Skip to content
Avanet

Set Up Sophos Firewall Cellular WAN and Test 4G/5G Failover

Cellular WAN usually serves as a backup link on a Sophos Firewall. At temporary sites, mobile broadband can also be the primary connection if the data plan, reception, latency, and operational risk are suitable. For 4G or 5G to take over reliably during an outage, more than the SIM and APN must be correct: Gateway monitoring, SD-WAN rules, firewall rules, and the return to the primary link must also be tested.

The reliable sequence is: Check the hardware and data plan, configure WWAN1, define the failover logic, and then test failover and failback with real application traffic.

Requirements and Planning

Before starting, the following are required:

  • a 4G/5G modem or Sophos module compatible with the firewall model and SFOS version
  • an active SIM with a suitable data plan, PIN, and APN
  • a provider username and password, if required
  • information about data volume, a public IP address, or CGNAT
  • adequate reception and correctly connected antennas
  • a list of services that must continue operating over the backup link
  • a test window during which the primary link may be intentionally interrupted

Long or poor-quality antenna cables can negate the benefit of a better antenna position.

For a legacy USB modem, use the official SFOS 22 USB compatibility matrix only as a historical lookup. The matrix is dated 2024-08-19, is indicative, is no longer updated, and is not approval for a new purchase. Record the exact manufacturer, model, and carrier, plus the Default ID presented at initial detection and the Modem ID presented by the modem function after mode switching. Likely is a historical indication only. Unlikely, an unlisted device, or an ID mismatch is unvalidated. Not compatible means reject the device.

Do not accept a modem from the matrix label alone. Runtime acceptance requires the firewall to detect it, create WWAN1, obtain the expected IP address and gateway, carry representative traffic, and complete controlled failover and failback. Record these results with the device identity and IDs.

For Sophos’ own modules, the current assignment is more specific: the Sophos 5G module Gen.2 is documented for XGS 118/118w, 128/128w, and 138/138w; these appliances require at least SFOS 20 MR2. The Sophos 5G module Gen.1 is listed for XGS 116/116w, 126/126w, and 136/136w. Check the module and firewall generation together before powering off and installing it. Sophos’ stated maximums of up to 4.5 Gbps download and 660 Mbps upload describe the radio module, not guaranteed end-to-end throughput from the firewall, carrier, or a single application.

A limited mobile data plan should not take over all site traffic without controls. A CGNAT address or another address that is not publicly reachable prevents inbound connections to the firewall. A site-to-site IPsec tunnel can still use the mobile path as the initiator. NAT-T is always active on Sophos Firewall, but the remote peer, identities, and return route must be configured accordingly.

Cellular WAN is not supported in any Sophos Firewall HA mode and must be turned off on both devices before configuring HA. If HA and mobile failover are both required, a separate WAN design is necessary. For details, see Sophos Firewall HA Cluster Variants and Operations.

Only change hardware or the SIM while the firewall is turned off. The Sophos 5G module is not hot-swappable.

Set Up Cellular WAN

Prepare the Modem and SIM

Clarify the SIM status, PIN, APN, and provider profile before configuring the firewall. Business, consumer, and IoT data plans may use different APNs. Connect all antennas and position them for a stable connection, not merely detectable network reception.

Check the Interface

Network > Cellular WAN
Network > Interfaces

Turn on Cellular WAN and check whether the modem status, IP address, and gateway are shown. For a 5G module, first use Show recommended configuration and Load recommended configuration, then save the APN, optional credentials, and SIM PIN.

The firewall automatically creates the WWAN1 interface in the WAN zone, so existing WAN rules also apply to this interface. It also creates the dynamic host ##WWAN1. Configure Sophos Firewall Zones and Interfaces explains the fundamentals.

For 5G modules, only Network adapter (DHCP) is available under IP assignment. Dial-up (PPP) remains disabled. If WWAN1 does not appear, check hardware detection and logs before changing the APN or routing.

