Skip to content
Avanet

Operating Sophos Firewall Air-Gap Licensing and Pattern Updates

A Sophos Firewall running SFOS 22 can be operated in highly isolated environments without direct internet access. This is not a normal offline mode but a deliberately planned air-gap operation with its own licensing logic, manual synchronization, and a separate update process for patterns.

The most important point: Air Gap is not a way to simply operate a firewall “without the internet” on the side. You need prior approval, a claimed hardware firewall, a clear update process, and regular checks of license and pattern statuses. Otherwise, the firewall may continue to run, but protection functions lose their currency, or subscriptions are deactivated.

For general licensing logic, first see Understanding Sophos Firewall Base License. This article focuses on the special case of Air Gap.

Important: An air-gap license does not technically disconnect the firewall from the internet. If the firewall is connected to the internet while Air Gap is enabled, it synchronizes its licenses online again. In real air-gap environments, this network path must therefore be deliberately prevented or controlled.

When Air Gap is Sensible

Air Gap is only suitable for environments where the firewall is deliberately operated separated from the internet. Typical examples are highly regulated networks, research environments, defense environments, production segments, or other zones where direct cloud or update connections are not allowed.

Before deciding, three questions should be separated:

  • Is the firewall really not allowed to have internet access?: If controlled internet access is possible, normal license and pattern sync is usually easier and safer.
  • Who will take over the manual update process?: Air Gap creates operational effort. License files and patterns must be consciously maintained.
  • Which functions are lost or weakened?: Some functions require online services, reputation, Sophos Fusion (formerly Sophos Central), or external resolution.

Air Gap does not automatically increase security. It reduces a certain connection surface but shifts responsibility to processes: download, verification, transfer, upload, documentation, and monitoring.

Prerequisites

Before installation, these points should be clarified:

  • The firewall must be claimed as an air-gap firewall in Sophos Fusion.
  • Air-gap usage must be approved by the Sophos Account Manager.
  • According to Sophos, Air Gap is intended for hardware firewalls.
  • The environment must not simply be temporarily offline but must be planned as an isolated environment.
  • The isolated network must not contain any MSP Flex licensed firewalls.
  • Admin access to CLI and WebAdmin is required.
  • A secure way to transfer license and pattern files into the isolated environment is needed.

Before implementation, document the serial number, model, Sophos Fusion account, license status, and responsible person. For serial numbers and license basics, see Activate Sophos Firewall License Key and Find Sophos Firewall Serial Number.

Before activation, also check the deployed rules for Web Server Protection (WAF) and Email Protection for dependencies on RBL and IP reputation, and document the loss of protection in the change record. If these checks are essential to the security design, do not activate Air Gap until a revised security design has been approved. A valid licence and up-to-date patterns do not make these online checks available offline.

Overview of the Process

The air-gap process consists of several separate steps. If one of them is missing, the firewall is not properly in air-gap operation.

  • Claim firewall: Sophos Fusion. Firewall is assigned to the correct account
  • Clarify air-gap approval: Sophos Account Manager. Air-gap authorization is present
  • Download air-gap license: Sophos Fusion. License file is available
  • Activate Air Gap on the firewall: CLI Device Console. Manual license synchronization becomes visible
  • Upload license file: Administration > Licensing. License status is updated locally
  • Apply pattern updates: Backup & firmware > Pattern updates. Protection patterns are updated
  • Monitor process and logs: WebAdmin, Alerts, licensing.log. Deactivation or outdated patterns are detected early

The order is important. A license file alone is not enough if Air Gap has not been activated on the firewall. Conversely, the CLI command is useless if there is no valid air-gap license file from the correct account.

Download Air-Gap License

Sign in to Sophos Fusion, then download the license file using this path:

Sophos Fusion > Profile icon > Licensing > Firewall licenses > Download airgap license

The license file should be handled carefully after download and should not be placed in private downloads, messengers, or unclear clipboards. A brief internal record is sensible:

  • Download date
  • Sophos Fusion account
  • Affected firewall or firewall group
  • Serial numbers
  • Responsible person
  • Planned upload time

Sophos specifies that a downloaded air-gap license must be applied within 30 days. If the file is used too late, a new file should be downloaded.

