Open a Sophos support ticket with Support Assistant
Since July 18, 2026, a new support request for signed-in customers no longer starts with the former New Technical Support Case form. Sophos Support Assistant is now the primary entry point. It first suggests relevant help and guides the customer through case creation if the issue remains unresolved.
💡 Important: Support Assistant is an AI-assisted guide, not a Support Engineer and not yet an open ticket. Its suggestions must be reviewed before making a change. A case exists only after the portal confirms a case number.
Good preparation therefore matters more than the new dialog. For Sophos Firewall, the evidence package should include the serial number, model, firmware version, license status, time of the error, affected function, logs, screenshots and checks already performed. This guide combines that preparation with the new Assistant workflow announced by Sophos. For classifying the different Sophos access points, see also Sophos portals: SophosID, Central, support and firewall access.
When a Sophos support ticket makes sense
A Sophos support ticket makes sense when a problem can no longer be clarified locally through configuration, logs or known operational processes alone.
Typical cases:
- hardware defect, RMA or suspected defective appliance
- license or account problem with a specific serial number
- firmware, hotfix or upgrade problem
- recurring service crash or unclear system state
- VPN, WAF, HA, RED or routing problem after initial local narrowing down
- error that looks like a product issue after logs and reproduction
- support request where Sophos needs access to internal analysis data
Before opening a ticket, the obvious local checks should be performed. For Sophos Firewall this does not mean everything must already be solved. But the more precisely the initial situation, time window and affected function are described, the fewer follow-up questions are needed.
What Sophos Support provides and what it does not
Sophos Support helps with technical product problems and can answer general configuration questions. It does not replace a complete implementation, migration or new architecture design. A ticket is especially appropriate when a function does not work correctly despite a traceable configuration, or when a specific product, license, hardware or software error is suspected.
A normal product support case is not the primary route for these tasks:
- planning a new VPN topology
- structuring firewall rules cleanly
- setting up NAT or WAF for a new service
- reviewing an HA design
- assessing a routing concept or VLAN architecture
- rebuilding an existing configuration according to best practices
In such cases, Avanet Support is the better contact. The firewall can then be checked, planned or configured as required under Avanet support conditions. Sophos Support remains the right route for specific product faults and general assistance within its documented support scope.
Severity and target response times
The support plan determines entitlement and response targets, but it does not replace a clear problem description. These targets are response times, not guaranteed resolution times. A complex VPN, HA or routing issue can still take longer despite a quick first response if logs, reproduction or remote access are missing.
The current Sophos Support Services Guide lists these target response times:
| Severity | Typical impact | Target response time |
|---|---|---|
| Critical | A mission-critical production service is completely unavailable with no acceptable workaround | 4 hours |
| High | Significant loss of service; operations continue only in a restricted way or through an alternative route | 8 hours |
| Medium | No or only minor loss of service; operations are not materially blocked | 24 hours |
| Low | Operational question or requested product or documentation change | 24 hours |
Severity should be selected honestly according to the actual impact. An overly high classification without matching impact rarely helps, because Sophos asks about impact, reproducibility and affected services. For a business-critical case, the description should clearly show the affected sites, number of users, lack of a workaround, timing, redundancy status and checks already performed. The current definitions and targets are published under Sophos service level targets.
Requirements
For a technical support ticket, the following are usually needed:
- SophosID for the Support Portal
- valid license or active support entitlement
- affected serial number or account assignment
- for partner cases: customer assignment and relevant license or serial number
- product and model, for example Sophos Firewall XGS or virtual firewall
- firmware version and build
- short error description with impact
- time window of the problem with time zone
- available logs, screenshots or error messages
Sophos checks the license and serial number assignment in support cases. Without a matching license or serial number, a case can go to Customer Care for validation. This delays technical processing. If a partner opens the case for a customer, the customer assignment and affected license or serial number must also be stated clearly. If Avanet is to manage support cases on behalf of a customer, the customer must allow Avanet the corresponding partner access.
The firewall serial number can be found directly in the SFOS dashboard. The process is described in Find the Sophos Firewall serial number.
If the request concerns a hardware defect, the article What should I do if my Sophos hardware has a technical defect? should also be checked.
Classify support channels
Sophos offers several ways to contact support. Not every channel is equally suitable for the same purpose.
- Support Assistant in the Sophos Support Portal: primary entry point for signed-in customers, self-service, license questions and guided case creation.
- Cases in the Support Portal: manage existing cases, history, attachments, status and escalation.
- Phone: report critical issues after case creation with the case number, or resolve access problems.
- Sophos Community: non-confidential questions, known symptoms, exchange with other admins.
- Sophos TechVids and Docs: how-to topics, configuration and known procedures.
For technical firewall issues, the workflow now starts with Support Assistant. Once the case has been created, its number, history and attachments remain traceable in the portal. For critical issues, first create the case, note the number and then call Sophos. Without working portal access, the For Critical Cases panel on the home page can show the direct phone route.