Under General settings, the display name can be changed, but the hardware name can’t. Depending on the modem, the firewall also shows Connect mode, Reconnect tries, Modem port, Phone number, Username, Password, SIM card PIN code, and APN, as well as optional DHCP connect/disconnect commands and an Initialization string. These values come from the carrier or approved modem profile; don’t copy them from examples. Selecting Always under Reconnect tries makes the firewall reconnect without a fixed attempt limit.

For MTU and MSS, Assignment type: Automatic is the default. Use Manual only during a controlled fragmentation or TCP test when the values obtained automatically from the carrier demonstrably don’t work. Then retest real applications, Packet Capture, and failover; a lower MTU alone isn’t proof of success.

Define the Gateway and SD-WAN Behavior

Network > WAN link manager
Routing > SD-WAN profiles
Routing > SD-WAN routes

The general meaning of Active, Backup, ANY/ALL, failover rules and failback is explained in Configure and test Sophos Firewall WAN failover. This article focuses on the additional characteristics of the mobile path.

For simple internet failover, click Edit for the WWAN gateway in WAN link manager and select Type: Backup. New gateways are active by default and would otherwise participate in load balancing. Under Activate this gateway, specify whether the backup link takes over when any (ANY) or only all (ALL) active gateways fail. Manually does not activate it automatically; you must change Type to Active in the configuration.

Action on failback determines what happens when the primary link returns. Existing sessions can continue over WWAN until they time out while only new connections use the primary link again, or all connections can be re-established over the restored link. The second option can interrupt active sessions. For SD-WAN routes, however, Serve all connections through restored gateway only applies when WAN link load balance is selected as the primary gateway. If an active WAN link is the primary SD-WAN gateway, only new connections are sent through the restored gateway; if a backup WAN link is the primary gateway, connections are re-established and continue through that backup link.

Configure selective routes, SLA checks, or different treatment of services through SD-WAN profiles and routes. Configure a Sophos Firewall SD-WAN Route explains the procedure in detail.

Health Checks can use Ping or TCP. An SD-WAN profile supports up to two Probe Targets; the second target serves as a fallback if the first does not respond. Prioritize critical applications during failover and limit data-intensive, nonessential services.

For a WWAN gateway, Sophos automatically creates a failover rule to 8.8.8.8 in addition to checking the leased gateway IP. This keeps the connection testable if the provider does not allow ping to the gateway address. Even so, verify whether this target complies with the local security policy.

If reply packets or firewall-generated traffic take a different path, see Check SD-WAN Routing for Reply Packets and System Traffic.

Check the Signal and Failover

Control Cellular WAN Through Device Console

system cellular_wan does more than display status. Cellular WAN is disabled by default. Enable it in Device Console before the other Cellular WAN commands work and before the menu becomes available in WebAdmin:

system cellular_wan enable
system cellular_wan show

disable turns the feature off again. Only use this command when WWAN1 carries neither active traffic nor a required backup path:

system cellular_wan disable

Sophos documents the following combined command template for modem startup and shutdown behavior:

system cellular_wan set modem-setup-delay <0-15> disconnect-on-systemdown [on|off]

Replace the placeholders with real values. modem-setup-delay is a delay of 0 to 15 seconds and defaults to 0. disconnect-on-systemdown defaults to off. Record the current state with show before changing it. A longer delay or disconnecting during shutdown is not a general stability optimization. Use it only for evidenced modem or shutdown behavior.

A serial-port query and the QMI switch are also available for deeper modem troubleshooting:

system cellular_wan query serialport <port-number> ATcommand <AT-command>
system cellular_wan qmi-mode [enable|disable]

query sends a valid modem-specific AT command directly to the selected port. An incorrect command can change registration, radio mode, or connectivity, so only use it in a documented vendor or support workflow. The qmi-mode CLI switch only applies to Sierra modems; QMI is already supported for non-Sierra modems. Do not toggle it speculatively. After every change, check show, WebAdmin status, modem and network logs, and a real data flow. Rollback restores the previously recorded values.

Check Signal Status Through the CLI

After signing in through SSH, select Option 4: Device Console. The following command shows configuration, SIM, connection, and signal status:

system cellular_wan show

The command existed previously; from SFOS 22.0 GA, it can also be used to check signal strength. Sophos does not publish universal thresholds for these values. Compare them during normal operation, after antenna changes, and during active failover. Strong fluctuations initially point to the radio path, antenna, provider, module, or SIM, but do not rule out simultaneous routing issues.

