Open a Sophos support ticket with Support Assistant
There are two standard ways to start a support case: directly from the Sophos Central Help menu, or through Support Assistant in the Sophos Support Portal. Participating Central tenants also have their own Assistant as an Early Access Program. Since July 18, 2026, the Assistant has replaced the former New Technical Support Case form in the portal for signed-in customers.
💡 Important: Support Assistant is an AI-assisted guide, not a Support Engineer and not yet an open ticket. Its suggestions must be reviewed before making a change. A case exists only after Sophos displays a case number or confirms it by email.
Good preparation therefore matters more than the new dialog. For Sophos Firewall, the evidence package should include the serial number, model, firmware version, license status, time of the error, affected function, logs, screenshots and checks already performed. For classifying the different Sophos access points, see also Sophos portals: SophosID, Central, support and firewall access.
When a Sophos support ticket makes sense
A Sophos support ticket makes sense when a problem can no longer be clarified locally through configuration, logs or known operational processes alone.
Typical cases:
- hardware defect, RMA or suspected defective appliance
- license or account problem with a specific serial number
- firmware, hotfix or upgrade problem
- recurring service crash or unclear system state
- VPN, WAF, HA, RED or routing problem after initial local narrowing down
- error that looks like a product issue after logs and reproduction
- support request where Sophos needs access to internal analysis data
Before opening a ticket, the obvious local checks should be performed. For Sophos Firewall this does not mean everything must already be solved. But the more precisely the initial situation, time window and affected function are described, the fewer follow-up questions are needed.
What Sophos Support provides and what it does not
Sophos Support helps with technical product problems and can answer general configuration questions. It does not replace a complete implementation, migration or new architecture design. A ticket is especially appropriate when a function does not work correctly despite a traceable configuration, or when a specific product, license, hardware or software error is suspected.
A normal product support case is not the primary route for these tasks:
- planning a new VPN topology
- structuring firewall rules cleanly
- setting up NAT or WAF for a new service
- reviewing an HA design
- assessing a routing concept or VLAN architecture
- rebuilding an existing configuration according to best practices
In such cases, Avanet Support is the better contact. The firewall can then be checked, planned or configured as required under Avanet support conditions. Sophos Support remains the right route for specific product faults and general assistance within its documented support scope.
Classify severity and priority correctly
The support plan determines entitlement and response targets; the terms of the affected contract at the time the case is opened are decisive. The levels below therefore deliberately have no fixed times attached. A response target is not a guaranteed resolution time.
| Severity | Typical impact |
|---|---|
| Critical | A mission-critical production service is completely unavailable with no acceptable workaround |
| High | Significant loss of service; operations continue only in a restricted way or through an alternative route |
| Medium | No or only minor loss of service; operations are not materially blocked |
| Low | Operational question or requested product or documentation change |
Choose severity from the actual current impact, not the desired handling speed. For a business-critical case, state the affected sites and users, lack of a workaround, start time and time zone, redundancy status and checks already performed. If the impact changes, update the same case with the new facts instead of opening a duplicate.
Requirements
For a technical support ticket, the following are usually needed:
- SophosID for the Support Portal
- valid license or active support entitlement
- affected serial number or account assignment
- for partner cases: customer assignment and relevant license or serial number
- product and model, for example XGS Appliance or virtual firewall
- firmware version and build
- short error description with impact
- time window of the problem with time zone
- available logs, screenshots or error messages
Sophos checks the license and serial number assignment in support cases. Without a matching license or serial number, a case can go to Customer Care for validation. This delays technical processing. If a partner opens the case for a customer, the customer assignment and affected license or serial number must also be stated clearly. If Avanet is to manage support cases on behalf of a customer, the customer must allow Avanet the corresponding partner access.
The firewall serial number can be found directly in the SFOS dashboard. The process is described in Find the Sophos Firewall serial number.
If the request concerns a hardware defect, the article What should I do if my Sophos hardware has a technical defect? should also be checked.
Classify support channels
Sophos offers several ways to contact support. Not every channel is equally suitable for the same purpose.
Typical support channels:
- Help menu in Sophos Central: direct form-based route for a Central support case; Remote Assistance can optionally be granted during submission.