The current contact options and phone numbers are on the official Sophos Support contact page. The general support overview remains available under Sophos Support.
Prepare account and partner access
A SophosID is required for the Support Portal. The account should match the company, license or Sophos Central tenant so that the affected products are visible. If the firewall is managed through a partner, it should be clarified before the actual support case whether the partner is allowed to manage cases.
If Avanet is to accompany a case on behalf of a customer or communicate with Sophos, access to the customer assignment must be allowed in the Sophos Support Portal. Sophos describes this step under Allow a Sophos Partner to manage your account.
In practice this means:
- Check SophosID.
- Have the affected license or serial number ready.
- If Avanet is to assist, prepare partner access in the Sophos portal.
- If Sophos needs remote access, prepare Support Access on the firewall.
Prepare before opening the ticket
A Support Case should be written so that support can classify the problem without guessing.
Technical key data
For Sophos Firewall, these details should be available:
- serial number
- model or platform
- firmware version and build
- license status or support plan, if relevant
- HA status, if the firewall is part of a cluster
- affected function, for example IPsec, SSL VPN, WAF, RED, Web Protection or Reporting
- exact time of the error with time zone
- affected users, networks, sites or services
- last changes before the problem
For HA clusters, both nodes should be documented clearly. For classifying roles, serial numbers and HA operation, see Sophos Firewall HA cluster variants and operation.
Reproduction and impact
The description should not only say that something does not work. A short, verifiable description is better:
- What was expected?
- What happens instead?
- Since when has the problem occurred?
- Is the problem permanent or sporadic?
- How can it be reproduced?
- Which users or services are affected?
- Is there a workaround?
- How critical is the impact on operations?
If a ticket consists only of a screenshot and one sentence, support almost inevitably has to ask follow-up questions. That costs time, especially for VPN, routing or HA problems.
Logs and attachments
For firewall problems, logs are often more important than long assumptions. If the problem is reproducible, the error time window should be recorded as precisely as possible and the matching logs should then be saved.
Depending on the problem, the following are helpful:
- screenshot of the error message
- Log Viewer screenshot with filter
- relevant service logs
- Packet Capture or
tcpdumpif packet flow is unclear - firmware or license screenshot
- short network diagram or affected IP addresses if routing is involved
- description of the rules, NAT objects or VPN parameters already checked
For complete log archives, Save Sophos Firewall logs for support and analysis is the matching procedure. Which log file belongs to which module is summarized in Assign Sophos Firewall service logs correctly.
Not every attachment answers the same question:
- Which rule or module made the decision? Log Viewer export, Rule ID, NAT ID, affected time period.
- Which service reports errors? relevant service logs or complete
/logarchive. - Does traffic arrive and continue? Packet Capture in WebAdmin.
- Does support need a PCAP file? narrow tcpdump capture, separate from the log archive.
- Did a change trigger the problem? audit trail, change time, affected objects.
A broad log archive without an error time is often less helpful than a smaller data package with an exact time, clear reproduction and a matching capture. For packet-flow problems, the PCAP file should be handled separately from the log archive so it remains clear in the ticket which file contains service logs and which file contains network packets.
⚠️ Logs, screenshots and Packet Captures can contain internal IP addresses, public IPs, user names, host names, certificate details or other confidential information. Before uploading, it should be clear who receives the data and whether it must be sanitized first.
Consolidated Troubleshooting Report
For device or system problems, Sophos may request a Consolidated Troubleshooting Report. In the firewall this can be found under Diagnostics > Tools. The report collects diagnostic information and relevant log data in a compressed archive.
Such a report is especially useful for:
- service crashes
- unclear system states
- recurring errors after updates
- problems Sophos cannot assess from a screenshot alone
- support cases where several modules may be affected
The report does not replace a good error description. Time, time zone, affected function and reproduction steps must still be included in the ticket.
Support Access and Remote Assistance ID
For firewall cases, Sophos may ask for a Remote Assistance ID or for enabled Support Access. This allows Sophos to access the firewall for a limited time if this is necessary for analysis.
Support Access should only be enabled when it is needed for the specific case. After the support case is closed, access should be disabled again or at least checked. For the practical process, see Release Sophos Firewall Support Access for Avanet. The official Sophos documentation describes the general process under Support access.
The ticket should state:
- whether Support Access is already active
- Remote Assistance ID, if available
- how long access has been enabled for
- whether MFA or ACL rules affect access
- whether there is a maintenance window for tests
Open a ticket with Sophos Support Assistant
The Sophos Support Portal is available at:
After signing in with SophosID, Support Assistant is available in the large input field on the home page and through the black Assistant button at the bottom right. The Cases menu remains available for existing cases, but it is no longer the normal starting point for creating a new one.