According to Sophos, one air-gap license file can be used for multiple firewalls from the same Sophos Fusion account. Still, document internally which serial numbers were updated with the same file.

Activate Air Gap on the Firewall

To make manual license synchronization visible in WebAdmin, Air Gap must be activated on the firewall via CLI.

Procedure:

  1. Log in to the firewall console or via SSH.
  2. In the Sophos console, select 4 for Device Console.
  3. Execute the command:
system airgap enable

Afterwards, the Manual license synchronization section should be visible under Administration > Licensing.

This step should be documented. In productive environments, it belongs in the same change as the license file upload, so it is clear later when Air Gap was activated and which license file it corresponds to.

Check the state and leave Air Gap in a planned way

After activation and before every license window, the following command shows the current Air Gap state. Record the output with the serial number, SFOS build, and license file:

system airgap show

system airgap disable isn’t a troubleshooting step for a failed license upload. Use it only for a planned exit from Air Gap operation. First prepare the permitted internet path, DNS and time source, normal online license synchronization, pattern updates, and the state of all subscriptions.

system airgap disable
system airgap show

Disabling the function doesn’t restore a previously blocked network path and doesn’t prove successful online synchronization. After the change, verify Administration > Licensing, pattern status, licensing.log, and the protection modules in use. If the firewall remains physically isolated, don’t disable Air Gap merely to change an indicator.

Upload Air-Gap License

After activation, the license file is applied in WebAdmin.

Procedure:

  1. Log in to the WebAdmin Console.
  2. Open Administration > Licensing.
  3. In the Manual license synchronization section, select Choose file.
  4. Select the air-gap license file.
  5. Apply with Update license.
  6. Check license status and expiration dates.

After the upload, check whether the expected subscriptions are active. A successful license synchronization does not replace a functionality check. If Web Protection, IPS, or other locally usable modules are used, policy, pattern status, logging, and tests must be correct separately. Zero-Day Protection isn’t part of this acceptance check because it isn’t supported in an air-gap deployment.

HA Cluster: Consider Initial Primary

In Active-Passive HA, air-gap licensing is particularly delicate. The license file must only be applied to the Initial Primary. This device must also be the current Primary during the upload.

If the license is uploaded to the wrong node, license differences or unexpected HA behavior can occur. Therefore, it is sensible for operation:

  1. Check System services > High availability before the upload.
  2. Document Initial Primary and current role.
  3. Set Initial Primary as Preferred primary device.
  4. Apply the license file on the correct Primary.
  5. Then check HA status and license status.

For HA basics and role logic, see Set Up Sophos Firewall High Availability. In Air Gap, this preparation is not optional because the wrong node can later cause incomprehensible license or failover symptoms.

Manually Apply Pattern Updates

Without automatic online updates, patterns must be consciously maintained. This affects signatures, engines, clients, and other update components. In air-gap environments, a pattern file is downloaded and uploaded in WebAdmin.

For SFOS 22.0 and later, Sophos provides one .tar file containing the patterns for all modules:

Open the SFOS 22 pattern download guidance

For older SFOS versions, select a pattern file that explicitly matches the installed version. Air-gap pattern packages are version-specific; an incorrect package can be rejected or update the wrong component set.

Procedure:

  1. Download the pattern file on a designated system and leave it unchanged.
  2. Transfer the file into the isolated environment via the approved transfer method.
  3. Log in to the firewall.
  4. Open Backup & firmware > Pattern updates > Manual pattern update.
  5. Select Choose File and open the downloaded .tar file.
  6. Select Upload, then confirm with OK.
  7. In the pattern list, check the version, last successful update, and status of every required component.

In HA environments, patterns are applied on the Primary and then synchronized to the Auxiliary. Therefore, the HA status should be checked first here as well.

Pattern updates do not include hotfixes. If a hotfix is needed in an air-gap environment, this must be clarified separately through Sophos Support or the planned support process.

Use Configure and Check Sophos Firewall Pattern Updates to select and download the correct manual package, interpret the status values, and distinguish pattern packages from APX, RED, and SFOS firmware. The automation only transports patterns and does not renew the air-gap license file.

