IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

WatchGuard XTM 535 review

Multi-Gigabit security appliances normally command premium prices but WatchGuard’s XTM 535 breaks with tradition by offering a high performance at SonicWALL beating value.

Anti-spam and web filtering

Setting up anti-spam measures is easy enough as you just enable and configure the POP3 and SMTP proxies within a policy. These use the Commtouch hosted service which we've always found delivers excellent spam detection rates.

Web filtering is applied using WebBlocker profiles within the HTTP and HTTPS proxies where you pick and choose from 56 URL categories and decide whether to block or allow them. You can tie alerts and logging actions to any transgressions and profiles can use the local override feature which allows users to enter a password to access a site that would normally be blocked.

There's nothing to configure for the gateway anti-virus as you merely enable it on selected policies. For IPS, you have five global threat levels where you choose drop, allow, log or alert actions for each one and apply them to policies.

WatchGuard's application controls are versatile as you can pick from a huge range of apps and at the most basic level, block or allow them. However, for many apps you can control specific activities. For example, for Facebook users you can decide whether they can login, edit their profile, chat, access web mail or transfer files.

WatchGuard XTM 535 - Websense

Websense looks after web content filtering and provides a database with 56 different categories

WatchGuard's Server Center

One feature that differentiates WatchGuard from the rest is its Server Center. This comprises separate WebBlocker, Report, Log and Quarantine services which we recommend loading before going any further.

Whereas much of the competition use hosted URL filtering services, WatchGuard's WebBlocker requires the Websense category database to be downloaded to the Server Center where the appliance accesses it locally. On-appliance logging and reporting is minimal so you'll need the Log and Report servers to gather more useful information.

The appliance also provides basic options for handling spam. If you don't use the separate quarantine server then spam and infected messages can only be deleted or tagged and passed on for processing by your mail server or client.

You can distribute the load by running each component on different systems but we found it easy enough to install them all on a single Windows 7 system.

WatchGuard XTM 535 - Server Center

You'll need to load up the Server Center components on a separate system to use WatchGuard's WebBlocker, quarantining and reporting features

Previously, you had to use the Windows Task Manager to automatically update the WebBlocker URL database but this is now run regularly every day at midnight. You can't change this schedule but you can manually run updates from the Server Center if required.

For reporting you need to set the appliance to send its logs to the log server. These are gathered by the report server which offers an extensive range of predefined reports which can be exported to HTML or PDF formats.


The combination of good value and high throughput makes the XTM 535 difficult to beat. It also offers an extensive range of security measures backed up by some big names. The additional Server Center components do mean it will require an additional host system to run them but their light footprint doesn't require it to be dedicated.


The XTM 535 packs in an impressive range of security measures and offers a very high throughput for the price. It does take some practice to get the hang of configuring WatchGuard’s proxies and actions but we found they perform very well in the real world.

Chassis: 1U rack

Performance: 3Gbps firewall; 1.1Gbps UTM

CPU: 2.6GHz Intel Pentium E5300

Memory: 2GB RAM; 1GB Flash

Network: 6 x Gigabit, 1 x 10/100

Ports: USB, RJ-45 serial

Management: Web browser or WatchGuard software

Software: WatchGuard System and Firebox Manager plus WebBlocker, Report, Log and Quarantine servers

Options: Appliance and 3-yr Security Bundle, £5,017 ex VAT

Featured Resources

What 2023 will mean for the industry

What do most IT decision makers really think will be the important trends and challenges in the coming year?

Free Download

2022 Magic quadrant for Security Information and Event Management (SIEM)

SIEM is evolving into a security platform with multiple features and deployment models

Free Download

IDC MarketScape: Worldwide unified endpoint management services

2022 vendor assessment

Free Download

Magic quadrant for application performance monitoring and observability

Enabling continuous updating of diverse & dynamic application environments

View Now

Most Popular

Dutch hacker steals data from virtually entire population of Austria
data breaches

Dutch hacker steals data from virtually entire population of Austria

26 Jan 2023
GTA V vulnerability exposes PC users to partial remote code execution attacks

GTA V vulnerability exposes PC users to partial remote code execution attacks

23 Jan 2023
European partners expect growth this year, here are three ways they will achieve it

European partners expect growth this year, here are three ways they will achieve it

17 Jan 2023