- Support Assistant in the Sophos Support Portal: primary entry point for signed-in customers, self-service, license questions and guided case creation.
- Cases in the Support Portal: manage existing cases, history, attachments, status and escalation.
- Phone: open Critical and High cases and resolve urgent or portal access problems.
- Sophos Community: non-confidential questions, known symptoms, exchange with other admins.
- Sophos TechVids and Docs: how-to topics, configuration and known procedures.
Sophos is also testing a Support Assistant inside Sophos Central as an Early Access Program. It appears for participating tenants through the sparkle icon in the top Central bar. This EAP Assistant is not synchronized with the Assistant at support.sophos.com; earlier portal chats therefore do not appear in its chat list.
The Central Assistant searches Sophos documentation and KB articles, can display existing cases with Show me my support cases, and can begin a new case with Create a new support case. Explicitly asking for a human Support Agent escalates the chat and creates a tracking ticket. Earlier Central chats can be continued after sign-out or an inactivity timeout. A traceable support case still requires the confirmed case number, not merely a started AI chat.
When opening a normal technical firewall issue in the Support Portal, the workflow starts with Support Assistant. Initiate Critical and High cases by phone rather than by web or email. For a Critical case, signed-in users additionally create the web case, record its number, and then call; users without a Support Portal account use the For Critical Cases phone route directly. This web-case-number-first sequence does not apply to High cases. Do not rely on an Assistant chat alone. Give the product, serial number, impact, workaround status and existing case number, if available.
Phone numbers can change. In the support area, select your region and country, check any charge notice and have the existing case number ready. If portal sign-in is unavailable, use the For Critical Cases phone route offered there and also report the access problem.
Prepare account and partner access
A SophosID is required for the Support Portal. The account should match the company, license or Sophos Central tenant so that the affected products are visible. If the firewall is managed through a partner, it should be clarified before the actual support case whether the partner is allowed to manage cases.
If Avanet is to accompany a case on behalf of a customer or communicate with Sophos, access to the customer assignment must be allowed in the Sophos Support Portal.
In practice this means:
- Check SophosID and have the affected license or serial number ready.
- If Avanet is to assist, find My Partners on the portal home page, choose Grant data access for the intended partner, review the terms and select Confirm.
- The partner can then see all assets in the account. Grant access only to the intended partner and review it again after the case.
- If My Partners is missing, Customer Care may first need to change the profile to Super Customer. Monthly-license customers working with an MSP cannot grant this access themselves; the MSP must open the case in its own name.
- Prepare firewall Support Access only when Sophos needs remote access for the specific case.
Prepare before opening the ticket
A Support Case should be written so that support can classify the problem without guessing.
Technical key data
For Sophos Firewall, these details should be available:
- serial number
- model or platform
- firmware version and build
- license status or support plan, if relevant
- HA status, if the firewall is part of a cluster
- affected function, for example IPsec, SSL VPN, WAF, RED, Web Protection or Reporting
- exact time of the error with time zone
- affected users, networks, sites or services
- last changes before the problem
For HA clusters, both nodes should be documented clearly. For classifying roles, serial numbers and HA operation, see Sophos Firewall HA cluster variants and operation.
Reproduction and impact
The description should not only say that something does not work. A short, verifiable description is better:
- What was expected?
- What happens instead?
- Since when has the problem occurred?
- Is the problem permanent or sporadic?
- How can it be reproduced?
- Which users or services are affected?
- Is there a workaround?
- How critical is the impact on operations?
If a ticket consists only of a screenshot and one sentence, support almost inevitably has to ask follow-up questions. That costs time, especially for VPN, routing or HA problems.
Logs and attachments
For firewall problems, logs are often more important than long assumptions. If the problem is reproducible, the error time window should be recorded as precisely as possible and the matching logs should then be saved.
Depending on the problem, the following are helpful:
- screenshot of the error message
- Log Viewer screenshot with filter
- relevant service logs
- Packet Capture or
tcpdumpif packet flow is unclear - firmware or license screenshot
- short network diagram or affected IP addresses if routing is involved
- description of the rules, NAT objects or VPN parameters already checked
For complete log archives, Save Sophos Firewall logs for support and analysis is the matching procedure. Which log file belongs to which module is summarized in Assign Sophos Firewall service logs correctly.
