Skip to content
Avanet

Configure and verify Sophos Firewall breakout interfaces

A breakout interface divides one fast physical port into two or four independent member interfaces. A QSFP port can therefore serve several smaller switch uplinks. This provides additional ports, but it is not a purely logical change: SFOS changes the hardware layout and then requires a firewall restart.

⚠️ Breaking out a production uplink interrupts the link and can affect WebAdmin, HA, VLANs, routing, and all data traffic. Before making the change, prepare a current backup, a maintenance window, independent management access, and documented port mappings on the firewall and peer device.

Quick procedure

First compare the appliance, source port, supported breakout mode, transceiver or breakout cable, and peer-device ports. Then open Network > Interfaces, select the required Breakout mode on the breakout-capable source port, and save the change.

SFOS initially shows Breakout: Not activated and requests a restart with Restart the firewall. Only after the restart does the source port appear as Breakout source, allowing the new member interfaces to be configured individually. Then verify each member with its link status, speed, VLAN or LAG configuration, and real test traffic.

Supported models and port combinations

Breakout isn’t supported on every XGS model or every high-speed port. The current SFOS 22 help lists these combinations:

  • XGS 8500: The fixed 100 Gbps ports F13 and F14 can be divided into 2 x 50 Gbps, or 4 x 25, 4 x 10, or 4 x 1 Gbps. The 40 Gbps FleXi module supports four members at 25, 10, or 1 Gbps.
  • XGS 7500: The fixed 40 Gbps ports F13 and F14, and the 40 Gbps FleXi module, support four members at 25, 10, or 1 Gbps.
  • XGS 6500 and XGS 5500: Fixed ports aren’t listed for breakout. The 40 Gbps FleXi module supports four members at 10 or 1 Gbps.

Sophos requires the AMDA0112-0001 module for FleXi breakout. This list doesn’t replace a current hardware and transceiver check. The port standard, module, cable, and peer device must match the specific appliance. Check SFP, SFP+, and QSFP on Sophos Firewall explains selection and read-only link diagnostics.

Important: A breakout cable that fits mechanically doesn’t prove that the combination is supported. The number of members, available link speeds, transceiver or DAC type, and switch ports must be checked together.

Prepare the breakout

Record the existing data path before switching modes. This includes the source port, current Link mode, FEC, auto-negotiation, zone, IP configuration, VLANs, LAG, routing, NAT, firewall rules, HA role, and cabling. Refresh Object usage so that dependent configurations aren’t overlooked.

A simple example uses source port F13 on an XGS 8500 and divides it into four 25 Gbps members. F13, the model, and the speed are example values and must be replaced with the actually supported combination. Four matching ports or a corresponding breakout design must be available on the switch side.

If the port carries the current management connection or the only production uplink, don’t change it without a separate recovery path. In HA, both appliances must meet the same hardware requirements. The breakout configuration is synchronized from the primary, but each node requires its own restart.

Enable breakout in SFOS

  1. Open Network > Interfaces.
  2. Select the breakout-capable source port. SFOS marks supported ports with a breakout icon.
  3. Under General settings, select the required Breakout mode, for example four member interfaces.
  4. Select Save.
  5. Confirm the status Breakout: Not activated and the message Restart the firewall.
  6. Restart the firewall in the maintenance window.
  7. After startup, confirm that the source port shows Breakout source and that the expected member interfaces appear with an Ethernet icon.

The members then behave as normal physical interfaces with separate configurations. Under Advanced settings, Link mode shows the maximum speed supported by the specific member. Match port speed, duplex, auto-negotiation, and FEC with the peer device. For high-speed links, Show recommended settings and Load recommended configuration help apply the supported values.

Each used member then receives its intended role. It can operate as an individual interface, a VLAN parent, or a LAG member. Breakout alone doesn’t create a zone, addressing, rules, or routing. Zones and interfaces on Sophos Firewall explains how these elements interact.

Breakout and HA

In an HA cluster, make the change on the primary. Sophos describes three important states:

  • When breakout is configured on the primary, restart the primary first and then the auxiliary.
  • If the primary already has breakout interfaces, the configuration is synchronized to the auxiliary. Restart the auxiliary afterward for the configuration to take effect.
  • If the primary has no breakout configuration, existing breakout interfaces on the auxiliary are removed during synchronization.

Restarting both nodes at the same time isn’t an acceptance test. Document roles, the dedicated HA link, monitored ports, and production uplinks first. After each restart, verify HA status, interface mappings, and the data path before continuing with the second node. Configure and test HA on Sophos Firewall contains the complete cluster workflow.

Change or remove the configuration

Change the breakout mode on the source port under Network > Interfaces. A different split also changes the member layout and therefore belongs in a maintenance window. If a selection is changed and reverted before activation, Sophos doesn’t require a restart.

To remove the configuration, select Breakout mode > No breakout on the source port. Move production dependencies from the members to a tested replacement path first. Then save, follow the restart message, and confirm after the reboot that the source port is available as a normal interface again.

No breakout isn’t a neutral display option. It removes the breakout configuration and must not be selected and saved merely to inspect the setting.

FleXi module, migration, and restore

If a broken-out FleXi port is removed, SFOS deletes the related member interfaces and shows the source port as Not Available. After reinstalling the module, break out the port again and restart the firewall. Therefore document members, zones, VLANs, LAGs, and all other dependencies before replacing a module.

The breakout configuration is generally retained during an upgrade, downgrade, or rollback, but the target must support the mode. On a version where breakout wasn’t previously configured, source and member interfaces may be visible in WebAdmin but not function. In that case, enable the breakout again or remove it in a controlled way and restart the firewall.

A factory reset deletes the breakout configuration. During backup and restore, the assistant shows only the Breakout Root Port, not individual members. Root ports can only be mapped to a target with a supported port count and combination. Sophos Firewall backup and restore explains migration limits and pseudo ports.

Verify after the restart

A visible member only proves that SFOS created the hardware split. Perform the technical verification in stages:

  1. The source port shows Breakout source; the number and names of members match the plan.
  2. Each used member shows the expected link status, speed, and full duplex.
  3. The switch port, transceiver or breakout cable, FEC, and negotiation match.
  4. VLANs or LAG members are bound to the correct breakout interface.
  5. Verify the gateway, routing, device access, and firewall rules with real traffic.
  6. In HA, validate the primary and auxiliary after separate restarts and a controlled failover test.

If a member remains Unplugged, check the physical path first: supported mode, port speed, cable split, transceiver, peer device, FEC, and auto-negotiation. Only after the link is stable should VLANs, LAG, routing, and firewall rules be investigated.

Frequently asked questions

Does a breakout change require a restart?

Yes. After saving, SFOS shows Breakout: Not activated and requests a restart. In HA, restart and verify the primary and auxiliary one after the other.

Can every QSFP port be broken out?

No. The appliance, source port, FleXi module, number of members, and speeds must be explicitly supported. For SFOS 22, Sophos lists breakout only for specific ports and modules on the XGS 5500, 6500, 7500, and 8500.