Start the case in Support Assistant
- Sign in to the Support Portal.
- Open the large input field or the Assistant button.
- Clearly state the product, issue and goal. For a product fault, the conversation can start with:
I need to open a technical support case for Sophos Firewall. - Add the symptoms, business impact and checks already performed. A subject such as
IPsec VPN fails after SFOS 22.0 MR1 upgrade on XGS 2100is more useful thanVPN problem. - Review suggested documentation and troubleshooting steps before acting. Unsuitable or risky changes must not be made solely because an AI response suggested them.
- If the issue remains unresolved, state clearly that a human Support Engineer and a Technical Support Case are required.
- Answer the guided questions and assign the correct account, affected license or serial number, and appropriate Severity.
- Add logs, screenshots, a CTR or PCAP files when the flow offers this or when the created case is visible under Cases.
- Complete case creation and record the confirmed case number internally.
The exact dialog is dynamic. Sophos may first offer guidance, a license check or additional questions before the case path appears. That alone is not an error. What matters is describing the actual issue and its impact clearly and, when deeper analysis is required, continuing case creation until a case number is issued.

How to recognize successful completion
A helpful AI response or a displayed knowledge article is not yet a Support Case. The process is complete only when a case number is shown or confirmed by email. The case can then be opened, updated and followed under Cases. Non-AI areas such as Cases, Accounts, Followed Cases and regular knowledge search remain available.
For a critical outage, the order is different: create the case, note the case number and then call Sophos. Without a Support Portal account, follow the regional phone route under For Critical Cases. Support Assistant does not replace this urgent human contact.
What belongs in the description
A good description is short enough to read and specific enough to work with.
Practical template:
Product:
Serial number:
License number:
Model:
Firmware version:
Support plan:
Impact:
Start time and time zone:
Affected users/sites/services:
Recent changes:
Expected behavior:
Actual behavior:
Steps to reproduce:
Checks already performed:
Remote Assistance ID:
Attachments:
For firewall rule, NAT or VPN problems, the following should also be stated:
- source and destination networks
- affected service or port
- expected firewall rule
- NAT rule, if involved
- VPN tunnel or remote access profile
- Log Viewer result
- Packet Capture or tcpdump PCAP if packet flow is relevant
- Support Access ID if Sophos needs remote access
For rule analysis, Test firewall rule with Log Viewer, Policy Test and Packet Capture can help before the Support Case is opened.
RMA and hardware defect
For hardware defects, Sophos needs additional information for RMA processing. This includes not only the error description and serial number, but also model, revision, firmware, license, HA status and shipping information.
Prepare:
- defective product and model
- serial number of the affected device
- firmware version
- license number or license assignment
- error description and points already checked
Dead on arrivalif the device is affected immediately after delivery- HA cluster: yes or no
- shipping address and contact person
- phone number and email address
- special shipping instructions
For firewalls, it should also be checked whether a current backup exists and how the replacement firewall will be restored. For backup and restore, see Backup and restore on Sophos Firewall.
For RMA cases, follow the current Sophos Support Portal and the response in the ticket. Community posts or older process descriptions may seem helpful, but they are not authoritative if Sophos asks for other details in the specific case.
Following up and escalating
After opening the case, a confirmation with the case number should arrive by email. This number belongs in every later communication. Under Cases, the case can be opened, updated with additional information and followed.
If a critical case does not move forward quickly enough, a second ticket should not be opened. Duplicate tickets create more coordination work and can slow down processing.
Better:
- have the existing ticket number ready
- describe impact and urgency specifically
- provide missing logs or answers
- for critical issues, follow up by phone with the case number
- use Request Escalation in the existing case when the impact or progress justifies it
- document internally who gave which feedback
An escalation should be justified. Useful reasons include:
- target response time was exceeded.
- production outage is still ongoing.
- no response despite additional information.
- wrong assignment or unsuitable product category.
- case blocks a planned recovery or maintenance process.
The escalation should always describe the current business impact. A sentence such as We need an update is weaker than a concrete statement such as The main site-to-site VPN between headquarters and production is still down, 80 users cannot access ERP, no workaround is available. The current official workflow is documented under Escalating a support case.
For serious security or outage cases, it should also be checked whether other support or incident response processes apply. A normal technical ticket is not automatically a complete incident response process.
Checklist
- SophosID works.
- License and support entitlement are clarified.
- Serial number, model and firmware version are documented.
- Error time with time zone is known.
- Impact on users, services or site is described.
- Last changes were noted.
- Reproduction or error pattern is traceable.
- Relevant logs and screenshots are prepared.
- Packet Capture or tcpdump PCAP is prepared only for packet-flow problems.
- Confidential data in attachments was checked.
- For RMA: shipping information and HA status are prepared.
- Case creation in Support Assistant was completed through confirmation of the case number.
- Ticket number is documented internally.