Not every attachment answers the same question:
- Which rule or module made the decision? Log Viewer export, Rule ID, NAT ID, affected time period.
- Which service reports errors? relevant service logs or complete
/logarchive. - Does traffic arrive and continue? Packet Capture in WebAdmin.
- Does support need a PCAP file? narrow tcpdump capture, separate from the log archive.
- Did a change trigger the problem? audit trail, change time, affected objects.
A broad log archive without an error time is often less helpful than a smaller data package with an exact time, clear reproduction and a matching capture. For packet-flow problems, the PCAP file should be handled separately from the log archive so it remains clear in the ticket which file contains service logs and which file contains network packets.
⚠️ Logs, screenshots and Packet Captures can contain internal IP addresses, public IPs, user names, host names, certificate details or other confidential information. Before uploading, it should be clear who receives the data and whether it must be sanitized first.
Consolidated Troubleshooting Report in SFOS 22
For device or system problems, Sophos may request a Consolidated Troubleshooting Report (CTR). In SFOS 22, go to Diagnostics > Tools > Consolidated troubleshooting report, select System snapshot and All log files, enter the specific reason for generating the report, and click Generate. When it is ready, click Download. The encrypted archive is then added to the existing support case.
Such a report is especially useful for:
- service crashes
- unclear system states
- recurring errors after updates
- problems Sophos cannot assess from a screenshot alone
- support cases where several modules may be affected
The report does not replace a good error description. Time, time zone, affected function and reproduction steps must still be included in the ticket. In an HA cluster, logs and reports are not synchronized between the primary and auxiliary devices. If either node may be involved, collect the CTR separately from each node.
Support Access and access ID
For firewall cases, Sophos may ask for enabled Support Access and its access ID. In SFOS 22, the feature is under Diagnostics > Support access. The firewall connects to *.apu.sophos.com over TCP 22, so an upstream router must allow this outbound connection. The access ID lets Sophos reach WebAdmin and the shell; do not share administrator credentials.
Enable Support Access only for the specific case and required duration: turn on Support access, select the duration, click Apply, and securely give the displayed access ID to Sophos. Access can be disabled at any time and should be turned off after the analysis. For the practical process, see Release Sophos Firewall Support Access for Avanet.
The ticket should state:
- whether Support Access is already active
- access ID, if available
- how long access has been enabled for
- whether MFA or ACL rules affect access
- whether there is a maintenance window for tests
For a Central case, use Remote Assistance for the tenant instead. The path is Profile > Support settings. Access is off by default and can be enabled for 3, 7, 14, 30, or 60 days. When Remote Assistance is enabled directly while creating a Central support case, Sophos disables it automatically after 120 hours.
Grant access only after the case number, purpose, responsible administrator, and duration are defined. After analysis, disable it early under Support settings and review activity in the Audit Log. Remote Assistance for a Central tenant is not the same as a Remote Assistance ID for a firewall, switch, or NDR appliance.
Partner Assistance and Enterprise Admin Access are other access paths with different effects. See Secure Sophos Central Partner and Remote Assistance.
Open a support case directly from Sophos Central
This route is useful when you are already working in the affected Central tenant. It is separate from the tenant-dependent Support Assistant EAP and from the Assistant in the Support Portal.
- Open the Help icon in the upper-right corner.
- In the Sophos Help menu, select the arrow beside Support center.
- Click Create a support case.
- Complete the form as precisely as possible. You can optionally allow Sophos to access the current Central session directly.
- Click Send, record the displayed case number, and confirm with OK.
If you select the optional access setting before submission, Sophos enables Remote Assistance when you click Send. It is disabled automatically after 120 hours. To end access earlier, open the account name in the upper-right corner and then Support Settings.
💡 Successful submission and the case number confirm case creation, not a fixed response or resolution deadline. Priority and the next contact route depend on the contract and actual impact. Initiate Critical and High cases by phone; for a Critical case, signed-in users also create the web case, record its number, and then call.
