WAN overlays for secure connectivity across sites and remote users. You will also set up email protection, generate compliance reports, and integrate the firewall with Sophos Central for centralised management.

How you study in practice Sophos Firewall Training

How you practise Sophos Firewall Training

For businesses looking to train their team

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Sophos Firewall Fundamentals and Architecture

  • Lesson 1 • Backup, Restore, and Firmware Management

    Teaches configuration backup strategies, restore procedures, and firmware upgrade paths. Ensures operational continuity before making production changes.

  • Lesson 2 • Admin Console Navigation and Initial Setup

    Guides through the web admin console layout, wizards, and CLI access. Proficiency here accelerates all hands-on labs in later chapters.

  • Lesson 3 • System Architecture and Core Components

    Examines internal processing pipeline, traffic flow, and key subsystems. Understanding architecture enables accurate troubleshooting and performance planning.

  • Lesson 4 • Deployment Modes and Network Placement

    Covers gateway, bridge, and TAP deployment modes with placement trade-offs. Students select the correct mode for a given network topology.

  • Lesson 5 • Firewall Concepts and Platform Overview

    Covers next-generation firewall principles and Sophos Firewall's position in the security ecosystem. Establishes the conceptual baseline for all subsequent configuration topics.

Chapter 2See details

Network Configuration and Interface Management

  • Lesson 1 • Network Address Translation

    Covers SNAT, DNAT, and masquerading rules with real-world use cases. NAT configuration is required before internet connectivity and server publishing labs.

  • Lesson 2 • IPv4 and IPv6 Addressing

    Configures static and dynamic addressing for both IP versions on all interface types. Dual-stack awareness prepares students for modern network environments.

  • Lesson 3 • Interface Types and Zone Design

    Covers physical, VLAN, LAG, and alias interfaces alongside security zone concepts. Correct zone design is prerequisite to all firewall rule creation.

  • Lesson 4 • DHCP Server and Relay Configuration

    Configures DHCP scopes, reservations, and relay agents for multi-segment networks. Proper DHCP setup reduces manual addressing errors in lab and production.

  • Lesson 5 • Routing: Static, Dynamic, and Policy-Based

    Teaches static routes, OSPF, BGP basics, and policy-based routing for traffic steering. Routing knowledge underpins VPN and SD-WAN configurations in later chapters.

Chapter 3See details

Firewall Rules and Traffic Control

  • Lesson 1 • Rule Optimisation and Auditing

    Identifies shadowed, unused, and overly permissive rules using built-in diagnostics. Regular auditing maintains a clean, effective rule base over time.

  • Lesson 2 • User-Based and Identity-Aware Policies

    Applies firewall rules to authenticated users and groups via directory integration. Identity-aware policies enable granular access control beyond IP addresses.

  • Lesson 3 • Firewall Rule Fundamentals

    Explains rule components, match criteria, and action types within the unified rule table. Mastery here is the gateway to all policy-based security controls.

  • Lesson 4 • Host, Network, and Service Objects

    Creates reusable IP host, network, and service objects to simplify rule management. Object-based design reduces errors and speeds up policy updates.

  • Lesson 5 • Application Control and Traffic Shaping

    Uses deep packet inspection to identify and control applications, then applies QoS policies. Combines visibility with bandwidth management for business-critical traffic.

Chapter 4See details

Web Filtering and Application Security

  • Lesson 1 • Application Visibility and Control

    Uses synchronised app control and deep packet inspection to manage SaaS and cloud apps. Visibility into application usage supports both security and compliance objectives.

  • Lesson 2 • URL Filtering and Category Management

    Configures category-based allow and block actions, custom URL lists, and override workflows. Granular URL control reduces exposure to phishing and inappropriate content.

  • Lesson 3 • HTTPS Inspection and Certificate Management

    Deploys SSL/TLS inspection to decrypt, scan, and re-encrypt HTTPS traffic. Certificate trust chain management ensures seamless user experience during inspection.

  • Lesson 4 • Web Malware Scanning and Sandboxing

    Integrates antivirus and Sophos Sandstorm for file-based threat detection in web traffic. Layered scanning stops known and unknown malware before it reaches endpoints.

  • Lesson 5 • Web Policy Architecture

    Explains web policy structure, category databases, and policy assignment to firewall rules. Understanding policy hierarchy prevents conflicting or bypassed controls.

Chapter 5See details

Intrusion Prevention and Threat Protection

  • Lesson 1 • IPS Engine Architecture and Policies

    Covers IPS rule sets, policy profiles, and assignment to firewall rules. Proper IPS policy design balances detection accuracy against false-positive risk.