Automate Pattern Transfer

This automation requires a server or computer with Apache, or an equivalent file-exchange service, that the firewalls can reach from the isolated network. Do not expose that server unnecessarily. Restrict clients and write access, use the approved transfer and malware-review process, and record hashes or file sizes before and after crossing the air-gap boundary. The commands below use HTTP and curl --insecure. With an HTTP URL, --insecure provides no benefit; with HTTPS, it disables certificate verification. This provides neither authenticity nor transport confidentiality: scope it to the isolated transfer path, verify files independently, and use certificate-validated HTTPS instead if the supported, approved design permits it.

On the file-exchange server, obtain the current official metadata object and pattern package. Because the Salesforce script attachment currently returns HTML to an unauthenticated request, obtain the current official airgap_pattern_update.sh through Sophos Support, referencing KBA-000006644; reject an HTML or login response rather than saving it as a script. Place the three verified files airgap_pattern_update.sh, sfos_pattern_updates_script.info, and sfos_pattern_updates_script.tar below /var/www/html/. The update payload and metadata must be served under these target names:

/var/www/html/airgap_pattern_update.sh
/var/www/html/sfos_patterns_update.tar
/var/www/html/sfos_patterns_update.info

Operational warning: the available package names are inconsistent: sfos_patterns_updates_script.info and sfos_pattern_updates_script.info both occur, and example mv commands may name the .info file as the source for sfos_patterns_update.tar. Those commands would not create the required tar payload correctly. Do not run or silently correct them. Inspect the downloaded files, confirm their types and contents, then map the .tar source to sfos_patterns_update.tar and the .info source to sfos_patterns_update.info. Stop and ask Sophos Support if the names, types, or contents do not match.

Edit the server copy of airgap_pattern_update.sh so PATTERN_URL points to http://<server ip address>/sfos_patterns_update.tar and INFO_URL points to http://<server ip address>/sfos_patterns_update.info. Keep the placeholders until the approved server address is known, preserve a reviewed copy, and test that both URLs return the intended files rather than an HTML error or login page.

On each firewall, open Device Management > Advanced Shell and run:

cd /content
curl --insecure http://<server ip address>/airgap_pattern_update.sh -o /content/airgap_pattern_update.sh
sh /content/airgap_pattern_update.sh > /log/airgap.log 2>&1 &
ps -w | grep airgap
tail -f /log/airgap_pattern_update.log

Replace only <server ip address>. The script’s default WAIT value polls every 24 hours; change WAIT only after documenting the resulting load and update interval. Run this setup once per firewall. In HA, unlike the manual pattern upload described above, install and start the automation on both Primary and Secondary nodes.

Operational warning: treat these commands as unvalidated for your firewall model and SFOS build. Run them only through an approved change, monitor the result, and be prepared to stop the process. Confirm the expected PID with ps, inspect /log/airgap.log for launch errors and /log/airgap_pattern_update.log for update activity, then verify component versions, Last successful update, and Success under Backup & firmware > Pattern updates. In HA, verify both node processes and HA health.

Before changing the server files, URLs, or WAIT, preserve the working script, metadata, payload details, and log baseline. If validation fails, stop the affected background process through the approved change procedure, restore the reviewed server and script copies, and use the manual upload workflow while investigating. Do not treat an old pattern archive as a product rollback, do not launch duplicate polling processes, and do not infer success from curl alone.

Check Pattern Status

An air-gap operation is only as good as the routine behind it. Sophos typically provides new patterns weekly. If the firewall is not updated for a long time, the value of IPS, Antivirus, Application Signatures, and other protection functions decreases.

For air-gap installations, Sophos Firewall updates IPS and application signatures together, even if IPS protection is not actively turned on. This does not replace checking that the relevant subscription is active and that the protection function is used in policies.

An accepted file isn’t a complete success criterion. With Success, Current version, Available version, and Last successful update should be plausible for the components you need. Don’t use an old archive as a rollback. If SFOS rejects the file, download the SFOS 22 package again, check the build and file size or transfer, and upload it unchanged.