Open a ticket with Sophos Support Assistant
The Sophos Support Portal is available at:
➜ Open the Sophos Support Portal
Sophos launched Assistant chat on June 3, 2026; it is available 24x7. Its deeper portal integration in mid-July made it the primary entry point for signed-in customers. After signing in with SophosID, Support Assistant is available in the large input field on the home page and through the black Assistant button at the bottom right. The Cases menu remains available for existing cases, but it is no longer the normal starting point for creating a new one.

Start the case in Support Assistant
- Sign in to the Support Portal.
- Open the large input field or the Assistant button.
- Clearly state the product, issue and goal. For a product fault, the conversation can start with:
I need to open a technical support case for Sophos Firewall. - Add the symptoms, business impact and checks already performed. A subject such as
IPsec VPN fails after upgrade to SFOS 22.0 on XGS 2100is more useful thanVPN problem. Replace the model and version with values from your environment. - Review suggested documentation and troubleshooting steps before acting. Unsuitable or risky changes must not be made solely because an AI response suggested them.
- If the issue remains unresolved, state clearly that a human Support Engineer and a Technical Support Case are required.
- Answer the diagnostic questions. The Assistant collects the required information; before submission, verify the account, contact, product, license or serial number, impact and description wherever those fields are shown.
- Review and submit the summary. The case number shown afterward is the success criterion.
- Add logs, screenshots, a CTR or PCAP files afterward under Cases > case number > Upload a File.
The exact dialog is dynamic. Sophos may first offer guidance, a license check or additional questions before the case path appears. That alone is not an error. What matters is describing the issue and impact clearly and continuing until a case number is issued. Preferred support team selection is no longer available; when a supported language is detected, the Assistant may offer transfer to the appropriate regional team.

How to recognize successful completion
A helpful AI response or a displayed knowledge article is not yet a Support Case. The process is complete only when a case number is shown or confirmed by email. The case can then be opened, updated and followed under Cases. Non-AI areas such as Cases, Accounts, Followed Cases and regular knowledge search remain available.
Critical and High cases require telephone contact. For a Critical case, signed-in users also create the case, record its number, and then call. Support Assistant does not replace this urgent human contact.
Resolve common portal problems safely
- Sign-in loop, blank page or missing Assistant: verify the correct SophosID and tenant/account context, allow required cookies and scripts, then reopen the workflow in a current browser or private window. If an outage is possible, save a secret-free draft locally; continue Critical or High cases by phone.
- Product, Cases or case creation is missing: check account and asset assignment, license/support entitlement and, for partners, customer assignment. Do not select another customer’s serial number; have a missing assignment corrected through the account or Customer Care process.
- The Assistant only returns articles: clarify the issue and business impact and explicitly request a Technical Support Case with human support. There is no ticket until a case number exists.
- Upload code, CAPTCHA or SendSafely notice is missing: for the initial verification, check the email address associated with the signed-in Support Portal account and complete the CAPTCHA. Only after Thank you confirms success, record the displayed Submission ID and refresh the case page. The refreshed SendSafely notice is visible only when the signed-in email matches the Case Contact. Do not send files unencrypted as a workaround; on failure, record the time and a sanitized screenshot in the existing case.
- No confirmation after submission: first search Cases and email, including spam, for the case number. Do not resubmit blindly. If the case remains missing, contact support with the time, account and a sanitized screenshot; escalate by phone when the impact is urgent.
What belongs in the description
A good description is short enough to read and specific enough to work with.
Practical template:
Product:
Serial number:
License number:
Model:
Firmware version:
Support plan:
Impact:
Start time and time zone:
Affected users/sites/services:
Recent changes:
Expected behavior:
Actual behavior:
Steps to reproduce:
Checks already performed:
Support access ID:
Attachments:
An adaptable completed example could start like this:
Product: Sophos Firewall
Serial number: [own serial number]
Model: XGS 2100 [replace]
Firmware version: SFOS 22.0 [replace with exact version and build]
Impact: Site-to-site VPN to production is down; 80 users cannot access ERP; no workaround
Start time and time zone: 2026-09-05 08:40 CEST [replace]
Recent changes: Firmware upgrade completed at 07:55 CEST
Expected behavior: IPsec tunnel establishes and production subnet is reachable
Actual behavior: Tunnel remains down; peer is reachable; authentication fails
Steps to reproduce: Disable and re-enable the affected connection once
Checks already performed: Peer reachability, matching proposals, Log Viewer at 08:43 CEST
Support access ID: Not enabled; can be enabled for an agreed window
Attachments: Filtered Log Viewer export and topology diagram; CTR available on request
Replace the bracketed values. The user count, ERP service and symptom are examples only; severity and wording must reflect the real impact. Never include passwords, pre-shared keys, private keys or session cookies in the description or attachments.