  • Lesson 2 • Signature Management and Tuning

    Manages signature updates, exception lists, and severity-based actions to reduce noise. Tuning ensures high-fidelity alerts without overwhelming security operations.

  • Lesson 3 • Synchronised Security and Security Heartbeat

    Links endpoint health status to firewall policy enforcement via the security heartbeat. Compromised endpoints are automatically restricted without manual intervention.

  • Lesson 4 • Advanced Threat Protection

    Configures ATP to detect command-and-control traffic and compromised host indicators. ATP integrates with synchronised security to isolate infected endpoints automatically.

  • Lesson 5 • DoS and Flood Protection

    Configures DoS rules, flood protection thresholds, and connection rate limits. These controls protect firewall resources and downstream servers from volumetric attacks.

Chapter 6See details

VPN Configuration and Remote Access

  • Lesson 1 • Sophos Connect Client Deployment

    Deploys and manages the Sophos Connect IPsec/SSL client for end-user remote access. Centralised provisioning reduces support overhead and enforces consistent tunnel settings.

  • Lesson 2 • Site-to-Site IPsec Tunnel Configuration

    Builds policy-based and route-based site-to-site tunnels between Sophos and third-party gateways. Interoperability knowledge enables secure branch connectivity in mixed environments.

  • Lesson 3 • IPsec VPN Fundamentals

    Covers IKEv1 and IKEv2 negotiation, phase parameters, and authentication methods. A solid IPsec foundation is required before configuring site-to-site or road-warrior tunnels.

  • Lesson 4 • SSL VPN for Remote Users

    Configures SSL VPN portals, client profiles, and split-tunneling for remote workers. SSL VPN provides clientless and full-tunnel access without complex client deployment.

  • Lesson 5 • VPN Troubleshooting and Diagnostics

    Uses logs, packet captures, and CLI tools to diagnose tunnel negotiation and routing failures. Systematic troubleshooting methodology resolves VPN issues faster in production.

Chapter 7See details

Email Protection and Anti-Spam

  • Lesson 1 • Email Malware Scanning and Sandboxing

    Applies AV scanning and sandbox analysis to email attachments and embedded links. Sandboxing catches zero-day malware that signature-based engines miss.

  • Lesson 2 • Email Security Architecture

    Explains MTA mode, MX record routing, and the email processing pipeline. Architecture understanding prevents misconfiguration that could expose mail servers.

  • Lesson 3 • Data Loss Prevention for Email

    Creates DLP rules to detect and block sensitive data in outbound email. DLP policies support regulatory compliance and protect intellectual property.

  • Lesson 4 • Email Policy and Quarantine Management

    Manages per-user and global quarantine, allow/block lists, and policy exceptions. Effective quarantine management balances security with minimal user disruption.

  • Lesson 5 • Anti-Spam and Anti-Phishing Controls

    Configures spam scoring, sender reputation, and phishing detection policies. Layered anti-spam controls reduce user exposure to social engineering attacks.

Chapter 8See details

Monitoring, Logging, and Advanced Administration

  • Lesson 1 • Log Management and SIEM Integration

    Configures local and remote syslog, log verbosity, and SIEM forwarding for centralised analysis. Structured log forwarding is essential for enterprise security operations.

  • Lesson 2 • Sophos Central Cloud Management

    Enrolls firewalls in Sophos Central for centralised policy management and group-based deployment. Cloud management scales administration across multi-site environments efficiently.

  • Lesson 3 • Dashboard and Real-Time Monitoring

    Uses the control centre dashboard and live connection viewer for real-time traffic visibility. Real-time monitoring enables rapid detection of anomalies and policy violations.

  • Lesson 4 • Reports and Compliance Dashboards

    Generates scheduled and on-demand reports for traffic, threats, and user activity. Reports provide evidence for audits and inform capacity planning decisions.

  • Lesson 5 • High Availability and Performance Tuning

    Configures active-active and active-passive HA clusters and tunes performance parameters. HA and tuning ensure continuous protection and optimal throughput under load.

Certification

Your valid completion certificate

This course is for you:

  • Network administrator: responsible for infrastructure but new to Sophos specifically.

  • IT support technician: ready to move into a dedicated network security role.

  • Systems integrator: deploying Sophos solutions for small and mid-sized business clients.

  • Security analyst: wanting deeper firewall visibility to strengthen threat investigation workflows.

  • Career changer: transitioning from general IT support into network security administration.

  • MSP technician: managing multiple client environments and needing scalable firewall skills.

What our students say

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast and simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top upskilling courses

FAQ

Who is Dedika?

Is the certificate valid in Australia?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course