Configure and verify Sophos Firewall breakout interfaces
A breakout interface divides one fast physical port into two or four independent member interfaces. A QSFP port can therefore serve several smaller switch uplinks. This provides additional ports, but it is not a purely logical change: SFOS changes the hardware layout and then requires a firewall restart.
⚠️ Breaking out a production uplink interrupts the link and can affect WebAdmin, HA, VLANs, routing, and all data traffic. Before making the change, prepare a current backup, a maintenance window, independent management access, and documented port mappings on the firewall and peer device.
Quick procedure
First compare the appliance, source port, supported breakout mode, transceiver or breakout cable, and peer-device ports. Then open Network > Interfaces, select the required Breakout mode on the breakout-capable source port, and save the change.
SFOS initially shows Breakout: Not activated and requests a restart with Restart the firewall. Only after the restart does the source port appear as Breakout source, allowing the new member interfaces to be configured individually. Then verify each member with its link status, speed, VLAN or LAG configuration, and real test traffic.
Supported models and port combinations
Breakout isn’t supported on every XGS Appliance model or every high-speed port. The current SFOS 22 help lists these combinations:
- XGS 8500: The fixed 100 Gbps ports
F13andF14can be divided into2 x 50 Gbps, or4 x 25,4 x 10, or4 x 1 Gbps. The 40 Gbps FleXi module supports four members at25,10, or1 Gbps. - XGS 7500: The fixed 40 Gbps ports
F13andF14, and the 40 Gbps FleXi module, support four members at25,10, or1 Gbps. - XGS 6500 and XGS 5500: Fixed ports aren’t listed for breakout. The 40 Gbps FleXi module supports four members at
10or1 Gbps.
Sophos requires the AMDA0112-0001 module for FleXi breakout. This list doesn’t replace a current hardware and transceiver check. The port standard, module, cable, and peer device must match the specific appliance. Check SFP, SFP+, and QSFP on Sophos Firewall explains selection and read-only link diagnostics.
Important: A breakout cable that fits mechanically doesn’t prove that the combination is supported. The number of members, available link speeds, transceiver or DAC type, and switch ports must be checked together.
Prepare the breakout
Record the existing data path before switching modes. This includes the source port, current Link mode, FEC, auto-negotiation, zone, IP configuration, VLANs, LAG, routing, NAT, firewall rules, HA role, and cabling. Refresh Object usage so that dependent configurations aren’t overlooked.
A simple example uses source port F13 on an XGS 8500 and divides it into four 25 Gbps members. F13, the model, and the speed are example values and must be replaced with the actually supported combination. Four matching ports or a corresponding breakout design must be available on the switch side.
If the port carries the current management connection or the only production uplink, don’t change it without a separate recovery path. In HA, both appliances must meet the same hardware requirements. The breakout configuration is synchronized from the primary, but each node requires its own restart.
Enable breakout in SFOS
- Open Network > Interfaces.
- Select the breakout-capable source port. SFOS marks supported ports with a breakout icon.
- Under General settings, select the required Breakout mode, for example four member interfaces.
- Select Save.
- Confirm the status
Breakout: Not activatedand the messageRestart the firewall. - Restart the firewall in the maintenance window.
- After startup, confirm that the source port shows
Breakout sourceand that the expected member interfaces appear with an Ethernet icon.
The members then behave as normal physical interfaces with separate configurations. Under Advanced settings, Link mode shows the maximum speed supported by the specific member. Match port speed, duplex, auto-negotiation, and FEC with the peer device. For high-speed links, Show recommended settings and Load recommended configuration help apply the supported values.
For 25, 50, and 100 Gbps links, the order matters. Connect the cable, select Link mode, and save first. Reopen the interface, select Show recommended settings, apply the values with Load recommended configuration, and save again. For all other ports, including 40 Gbps ports, SFOS shows the recommendations as soon as you select the link mode.
Each used member then receives its intended role. It can operate as an individual interface, a VLAN parent, or a LAG member. Breakout alone doesn’t create a zone, addressing, rules, or routing. Zones and interfaces on Sophos Firewall explains how these elements interact.
Breakout and HA
In an HA cluster, make the change on the primary. Sophos describes three important states:
- When breakout is configured on the primary, restart the primary first and then the auxiliary.
- If the primary already has breakout interfaces, the configuration is synchronized to the auxiliary. Restart the auxiliary afterward for the configuration to take effect.
- If the primary has no breakout configuration, existing breakout interfaces on the auxiliary are removed during synchronization.
Restarting both nodes at the same time isn’t an acceptance test. Document roles, the dedicated HA link, monitored ports, and production uplinks first. After each restart, verify HA status, interface mappings, and the data path before continuing with the second node. Configure and test HA on Sophos Firewall contains the complete cluster workflow.
Change or remove the configuration
Change the breakout mode on the source port under Network > Interfaces. A different split also changes the member layout and therefore belongs in a maintenance window. If a selection is changed and reverted before activation, Sophos doesn’t require a restart.
To remove the configuration, select Breakout mode > No breakout on the source port. Move production dependencies from the members to a tested replacement path first. Then save, follow the restart message, and confirm after the reboot that the source port is available as a normal interface again.
No breakoutisn’t a neutral display option. It removes the breakout configuration and must not be selected and saved merely to inspect the setting.
FleXi module, migration, and restore
If a broken-out FleXi port is removed, SFOS deletes the related member interfaces and shows the source port as Not Available. After reinstalling the module, break out the port again and restart the firewall. Therefore document members, zones, VLANs, LAGs, and all other dependencies before replacing a module.
The breakout configuration is generally retained during an upgrade, downgrade, or rollback, but the target must support the mode. On a version where breakout wasn’t previously configured, source and member interfaces may be visible in WebAdmin but not function. Because the members already exist, you can break out the source again in this specific case without restarting. If you remove the configuration instead, restart the firewall afterward. SFOS also accepts an imported breakout configuration only on a supported version and appliance.
A factory reset deletes the breakout configuration. During backup and restore, the assistant shows only the Breakout Root Port, not individual members. The target must have at least as many breakout ports configured as the backup. Two can be mapped to two or four, but four can’t be mapped to two. A physical source port can be mapped to a supported Breakout Root Port.
Selecting Don’t map. Creates Pseudo port leaves the root port unmapped. SFOS retains the dependent configuration, but it doesn’t work on the pseudo port and must be moved to active ports before production acceptance. Sophos Firewall backup and restore explains the remaining migration limits.
Verify after the restart
A visible member only proves that SFOS created the hardware split. Perform the technical verification in stages:
- The source port shows
Breakout source; the number and names of members match the plan. - Each used member shows the expected link status, speed, and full duplex.
- The switch port, transceiver or breakout cable, FEC, and negotiation match.
- VLANs or LAG members are bound to the correct breakout interface.
- Verify the gateway, routing, device access, and firewall rules with real traffic.
- In HA, validate the primary and auxiliary after separate restarts and a controlled failover test.
If a member remains Unplugged, check the physical path first: supported mode, port speed, cable split, transceiver, peer device, FEC, and auto-negotiation. Only after the link is stable should VLANs, LAG, routing, and firewall rules be investigated.
Frequently asked questions
Does a breakout change require a restart?
Breakout: Not activated and requests a restart. No restart is required if you revert a selection before activation or reactivate members that already exist after a downgrade or rollback. In HA, follow the state-specific procedure in Breakout and HA.