Practical control:

  • Current pattern versions: Backup & firmware > Pattern updates
  • Last successful update: Backup & firmware > Pattern updates
  • Update status: Ready to install, Downloading, Success, or Failed
  • License status: Administration > Licensing
  • License and deactivation notices: licensing.log

For a general operational check, additionally see Proper Use of Sophos Firewall Health Check. There, Air Gap should not be understood as an exception to update hygiene but as a special process for the same duty: keeping protection functions current.

License Expiration and Incommunicado Window

With normal license synchronization, 90 days without a successful sync are critical. For air-gap licenses, a longer window of 180 days applies. Download and upload a new license file before expiration, otherwise security subscriptions are deactivated. Enhanced Support entitlement after the air-gap license expires cannot be guaranteed universally: check the actual support subscription and RMA entitlement separately, and resolve uncertainty with authorized account administration or Sophos Support. Uploading a license does not renew a paid support contract. The 180-day cycle is not the 90-day renewal deadline in the documented Active-Passive support case; see Base License and support expiration for that distinction.

For operation, this means:

  • After 160 days, SFOS shows a warning with 20 days remaining; prepare the new air-gap license file no later than this point.
  • At the latest with warning messages, the upload must be planned.
  • After 180 days without a new air-gap license, deactivation of protection subscriptions threatens.
  • Traffic can continue, but without the affected protection functions.
  • The status should be monitored via WebAdmin, Alerts, and licensing.log.

A successful license synchronization resets this incommunicado window. After the upload, don’t only check that the warning has disappeared: verify that the expected subscriptions and expiration dates are correct under Administration > Licensing.

licensing.log is particularly important for license problems. An overview of relevant firewall logs is available in Sophos Firewall Troubleshooting: Services and Logs.

What is Restricted in Air-Gap Environments

Air Gap means that online services do not function as they would in a normally connected firewall. Some functions are not supported at all, while others lose part of their effectiveness.

Typical limitations:

  • Sophos Fusion Management: Central management and Synchronized Security are not usable as in online environments
  • Dynamic DNS: Requires internet connection
  • External NTP: Only works if a reachable internal time server is available
  • FQDN: Only sensible with internal DNS resolution
  • Online Help: Not available without internet access
  • RED Online Provisioning: Requires online provisioning
  • Email Protection: Anti-spam, RDNS, SPF, RBL, and IP reputation are unavailable; malware scanning, email routing, MIME file filter, and SPX encryption can continue to work
  • Web Server Protection (WAF): Real-time Blackhole List (RBL) and IP reputation are also unavailable in Air Gap operation. This limitation does not only affect Email Protection.
  • Sophos Anti-Virus Live Protection: SXL2 live lookups do not work without an online connection
  • Chromebook Authentication and SMS Gateway: Require online services and do not fit classic Air Gap
  • Web and URL Categorization: Web categorization, Micro Apps Discovery, and CASB Lite are limited to locally available categories and signatures without online services
  • Zero-Day Protection: Requires cloud connection and does not fit classic Air Gap
  • Support Access: Remote support access is not available in isolated networks

This point is often underestimated in projects. An air-gap firewall cannot deliver the same cloud-supported protection effect as a normally connected firewall. Therefore, it should be decided before the design which protection functions are absolutely necessary and how the missing online functions will be compensated: internal DNS and NTP servers, manual pattern routine, Syslog, local documentation, and a clear support process.

Establish Operational Routine

Air Gap requires a fixed routine. Otherwise, license and pattern updates only become noticeable when a warning appears or a protection module is no longer current.

Sensible routine:

  • Weekly or according to internal risk: Check, download, and apply pattern file
  • Monthly: Document pattern status, license status, HA status, and alerts
  • By day 160 at the latest: Prepare new air-gap license file from Sophos Fusion
  • After each upload: Check license status, pattern status, relevant protection modules, and HA sync
  • During each firmware window: Plan air-gap process, backup, pattern, and rollback together

Firmware updates remain a separate process. For execution, see Perform Sophos Firewall Firmware Update, for backup and recovery Create or Restore Sophos Firewall Backup.

