
Sophos Firewall Training
Master Sophos Firewall from the ground up and gain the hands-on skills to deploy, configure, and manage enterprise-grade network security. This course covers everything from firewall fundamentals and VPN setup to advanced threat protection and compliance reporting. Whether you're securing a single site or a distributed enterprise, you'll finish ready to protect real networks with confidence.
What you will learn:
This course takes you through every critical layer of Sophos Firewall administration. You will configure network interfaces, zones, routing, and NAT to build a solid network foundation. From there, you will enforce access control with firewall rules, web filtering, and application control policies. You will deploy IPS, ATP, and synchronized security to detect and contain advanced threats. VPN chapters cover IPsec, SSL, and SD-WAN overlays for secure connectivity across sites and remote users. You will also set up email protection, generate compliance reports, and integrate the firewall with Sophos Central for centralized management.
How you study in a practical way Sophos Firewall Training
How you practice Sophos Firewall Training
For companies who want to train their team
With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsSophos Firewall Fundamentals and Architecture
Sophos Firewall Fundamentals and Architecture
Lesson 1 • Backup, Restore, and Firmware Management
Teaches configuration backup strategies, restore procedures, and firmware upgrade paths. Ensures operational continuity before making production changes.
Lesson 2 • Admin Console Navigation and Initial Setup
Guides through the web admin console layout, wizards, and CLI access. Proficiency here accelerates all hands-on labs in later chapters.
Lesson 3 • System Architecture and Core Components
Examines internal processing pipeline, traffic flow, and key subsystems. Understanding architecture enables accurate troubleshooting and performance planning.
Lesson 4 • Deployment Modes and Network Placement
Covers gateway, bridge, and TAP deployment modes with placement trade-offs. Students select the correct mode for a given network topology.
Lesson 5 • Firewall Concepts and Platform Overview
Covers next-generation firewall principles and Sophos Firewall's position in the security ecosystem. Establishes the conceptual baseline for all subsequent configuration topics.
Chapter 2HideHide detailsSee detailsNetwork Configuration and Interface Management
Network Configuration and Interface Management
Lesson 1 • Network Address Translation
Covers SNAT, DNAT, and masquerading rules with real-world use cases. NAT configuration is required before internet connectivity and server publishing labs.
Lesson 2 • IPv4 and IPv6 Addressing
Configures static and dynamic addressing for both IP versions on all interface types. Dual-stack awareness prepares students for modern network environments.
Lesson 3 • Interface Types and Zone Design
Covers physical, VLAN, LAG, and alias interfaces alongside security zone concepts. Correct zone design is prerequisite to all firewall rule creation.
Lesson 4 • DHCP Server and Relay Configuration
Configures DHCP scopes, reservations, and relay agents for multi-segment networks. Proper DHCP setup reduces manual addressing errors in lab and production.
Lesson 5 • Routing: Static, Dynamic, and Policy-Based
Teaches static routes, OSPF, BGP basics, and policy-based routing for traffic steering. Routing knowledge underpins VPN and SD-WAN configurations in later chapters.
Chapter 3HideHide detailsSee detailsFirewall Rules and Traffic Control
Firewall Rules and Traffic Control
Lesson 1 • Rule Optimization and Auditing
Identifies shadowed, unused, and overly permissive rules using built-in diagnostics. Regular auditing maintains a clean, effective rule base over time.
Lesson 2 • User-Based and Identity-Aware Policies
Applies firewall rules to authenticated users and groups via directory integration. Identity-aware policies enable granular access control beyond IP addresses.
Lesson 3 • Firewall Rule Fundamentals
Explains rule components, match criteria, and action types within the unified rule table. Mastery here is the gateway to all policy-based security controls.
Lesson 4 • Host, Network, and Service Objects
Creates reusable IP host, network, and service objects to simplify rule management. Object-based design reduces errors and speeds up policy updates.
Lesson 5 • Application Control and Traffic Shaping
Uses deep packet inspection to identify and control applications, then applies QoS policies. Combines visibility with bandwidth management for business-critical traffic.
Chapter 4HideHide detailsSee detailsWeb Filtering and Application Security
Web Filtering and Application Security
Lesson 1 • Application Visibility and Control
Uses synchronized app control and deep packet inspection to manage SaaS and cloud apps. Visibility into application usage supports both security and compliance objectives.
Lesson 2 • URL Filtering and Category Management
Configures category-based allow and block actions, custom URL lists, and override workflows. Granular URL control reduces exposure to phishing and inappropriate content.
Lesson 3 • HTTPS Inspection and Certificate Management
Deploys SSL/TLS inspection to decrypt, scan, and re-encrypt HTTPS traffic. Certificate trust chain management ensures seamless user experience during inspection.
Lesson 4 • Web Malware Scanning and Sandboxing
Integrates antivirus and Sophos Sandstorm for file-based threat detection in web traffic. Layered scanning stops known and unknown malware before it reaches endpoints.
Lesson 5 • Web Policy Architecture
Explains web policy structure, category databases, and policy assignment to firewall rules. Understanding policy hierarchy prevents conflicting or bypassed controls.
