Skip to content
Avanet

Check the Sophos Central Firewall Task Queue

If a change from Sophos Central does not reach the firewall, first open:

My Products > Firewall Management > Tasks Queue

There are two views: Task Queue shows group policies, while Firewall Task Queue shows MDR and API operations. A successful task confirms processing in Central, but not necessarily the intended effect on the firewall. A local check must therefore always follow the queue review.

Quick check for a failed task

  1. Open the appropriate tab and expand the task.
  2. Record the affected group or firewall, status, time, entity, and error message.
  3. For group policies, check the firewall’s group membership and synchronization status.
  4. For MDR/API tasks, match the Credential ID, Entity, and Action to the initiating system.
  5. On the firewall, check whether the change is present in full or only in part.
  6. For configuration changes, check the Audit Trail Logs; for traffic issues, use the Log Viewer, Policy Test, and Packet Capture.
  7. Only decide on Retry, Skip, or a support case after identifying the cause.
  8. Validate the technical effect with an appropriate test case.

This process separates two questions: Did Central process the operation, and does the change actually work on the firewall?

Distinguishing Task Queue and Firewall Task Queue

Task Queue for group policies

Sophos Central creates a task when an administrator changes a firewall group policy. It shows Task, Group, Firewalls, Status, Modified by, Entity, Sub-entity, and Time. Status shows the overall progress and how many firewalls successfully received the policy; expanding the task shows the affected firewalls.

The timestamp initially shows when the policy was created or last changed. It is updated during distribution and eventually shows when the last firewall received the policy. Show History displays completed or skipped tasks for firewalls or groups that have since been deleted.

Sophos Central deletes tasks that remain Pending for three weeks. For a support case, record the task number, error message, affected firewalls, and time before this happens.

Firewall Task Queue for MDR and API operations

Firewall Task Queue shows MDR Settings and MDR IOCs initiated through the Firewall Configuration API. The overview groups them under Total Firewall Tasks, Pending, In Progress, Failed, Partial Successful, and Successful.

An expanded task shows the firewall, status, Credential ID under Modified by, entity, action, and time. Possible actions include Add, Update, and Delete. The Credential ID helps identify the system that initiated the operation.

The individual status values are Pending, In Progress, Success, Failed, and Partial Success. Partial Success means that only part of the operation was applied, for example two out of three MDR indicators. Separate the successful and failed items or firewalls, correct the cause, rerun only the affected operation, and compare the result with the local configuration.

Firmware upgrades are scheduled and monitored in Sophos Central under My Products > Firewall Management > Firewalls. They are not part of the two queue views described here.

Using Retry, Skip, and Force sync safely

Retry and Skip apply only to group policies in Task Queue. Sophos Central offers Retry for Failed, Skipped, and Invalid license; Skip for Created, Pending, Invalid license, and Failed.

  • Retry: Use only after resolving the cause, such as an interrupted Central connection, an object conflict, or a license assignment that has since been corrected.
  • Skip: Use only when it is clear which change will not be applied and how the affected firewall will be checked afterward.
  • Wait: Use when the task is still being processed and there is no reliable error message.
  • Support case: Use when the error recurs, affects several production firewalls, or cannot be classified with confidence.

⚠️ Do not skip a failed task just to clear the queue. Skip is an operational decision; the omitted change must still be checked or implemented separately.

If a firewall was added to a group with Skip full sync, its local configuration may differ from the group policy. Check its status under My Products > Firewall Management > Firewalls. If Sync & Management shows Failed to apply a policy, check the corresponding entry in Task Queue. A Force sync applies the complete group configuration and should therefore only be initiated deliberately. For an HA pair, the link is only available on the active firewall.

Verifying the Central policy locally

For firewall and NAT rules, Top and Bottom only control the order within the Central policy. Rules distributed from Central are inserted at the top of the local rule list on the firewall. Local rules can therefore make the effective order more difficult to predict; Sophos recommends creating rules consistently through Central on centrally managed firewalls.

After a successful task, check the following on the firewall:

  • Is the changed rule, policy, list, or object visible?
  • Does the Audit Trail show the expected configuration change?
  • Does test traffic match the expected Firewall Rule ID and, for NAT, the expected NAT Rule ID?
  • For web or TLS changes, do the test client, target domain, and Web and SSL/TLS Inspection logs agree?
  • For VPN or other functional changes, does the specific use case work with the expected user or object assignment?
  • For MDR/API tasks, are the entity or indicators visible locally, and does the result match the Credential ID and expected log event?

For a concise acceptance record, the task status, affected firewall, local test, and log or audit evidence are sufficient. For extensive changes, Sophos Firewall Config Studio can also help compare expected and actual configurations. If the relevant log is unclear, Sophos Firewall Troubleshooting: Services and Logs provides the mapping.

Known version-dependent issues

Group policy remains Pending

NC-181175 describes an issue where a group policy push from Sophos Central remained Pending and was not applied to firewalls. Sophos fixed it in SFOS 22.0 MR2 Build 546. On an earlier 22.0 version with a task that remains Pending, also check the firmware version.

XGS 88/w: Local TLS exclusion list

NC-177522 affects XGS 88/w running SFOS 21.5 MR2 Build 323 or 22.0 GA Build 411. During Central policy synchronization, editing the Local TLS exclusion list could fail with Failed to apply a policy because a URL group could not be updated.

The documented workaround is to skip the failed transaction so that subsequent tasks can continue. The local TLS exclusion list and related policies must then be checked. The current Known Issues List is contradictory about the fix status: Under Fix versions, it lists SFOS 22.0 MR1 Build 490, while the workaround text still announces a fix in the next maintenance release. Therefore, check the current entry and the release notes before assessing the issue.