Upload files after creating the case
Portal uploads always belong to an existing case. Sign in to the Support Portal, open Cases, select the case number, and click Upload a File. On the first upload, SendSafely may verify the email address associated with that Support Portal account using a code and CAPTCHA. Multiple files, files without an allowed extension, files over 100 GB and executable files must first be placed in a ZIP. On public or shared devices, leave remember me for 30 days cleared.
Only the Thank you message confirms a successful upload. Record the displayed Submission ID for follow-up. Then refresh the case page; the SendSafely notification is visible only when the email address matches the Case Contact. To view or download an uploaded file later, the signed-in user must be both its uploader and the Case Contact.
For firewall rule, NAT or VPN problems, the following should also be stated:
- source and destination networks
- affected service or port
- expected firewall rule
- NAT rule, if involved
- VPN tunnel or remote access profile
- Log Viewer result
- Packet Capture or tcpdump PCAP if packet flow is relevant
- Support Access ID if Sophos needs remote access
For rule analysis, Test firewall rule with Log Viewer, Policy Test and Packet Capture can help before the Support Case is opened.
RMA and hardware defect
For hardware defects, Sophos needs additional information for RMA processing. This includes not only the error description and serial number, but also model, revision, firmware, license, HA status and shipping information.
Prepare:
- defective product and model
- serial number of the affected device
- firmware version
- license number or license assignment
- error description and points already checked
Dead on arrivalif the device is affected immediately after delivery- HA cluster: yes or no
- shipping address and contact person
- phone number and email address
- special shipping instructions
For firewalls, it should also be checked whether a current backup exists and how the replacement firewall will be restored. For backup and restore, see Backup and restore on Sophos Firewall.
For RMA cases, provide the requested details through the current Sophos Support Portal and follow the instructions in the ticket. Add any further device, license or shipping information requested for that specific case.
Following up and escalating
After opening the case, a confirmation with the case number should arrive by email. This number belongs in every later communication. Under Cases, the case can be opened, updated with additional information and followed.
If a critical case does not move forward quickly enough, a second ticket should not be opened. Duplicate tickets create more coordination work and can slow down processing.
Better:
- have the existing ticket number ready
- describe impact and urgency specifically
- provide missing logs or answers
- for critical issues, follow up by phone with the case number
- select Request Escalation in the existing case, choose the region, enter the reason and business impact, and click Escalate
- document internally who gave which feedback
An escalation should be justified. Useful reasons include:
- target response time was exceeded.
- production outage is still ongoing.
- no response despite additional information.
- wrong assignment or unsuitable product category.
- case blocks a planned recovery or maintenance process.
The escalation should always describe the current business impact. A sentence such as We need an update is weaker than a concrete statement such as The main site-to-site VPN between headquarters and production is still down, 80 users cannot access ERP, no workaround is available. Alternatively, Sophos accepts email at supportescalations@sophos.com with the case number, an explicit escalation request, reason and business impact. For time-sensitive issues, Sophos also recommends calling.
For serious security or outage cases, it should also be checked whether other support or incident response processes apply. A normal technical ticket is not automatically a complete incident response process.
Checklist
- SophosID works.
- License and support entitlement are clarified.
- Serial number, model and firmware version are documented.
- Error time with time zone is known.
- Impact on users, services or site is described.
- Last changes were noted.
- Reproduction or error pattern is traceable.
- Relevant logs and screenshots are prepared.
- Packet Capture or tcpdump PCAP is prepared only for packet-flow problems.
- Confidential data in attachments was checked.
- For RMA: shipping information and HA status are prepared.
- Case creation through the selected route was completed through confirmation of the case number.
- Ticket number is documented internally.