Chapter 5HideHide detailsSee detailsIntrusion Prevention and Threat Protection
Intrusion Prevention and Threat Protection
Lesson 1 • IPS Engine Architecture and Policies
Covers IPS rule sets, policy profiles, and assignment to firewall rules. Proper IPS policy design balances detection accuracy against false-positive risk.
Lesson 2 • Signature Management and Tuning
Manages signature updates, exception lists, and severity-based actions to reduce noise. Tuning ensures high-fidelity alerts without overwhelming security operations.
Lesson 3 • Synchronized Security and Security Heartbeat
Links endpoint health status to firewall policy enforcement via the security heartbeat. Compromised endpoints are automatically restricted without manual intervention.
Lesson 4 • Advanced Threat Protection
Configures ATP to detect command-and-control traffic and compromised host indicators. ATP integrates with synchronized security to isolate infected endpoints automatically.
Lesson 5 • DoS and Flood Protection
Configures DoS rules, flood protection thresholds, and connection rate limits. These controls protect firewall resources and downstream servers from volumetric attacks.
Chapter 6HideHide detailsSee detailsVPN Configuration and Remote Access
VPN Configuration and Remote Access
Lesson 1 • Sophos Connect Client Deployment
Deploys and manages the Sophos Connect IPsec/SSL client for end-user remote access. Centralized provisioning reduces support overhead and enforces consistent tunnel settings.
Lesson 2 • Site-to-Site IPsec Tunnel Configuration
Builds policy-based and route-based site-to-site tunnels between Sophos and third-party gateways. Interoperability knowledge enables secure branch connectivity in mixed environments.
Lesson 3 • IPsec VPN Fundamentals
Covers IKEv1 and IKEv2 negotiation, phase parameters, and authentication methods. A solid IPsec foundation is required before configuring site-to-site or road-warrior tunnels.
Lesson 4 • SSL VPN for Remote Users
Configures SSL VPN portals, client profiles, and split-tunneling for remote workers. SSL VPN provides clientless and full-tunnel access without complex client deployment.
Lesson 5 • VPN Troubleshooting and Diagnostics
Uses logs, packet captures, and CLI tools to diagnose tunnel negotiation and routing failures. Systematic troubleshooting methodology resolves VPN issues faster in production.
Chapter 7HideHide detailsSee detailsEmail Protection and Anti-Spam
Email Protection and Anti-Spam
Lesson 1 • Email Malware Scanning and Sandboxing
Applies AV scanning and sandbox analysis to email attachments and embedded links. Sandboxing catches zero-day malware that signature-based engines miss.
Lesson 2 • Email Security Architecture
Explains MTA mode, MX record routing, and the email processing pipeline. Architecture understanding prevents misconfiguration that could expose mail servers.
Lesson 3 • Data Loss Prevention for Email
Creates DLP rules to detect and block sensitive data in outbound email. DLP policies support regulatory compliance and protect intellectual property.
Lesson 4 • Email Policy and Quarantine Management
Manages per-user and global quarantine, allow/block lists, and policy exceptions. Effective quarantine management balances security with minimal user disruption.
Lesson 5 • Anti-Spam and Anti-Phishing Controls
Configures spam scoring, sender reputation, and phishing detection policies. Layered anti-spam controls reduce user exposure to social engineering attacks.
Chapter 8HideHide detailsSee detailsMonitoring, Logging, and Advanced Administration
Monitoring, Logging, and Advanced Administration
Lesson 1 • Log Management and SIEM Integration
Configures local and remote syslog, log verbosity, and SIEM forwarding for centralized analysis. Structured log forwarding is essential for enterprise security operations.
Lesson 2 • Sophos Central Cloud Management
Enrolls firewalls in Sophos Central for centralized policy management and group-based deployment. Cloud management scales administration across multi-site environments efficiently.
Lesson 3 • Dashboard and Real-Time Monitoring
Uses the control center dashboard and live connection viewer for real-time traffic visibility. Real-time monitoring enables rapid detection of anomalies and policy violations.
Lesson 4 • Reports and Compliance Dashboards
Generates scheduled and on-demand reports for traffic, threats, and user activity. Reports provide evidence for audits and inform capacity planning decisions.
Lesson 5 • High Availability and Performance Tuning
Configures active-active and active-passive HA clusters and tunes performance parameters. HA and tuning ensure continuous protection and optimal throughput under load.
Your valid completion certificate
This course is for you:
Network administrator: responsible for infrastructure but new to Sophos specifically.
IT support technician: ready to move into a dedicated network security role.
Systems integrator: deploying Sophos solutions for small and mid-sized business clients.
Security analyst: wanting deeper firewall visibility to strengthen threat investigation workflows.
Career changer: transitioning from general IT support into network security administration.
MSP technician: managing multiple client environments and needing scalable firewall skills.
What our students say
Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of my interest without needing to change platforms... I thank you for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top trainings
FAQs
Who is Dedika?
Is the certificate valid in the Philippines?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















