{"id":20378,"date":"2022-10-17T09:20:56","date_gmt":"2022-10-17T17:20:56","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/10\/17\/news-14111\/"},"modified":"2022-10-17T09:20:56","modified_gmt":"2022-10-17T17:20:56","slug":"news-14111","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/10\/17\/news-14111\/","title":{"rendered":"Sophos Firewall v19.5: Xstream TLS FastPath architecture enhancements"},"content":{"rendered":"<p><strong>Credit to Author: Chris McCormack| Date: Mon, 17 Oct 2022 14:20:56 +0000<\/strong><\/p>\n<div class=\"entry-content lg:prose-lg mx-auto prose max-w-4xl\" width=\"100%\" height=\"420\">\n<p>With Sophos Firewall v19.5 firmware now available for early access, we are coving one of the top new features <a href=\"https:\/\/news.sophos.com\/en-us\/tag\/sfos-v19-5\/\">every week<\/a> leading up to launch.<\/p>\n<p>In <a href=\"https:\/\/news.sophos.com\/en-us\/2022\/10\/10\/sophos-firewall-v19-5-sd-wan-load-balancing\/\">last week\u2019s article<\/a>, we covered the new SD-WAN load balancing feature that rounds out the full suite of Xstream SD-WAN capabilities in Sophos Firewall.<\/p>\n<p>This week, we\u2019ll have a look at the latest enhancements to the Xstream Architecture in Sophos Firewall, Xstream TLS FastPath.<\/p>\n<h2>Xstream Architecture<\/h2>\n<p>Sophos Firewall first introduced the Xstream Architecture in v18, but it really came to life with the introduction of the XGS Series appliances with dedicated Xstream Flow Processors for hardware acceleration.<\/p>\n<p>The illustration below outlines the internal architecture of the XGS Series appliances and how the Xstream Flow Processors provide FastPath acceleration for VPN, SD-WAN, and now TLS traffic flows.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/10\/Xstream.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-87404 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/10\/Xstream.png\" alt=\"\" width=\"2464\" height=\"1580\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/10\/Xstream.png 2464w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/10\/Xstream.png?resize=300,192 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/10\/Xstream.png?resize=768,492 768w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/10\/Xstream.png?resize=1024,657 1024w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/10\/Xstream.png?resize=1536,985 1536w, https:\/\/news.sophos.com\/wp-content\/uploads\/2022\/10\/Xstream.png?resize=2048,1313 2048w\" sizes=\"auto, (max-width: 2464px) 100vw, 2464px\" \/><\/a><\/p>\n<h2>Programmable processors = free performance upgrades<\/h2>\n<p>One of the key benefits of the Xstream Architecture and the Xstream Flow Processors is that they are programmable. This means that new features and capabilities can be added over time.<\/p>\n<p>For example, when the XGS Series launched, they initially supported FastPath acceleration of SD-WAN application traffic for up to double the performance over previous gen appliances. With v19, we added IPsec VPN acceleration, which provided up to a 5x increase in VPN traffic capacity.<\/p>\n<p>Now with v19.5, we\u2019re adding TLS traffic inspection to the FastPath to enable a significant performance boost in both TLS encrypted traffic and overall performance by adding additional headroom for traffic that needs deep packet inspection.<\/p>\n<p>Our design ensures your investment in Sophos Firewall and the XGS Series is protected and future-proof as you get free performance upgrades with every release.<\/p>\n<h2>TLS FastPath acceleration in v19.5<\/h2>\n<p>Sophos Firewall already has the best TLS inspection technology in the business, including&#8230;<\/p>\n<ul>\n<li>TLS 1.3 without downgrading<\/li>\n<li>Support for the latest cipher suites<\/li>\n<li>Powerful policy tools<\/li>\n<li>Instant visibility and troubleshooting right from the dashboard.<\/li>\n<\/ul>\n<p>Now, SFOS v19.5 adds TLS encrypted traffic FastPath acceleration for select XGS Series appliances, which automatically puts CPU-intensive asymmetric encryption operations for inspected TLS traffic flows on the FastPath through the Xstream Flow Processor.<\/p>\n<p>This takes full advantage of the hardware\u2019s asymmetric crypto capabilities within the Xstream Flow Processor and has the benefit of improving overall throughput and freeing up CPU resources for other tasks like deep-packet inspection.<\/p>\n<p>This new capability will initially be supported on the high-end XGS 4xxx and above only, which covers the vast majority of partners and customers utilizing TLS inspection today. Eventually, support will also be extended to other models in the series.<\/p>\n<p>If you want a quick refresher on the exciting Xstream technology packed into every XGS Series appliance, be sure to check out this video:<\/p>\n<div class=\"embed-vimeo\" style=\"text-align: center;\"><iframe loading=\"lazy\" src=\"https:\/\/player.vimeo.com\/video\/538986374\" width=\"100%\" height=\"420\" frameborder=\"0\" webkitallowfullscreen mozallowfullscreen allowfullscreen style=\"\"><\/iframe><\/div>\n<h2>Check out all the new features in v19.5<\/h2>\n<p>Sophos Firewall OS v19.5 includes a ton of great new capabilities. Check out the full list of what\u2019s new in this <a href=\"https:\/\/community.sophos.com\/sophos-xg-firewall\/sfos-v19-5-early-access-program\/m\/files\/9529\/download\">What\u2019s New PDF download<\/a>.<\/p>\n<h2>Early access<\/h2>\n<p>Start taking advantage of all the great new features in SFOS v19.5 today and help us make this release the best it can be by participating in the early access program. <a href=\"https:\/\/events.sophos.com\/sophosfirewallv195earlyaccess\">Visit the SFOS v19.5 EAP registration page<\/a> to get started.<\/p>\n<p>Sophos Firewall OS v19.5 EAP1 is a fully supported upgrade from any v18.5 firmware as well as v19, including the very recent v19 MR1 build 365 release.<\/p>\n<p>Once you\u2019re up and running, please provide feedback through your Sophos Firewall\u2019s feedback mechanism (top right of every screen on your Firewall). Also visit our <a href=\"https:\/\/community.sophos.com\/sophos-xg-firewall\/sfos-v19-5-early-access-program\/\">EAP community forums<\/a> to share your experiences with others.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2022\/10\/17\/sophos-firewall-v19-5-xstream-tls-fastpath-architecture-enhancements\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2021\/04\/sophos-firewall-Xstream-Flame-Graphic.png\"\/><\/p>\n<p><strong>Credit to Author: Chris McCormack| Date: Mon, 17 Oct 2022 14:20:56 +0000<\/strong><\/p>\n<p>Start taking advantage of all the great new features in SFOS v19.5 today.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[12235,10384,24562,27689],"class_list":["post-20378","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-firewall","tag-network","tag-products-services","tag-sfos-v19-5"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20378","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=20378"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20378\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=20378"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=20378"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=20378"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}