TTechclick ⚡ XP 0% All lessons
Sophos · Next-Gen Firewall · Synchronized SecurityInteractive · L1 / L2 / L3

Sophos Synchronized Security — the Security Heartbeat & Auto-Isolation

Most networks treat the firewall and the endpoint as strangers — one sees packets, the other sees the host, and neither tells the other anything. Sophos Synchronized Security wires them together over the Security Heartbeat so that the moment an endpoint is compromised, the firewall knows and the network reacts on its own.

📅 2026-06-19 · ⏱ 16 min · 5 infographics · live heartbeat demo · 🏷 10-Q assessment + AI Tutor inline

⚡ Quick Answer

A clear, interactive guide to Sophos Synchronized Security and the Security Heartbeat (2026): how Sophos Firewall and Sophos endpoints (Intercept X) share live telemetry through Sophos Central, the green/yellow/red health model, heartbeat policies that auto-isolate a compromised host, Lateral Movement Protection, and Synchronized App Control.

🎯 By the end you will be able to

Read as:

Pick where you want to start

1

The problem

Firewall and endpoint do not talk; dwell time and lateral spread.

2

The Heartbeat

Live telemetry plus the green/yellow/red health model.

3

Auto-response

Isolate red hosts and stop lateral movement.

4

App Control & setup

Name unknown apps; wire it up in Sophos Central.

🧠 Warm-up — 3 questions, no score

Just notice which ones make you pause. We answer all three inside the lesson.

1. Do a normal firewall and a normal endpoint share what they each see?

Answered in The problem.

2. What colour does a compromised endpoint show to the firewall?

Answered in The Heartbeat.

3. Can the firewall isolate a sick host on its own?

Answered in Auto-response.

Most engineers think…

Most people picture the firewall and the endpoint as two separate products you happen to buy from the same vendor — the firewall guards the perimeter, the antivirus guards the laptop, and that is the end of it.

Sophos Synchronized Security breaks that wall down. The Sophos Firewall and the Sophos endpoints (Intercept X), both managed in Sophos Central, share live telemetry over the Security Heartbeat. The firewall always knows each endpoint's health, so a compromised host is automatically restricted or isolated and healthy machines stop talking to it — no analyst, no ticket, no waiting. Understanding that the network and the host act as one system is the whole point of the feature, and the thing interviewers want to hear.

① The problem — the firewall and the endpoint don't talk

In a traditional network the firewall and the endpoint are blind to each other. The firewall sees packets crossing the boundary but has no idea whether the laptop sending them is healthy or already owned. The endpoint agent sees the host in detail but cannot change anything on the network. Two sensors, zero conversation.

That gap has a cost. After a phishing click, malware can sit on a machine for minutes or hours — that delay is dwell time — and reach file shares and other PCs before anyone reacts. Worse, two machines on the same switch can infect each other without ever crossing the firewall, so the perimeter never sees the lateral movement at all. The endpoint knew, the firewall could have helped, but nobody told anybody.

Quick check · Q1 of 10 · Understand

Why is dwell time and lateral movement a problem on a traditional network?

Correct: b. The firewall sees packets but not host health; the endpoint sees the host but can't change the network. With no shared signal, a sick machine reaches shares and peers for minutes — and same-switch spread never even crosses the firewall.
👉 So far: Traditionally the firewall sees packets and the endpoint sees the host, but they don't share — so dwell time and same-switch lateral movement go unaddressed.

② What the Security Heartbeat is — and the colour model

Synchronized Security closes that gap. The Security Heartbeat is a real-time telemetry channel that connects the Sophos Firewall to the Sophos endpoints, all orchestrated through Sophos Central. Over it the endpoints continuously report health and the firewall continuously reads it, so the network finally knows what the hosts know.

Health is a colour

Each endpoint shows the firewall one of three states. GREEN means healthy. YELLOW means potentially compromised — for example a PUA was detected or the agent is inactive. RED means compromised or under active threat. The firewall sees each endpoint's colour live, which is what lets the next step — automated response — actually happen.

