With plug‑and‑protect deployment, centralized firewall management, AES‑256 encryption, optional Wi‑Fi/3G/4G modules, and Synchronized SD‑WAN capabilities, SD‑RED appliances offer an easy and affordable alternative to traditional MPLS connections.
Sophos SD‑RED Models
Sophos provides two SD‑RED models to address different performance and branch‑office needs:
- SD‑RED 20: Entry‑level model designed for small branch offices, retail sites, and home‑office deployments requiring secure, centrally managed connectivity.
- SD‑RED 60: High‑performance model built for larger branch offices with more users, higher throughput demands, and Power‑over‑Ethernet (PoE) support.
What’s special about SD‑RED?
- Zero‑touch deployment — plug in the device, connect to the internet, and it automatically establishes a secure VPN tunnel to your Sophos Firewall.
- Centrally managed from your Sophos Firewall (XGS/SG), with all configuration pushed automatically—no on‑site technical skills needed.
- AES‑256 encrypted tunnels for secure branch connectivity.
- Flexible WAN options, including support for Wi‑Fi, 3G/4G modules, and SFP transceivers.
- Synchronized SD‑WAN when managed by Sophos Firewall OS (SFOS), optimizing application routing and ensuring reliable connectivity.
- Plug‑and‑play connectivity replaces costly MPLS circuits with encrypted SD‑WAN tunneling.
- Optional redundant power supplies for high availability.
SD‑RED 20 – Features & Specs
The SD‑RED 20 is ideal for smaller branch offices, home offices, or retail environments needing secure, low‑maintenance VPN connectivity.
Performance
- Max tunnel throughput: 250 Mbps
Connectivity
- 4 × GE LAN ports
- 1 × SFP (shared with WAN)
- 1 × WAN (shared with SFP)
Modularity
- 1 expansion slot for optional:
- Wi‑Fi module
- 3G/4G module
- SFP transceivers
Highlights
- Easy plug‑and‑protect deployment
- Centralized firewall‑based management
- AES‑256 encrypted tunnels
- Suitable for small offices with basic throughput needs
SD‑RED 60 – Features & Specs
The SD‑RED 60 is designed for larger branch offices requiring higher throughput, more WAN options, and PoE capability.
Performance
- Max tunnel throughput: 850 Mbps
Connectivity
- 4 × GE LAN ports
- 1 × SFP (shared with WAN1)
- 2 × WAN ports
- 2 × PoE ports (total 30W) for powering APs or VoIP devices
Modularity
- 1 expansion slot for optional:
- Wi‑Fi module
- 3G/4G module
- SFP transceivers
Highlights
- Supports powering Sophos APs directly via PoE
- Provides dual‑WAN failover or load balancing
- Higher throughput for busy branch networks
- Perfect for distributed enterprises with multiple users
Key Capabilities
- Plug‑and‑Protect Branch Connectivity: Simply enter the device ID into your firewall, ship the device to the remote location, and plug it in. It automatically retrieves the config and establishes a secure tunnel.
- Flexible Deployment Modes:
- Tunnel all traffic through HQ firewall
- Split tunnel for optimized internet routing
- Transparent mode to blend into existing networks
- Strong Encryption: All traffic between SD‑RED and the firewall is protected with AES‑256 encryption, ensuring secure communication across public networks.
- Synchronized SD‑WAN: Integrated with Sophos Firewall and Intercept X for intelligent, application‑aware WAN routing.
- Optional Add‑Ons
- Wi‑Fi 5 module
- 3G/4G cellular module
- SFP optical transceivers
- Redundant power supply
Business Impact
- Extend secure connectivity to remote sites without additional IT staff.
- Reduce MPLS costs by replacing them with encrypted SD‑WAN tunnels.
- Improve reliability with dual‑WAN and PoE (SD‑RED 60).
- Simplify operations through centralized firewall management.
- Scale easily across multiple branch locations.
- Enhance visibility and safety with real‑time integration into the Sophos ecosystem.