If an Upload Fails

For a rejected license upload, first compare system airgap show, serial number, Sophos Fusion account, download date, and the HA node’s role. Don’t retry a file older than 30 days; download a new one from Sophos Fusion. In HA, the Initial Primary remains the only upload node. Uploading the license to the other node isn’t a workaround.

If an active-passive air-gap license upload fails on SFOS 22.0 GA, the firmware level matters: Sophos lists this issue as fixed in 22.0 MR1 (NC-169474). For failed pattern updates, see the Sophos Firewall v22 MR2 context for the SAVI/AVIRA fix (NC-180066) and an eBPF service that became unresponsive after a pattern update (NC-177769). Use the Sophos Firewall firmware update guide to decide whether a planned update should precede more upload attempts; these IDs don’t explain every failure.

For a pattern failure, record the component, versions, timestamp, and status, then collect logs under Diagnostics > Troubleshooting logs. For licensing failures, licensing.log is one of the relevant files. If the cause remains unclear, send these details with the serial number and SFOS build to Sophos Support. Restarting a service or running system airgap disable without a matching diagnosis obscures the initial state.

Common Mistakes

Clarifying Air Gap Only After Installation

Air Gap should be clarified before procurement and installation. If the firewall is already productively isolated but no suitable air-gap approval or license file is available, unnecessary pressure arises.

Treating Pattern Updates as Optional

Pattern updates are not less important in air-gap environments but operationally more demanding. Without routine, protection functions quietly become outdated.

Ignoring HA Role Before License Upload

In Active-Passive HA, the Initial Primary must be the correct current Primary. Otherwise, the license status can become unclear after failover or upload.

Assuming Cloud Functions

Zero-Day Protection, Sophos Fusion Management, Online Reputation, RED Online Provisioning, or Support Access should not be silently planned in air-gap designs.

Handling License Warnings Too Late

Air-gap licenses have a 180-day window, but the process should not start on the last day. Download, transfer, change approval, and upload take time.

Checklist

  • Air-gap approval clarified with Sophos.
  • Firewall claimed in the correct Sophos Fusion account.
  • Serial number, model, and license status documented.
  • Secure file transfer into the isolated environment defined.
  • system airgap enable executed and documented.
  • Air-gap license uploaded under Administration > Licensing.
  • For HA: Initial Primary, current Primary, and Preferred Primary checked.
  • Pattern file downloaded and applied under Backup & firmware > Pattern updates.
  • License status, pattern status, and licensing.log checked.
  • Operational routine for pattern, license file, HA status, and firmware window established.

FAQ

What is Sophos Firewall Air Gap?

Air Gap is an operational model for isolated Sophos firewall environments without direct internet access. Licensing and pattern updates are maintained manually or through a separate air-gap process.

How do you activate Air Gap on the Sophos Firewall?

Air Gap is activated in the Device Console with system airgap enable. Afterwards, the section for manual license synchronization appears under Administration > Licensing.

How long is an air-gap license valid?

Air-gap licenses have a 180-day window without new synchronization, with a warning after 160 days. Upload a new license file before expiration, then check subscriptions and expiry dates under Administration > Licensing. Check the support subscription and RMA entitlement separately; the upload neither renews a paid support contract nor guarantees continuing Enhanced Support.

Do patterns need to be manually updated in air-gap environments?

Yes, if no automated air-gap update solution is set up. For SFOS 22.0 and newer, the pattern file is downloaded and uploaded under Backup & firmware > Pattern updates > Manual pattern update.

Do air-gap pattern updates also include hotfixes?

No. Pattern updates update patterns and signatures, but they do not include hotfixes. For hotfixes in air-gap environments, clarify the support process with Sophos in advance.

What is important for Air Gap and HA?

In Active-Passive HA, the air-gap license should be applied on the Initial Primary while this device is also the current Primary. The Initial Primary should be set as the Preferred Primary.

Do all Sophos Firewall functions work in air-gap operation?

No. Functions with cloud, online reputation, Sophos Fusion, or remote support dependency are not or only partially usable. This must be checked before the design.