Figure 1 — How the heartbeat loop works
Detect on the host, share over the heartbeat, decide on the firewall, then respond and recover.How the heartbeat loop worksDetectIntercept X on hostReporthealth over heartbeatSee colourfirewall reads statusRespondrestrict / isolateRecovergreen = restored
Detect on the host, share over the heartbeat, decide on the firewall, then respond and recover.
Figure 2 — The three heartbeat colours
Each endpoint reports one health colour that the firewall reads in real time.The three heartbeat coloursGREEN — healthyNo detections; full network accessYELLOW — potentialPUA detected or agent inactiveRED — compromisedActive threat; eligible for isolation
Each endpoint reports one health colour that the firewall reads in real time.
💓
Security Heartbeat
tap to flip

The real-time channel carrying endpoint health, app identity and clean-up signals between Sophos Firewall and Sophos endpoints via Central.

🚦
Health colour
tap to flip

Green = healthy, Yellow = potentially compromised (PUA or inactive agent), Red = compromised. The firewall reads each endpoint's colour live.

🛡️
Lateral Movement Protection
tap to flip

When a host goes red, healthy endpoints stop accepting its traffic — isolation enforced host-to-host, even on the same switch.

🔎
Synchronized App Control
tap to flip

The firewall asks the endpoint to name the app behind 'Unknown' traffic, turning unclassified flows into identified applications.

Say 'one system', not 'two products'

In an interview, frame Synchronized Security as the firewall and endpoint acting as one system over the Security Heartbeat, orchestrated by Sophos Central. The headline is that the network reacts to host health automatically — green/yellow/red — without a human in the loop.

Quick check · Q2 of 10 · Remember

What does a YELLOW heartbeat status indicate?

Correct: c. Yellow is the warning state: potentially compromised, such as a PUA detection or an inactive agent. Green is healthy and red is compromised / active threat.
👉 So far: The Security Heartbeat is the real-time channel between Sophos Firewall and endpoints via Sophos Central; health shows as green (healthy), yellow (potential), red (compromised).

③ Automated response — isolate the sick, protect the healthy

Knowing a host is red is only useful if something acts on it. In Sophos Firewall a rule can require a minimum heartbeat status for the source and/or destination. When an endpoint turns RED, the rule automatically restricts or isolates it — often limiting it to remediation destinations only — until it returns to green. The same rule can act on a missing heartbeat: a host that should be reporting but has gone silent.

Containment at two levels

The firewall handles traffic that crosses it, but Lateral Movement Protection handles the rest. When an endpoint goes red, the healthy endpoints stop accepting its traffic — isolation enforced by the endpoint agents themselves, not just the firewall. That contains the spread even between two machines on the same subnet or switch that never touch the firewall. Once Intercept X cleans the host and it reports green again, access is restored automatically.

Figure 3 — One system, orchestrated by Central
Firewall and endpoints exchange health, app identity and clean-up signals over the Security Heartbeat.One system, orchestrated by CentralSophos Central+ Security HeartbeatSophos FirewallIntercept X hostHeartbeat policyLateral Move Prot.Synced App ControlSource of Infection
Firewall and endpoints exchange health, app identity and clean-up signals over the Security Heartbeat.
Figure 4 — Firewall isolation vs Lateral Movement Protection
Two layers of containment — one at the boundary, one host-to-host — cover different paths a threat can take.Firewall isolation vs Lateral Movement ProtectionFirewall heartbeat policyActs on traffic crossing theRestricts or isolates a red hostCan limit it to remediation onlyAlso catches a missing heartbeatLateral Movement ProtectionActs host-to-host on the endpointHealthy endpoints refuse the redWorks on the same subnet / switchContains spread the firewall never
Two layers of containment — one at the boundary, one host-to-host — cover different paths a threat can take.
'The firewall isolates everything' over-claim

The firewall heartbeat policy only acts on traffic that crosses the firewall. It cannot stop two machines on the same switch infecting each other — that is Lateral Movement Protection, enforced by the endpoints. Always name both layers.

▶ Watch an infected laptop get isolated, then restored

How one compromised endpoint is contained end-to-end. Press Play for the healthy path, then Break it to see the classic failure.

① InfectedA finance laptop in Mumbai is compromised after a phishing click; Intercept X detects the active threat on the host.
② Tell CentralThe endpoint reports its health over the Security Heartbeat through Sophos Central — its status flips to RED.
③ IsolateThe firewall rule sees RED and restricts the host, while healthy endpoints stop talking to it (Lateral Movement Protection).
④ Clean & restoreIntercept X cleans the threat; the host reports GREEN again and the firewall automatically restores normal access.
Press Play to step through the healthy isolation path. Then press Break it.
Quick check · Q3 of 10 · Apply

A red endpoint and a healthy one sit on the same switch and never cross the firewall. What stops the infection spreading?

Correct: a. Firewall rules only act on traffic that crosses the firewall. Lateral Movement Protection is enforced by the endpoint agents host-to-host, so healthy machines stop talking to the red one even on the same subnet.
👉 So far: A firewall heartbeat policy isolates a red or missing-heartbeat host; Lateral Movement Protection makes healthy endpoints refuse its traffic even on the same subnet — recovery on green is automatic.

④ Synchronized App Control — and setting it up without breaking it

The same channel solves a different blind spot. Pattern-based app control labels a lot of traffic as 'Unknown' or 'Unclassified' — custom apps, evasive tools, odd ports. With Synchronized App Control the firewall simply asks the endpoint which application produced that flow, turning those unknowns into named applications. The endpoint sees the process; the firewall gets the name. The Control Center also surfaces Source of Infection and Security Heartbeat reporting, and the firewall can trigger a clean-up on the endpoint over the link.

Set it up via Sophos Central

All of this needs the endpoints managed in the same Sophos Central account and registered with the firewall. Then you must enable the heartbeat requirement in the firewall rule itself. The classic failure: endpoints are not registered, or the rule never asks for a minimum heartbeat — so a red host is treated exactly like a healthy one and nothing is isolated. Register, then turn the heartbeat on in the rule, then test.

Figure 5 — Setting it up in Sophos Central
Get the prerequisites right first, then enable the heartbeat in the rule — or nothing isolates.Setting it up in Sophos CentralSame Centralone account, bothproductsRegisterendpoints to firewallEnable in rulemin heartbeat requiredTestforce red, watchisolate
Get the prerequisites right first, then enable the heartbeat in the rule — or nothing isolates.

Priya at Mehta Logistics, Mumbai faces this

A finance laptop is hit by malware after a phishing click and keeps reaching internal file shares and other PCs for several minutes — Intercept X flagged it, but nothing on the network changed.

Likely cause

The endpoints report health to the firewall, but the firewall rule covering the finance VLAN has the minimum-heartbeat requirement left OFF, so a red host is treated like a healthy one.

Diagnosis

In the Control Center the laptop shows RED, but the relevant firewall rule has no heartbeat option set — so the rule never triggers isolation and Lateral Movement Protection never contains the peer traffic.

Sophos Central ▸ Firewall ▸ Control Center ▸ Security Heartbeat, then Rules and Policies ▸ the rule
Fix

Confirm the endpoints are registered with the firewall in Central, then edit the rule to require a minimum source heartbeat and isolate a RED host (limit to remediation) until green; enable missing-heartbeat handling too.

Verify

Force a controlled detection — the laptop goes RED, the firewall isolates it, healthy endpoints stop accepting its traffic, and once Intercept X cleans it and it returns GREEN, normal access is restored automatically.

Prove isolation, don't assume it

Never trust that Synchronized Security is working because the products are installed. Force a test detection and watch the host go RED in the Control Center and actually lose access. If it doesn't, the endpoints aren't registered or the rule has no minimum heartbeat.

Quick check · Q4 of 10 · Analyze

Synchronized Security is configured but a red host is never isolated. What is the most likely cause?

Correct: d. The real prerequisites are registration in the same Sophos Central account and a heartbeat requirement enabled in the rule. If endpoints aren't registered or the rule never asks for a minimum heartbeat, a red host is treated like a healthy one and nothing isolates.
👉 So far: Synchronized App Control names 'Unknown' traffic via the endpoint. It all needs endpoints in the same Central account, registered with the firewall, and the heartbeat enabled in the rule — or nothing isolates.

🤖 Ask the AI Tutor

Tap any question — instant, scoped to this lesson. No login, no waiting.

Pre-curated from vendor docs + community Q&A, scoped to this lesson. For a live prod issue, paste your export into chat.techclick.in.

📝 Wrap-up assessment — six more

You've answered 4 inline. Six left. 70% (7 of 10) marks the lesson complete on your profile. Tap Submit all answers at the end.

Q5 · Apply

An endpoint goes red but a peer on the same switch still gets infected without crossing the firewall. Which feature should have stopped it?

Correct: a. Lateral Movement Protection is enforced host-to-host by the endpoint agents, so healthy endpoints refuse the red one's traffic even on the same subnet. Firewall rules only act on traffic that crosses the firewall.
Q6 · Understand

The Security Heartbeat is best described as…

Correct: b. The Security Heartbeat is the real-time link that shares endpoint health, app identity and clean-up signals between the firewall and the endpoints, orchestrated through Sophos Central.
Q7 · Remember

Which colour means an endpoint is compromised or under active threat?

Correct: c. Red = compromised / active threat and is eligible for isolation. Green is healthy; yellow is potentially compromised (e.g. PUA or inactive agent).
Q8 · Analyze

Why is Synchronized App Control useful on top of normal app control?

Correct: d. Pattern-based app control leaves custom or evasive traffic as 'Unknown'. The endpoint sees the process, so the firewall can label the flow — closing a visibility gap that signatures miss.
Q9 · Evaluate

Synchronized Security is installed but a red host is never isolated. What do you check first?

Correct: a. The prerequisites are endpoints managed in the same Sophos Central account and registered with the firewall, plus a heartbeat requirement enabled in the rule. Miss either and a red host is treated like a healthy one.
Q10 · Evaluate

What is the strongest description of the value Synchronized Security adds?

Correct: b. The point is automated, coordinated response: shared telemetry over the heartbeat means a compromised host is isolated and contained on its own, not after a human notices a ticket.
Lesson complete — saved to your profile.
Almost! You need 70% (7 of 10) — re-read the path that tripped you up and tap "Try again".

🧠 In your own words

Type one line: why does Sophos call the firewall and the endpoint working together 'Synchronized Security'? Then compare with the expert version.

Expert version: Because the firewall and the endpoint stop being two blind silos and start acting as one system. Over the Security Heartbeat — orchestrated by Sophos Central — Sophos endpoints (Intercept X) report live health as green, yellow or red, and the firewall reads it. A red host is automatically restricted or isolated by a heartbeat policy while healthy endpoints stop talking to it through Lateral Movement Protection, and Synchronized App Control even lets the firewall name the apps it could only see as 'Unknown'. The network responds to host health on its own, which is exactly why it is 'synchronized' rather than just 'two products from one vendor'.

🗣 Teach a friend

Best way to lock it in — explain it in one line to a teammate. Tap to generate a paste-ready summary.

📖 Glossary

Synchronized Security
Sophos's approach where the firewall and endpoints share telemetry over the Security Heartbeat and respond together as one system.
Security Heartbeat
The real-time channel that shares endpoint health, app identity and clean-up signals between Sophos Firewall and Sophos endpoints via Sophos Central.
Heartbeat status
An endpoint's live health colour — green (healthy), yellow (potentially compromised), red (compromised) — that the firewall reads.
Heartbeat policy
A setting in a firewall rule requiring a minimum heartbeat for source/destination, isolating a red or missing-heartbeat host until it goes green.
Lateral Movement Protection
Host-to-host isolation where healthy endpoints stop accepting traffic from a red one, containing spread even on the same subnet.
Synchronized App Control
The firewall asking the endpoint to name the app behind unknown/unclassified traffic, turning 'Unknown' flows into identified applications.
Intercept X
Sophos's endpoint protection that detects threats locally and reports health over the heartbeat.
Sophos Central
The cloud console that connects and manages the firewall and endpoints in one account.
Source of Infection
The Control Center view showing which host originated a detected threat.

📚 Sources

  1. Sophos — Synchronized Security: how Sophos Firewall and endpoints work together. sophos.com
  2. Sophos Firewall docs — Security Heartbeat and heartbeat configuration. docs.sophos.com
  3. Sophos Firewall docs — Configure a firewall rule with a minimum source/destination heartbeat. docs.sophos.com
  4. Sophos — Lateral Movement Protection in Synchronized Security. sophos.com
  5. Sophos Firewall docs — Synchronized Application Control. docs.sophos.com
  6. Sophos Central docs — Registering Sophos Firewall and managing endpoints. docs.sophos.com

What's next?

Now that the firewall and endpoint talk, the next gap is encrypted traffic. Next, go deep on Xstream TLS 1.3 inspection — how decryption rules and profiles let the firewall actually see inside HTTPS without breaking everything.