⚠️ Allow SSH access only from trusted administrator networks. Before use, review Connect to Sophos Firewall Using SSH and harden access as described in Device Access and Local Service ACL.

Test Failover and Failback

Before the test, ensure that a current configuration backup exists, document the primary and backup paths, inform affected users, and open Log Viewer and monitoring. When using SD-WAN, also enable the local SD-WAN logs under System services > Log settings.

  1. In the initial state, check the primary gateway, WWAN gateway, applied SD-WAN route, and data counters.
  2. Generate relevant test traffic, such as DNS, HTTPS, RDP, VPN, and an important business application.
  3. Intentionally disable the primary link or force its Health Check to fail.
  4. In WAN link manager or under Routing > SD-WAN routes, verify that WWAN1 takes over.
  5. In Log Viewer, check the SD-WAN module and the matched firewall rules.
  6. Under Network > Cellular WAN, check Status, IP address, Gateway IP, Bytes uploaded, Bytes downloaded, and Time duration.
  7. Test DNS, HTTPS, RDP, VPN, and the selected business applications again over WWAN1.
  8. Restore the primary link and verify the return path. In WAN link manager, the configured failback behavior must take effect; with SD-WAN, the return also depends on the strategy and SLA.
  9. Finally, verify the gateway, connections, and applications over the primary path again.

A successful ping proves only reachability, not that the required services work. The Policy Tester also does not consider SD-WAN routes and is therefore not proof of the actual path. Test a Firewall Rule with Log Viewer, Policy Test, and Packet Capture is still useful for firewall rules, logs, and packet captures.

Troubleshoot Problems

  • Modem or WWAN1 is missing: First compare the physical manufacturer/model and the detected Default/Modem IDs with the recorded identity. Then check power, the USB port and connection, and firmware. modemd.log records insertion or removal of WWAN USB devices, syslog.log records USB, modem, and PPP events, and networkd.log records modem-related network configuration. Escalate to Sophos, the modem vendor, or the carrier with that identity, the IDs, and the relevant log extracts; replace a mismatched or Not compatible device, or one that cannot pass runtime acceptance.
  • The SIM does not connect: Check the PIN, APN, provider profile, SIM lock, and reception. Confirm the APN with the provider instead of guessing it.
  • The gateway is active, but no traffic passes: Check the applied gateway and SD-WAN route, firewall rule, NAT, DNS, and return path. dgd.log contains events for WAN gateways and link failover; SD-WAN Health Checks and route changes appear in the SD-WAN module in Log Viewer.
  • Applications are unstable: Mobile connections often have higher latency, packet loss, and fluctuations. Test real applications and, if necessary, measure throughput with iPerf between two endpoints. For VPN or fragmentation issues, also Check MTU and MSS.
  • VPN works only over the primary link: Inbound connections are not directly possible with CGNAT. Check whether the mobile side initiates the tunnel, the remote peer accepts dynamic addresses or suitable identities, and the return route is correct.

Identify Sophos Firewall Service Logs Correctly explains the purpose of each log file.

Reconnect or Restart the Modem in SFOS 23

Under Network > Cellular WAN, Connect establishes the modem connection. Reset instead restarts the modem and reconnects it to the firewall. Existing WWAN interface settings and dependent configurations are retained; this is not a factory reset. This reset procedure is documented for SFOS 23, not as an SFOS 22 feature.

Reset is available only for the Quectel and Sierra Wireless 5G models, not other modem models or USB dongles. Check the exact model before choosing a recovery method; the manufacturer name or 5G support alone is not enough.

⚠️ Restarting the modem temporarily interrupts mobile connectivity even though configuration is retained. Ensure an independent administrative access path first. If WWAN carries active traffic or is a required backup, arrange a maintenance window. Shutting down the firewall for the hardware alternative below also interrupts its other services.

  1. Record the model, current modem status, IP address and gateway, and relevant modem and network logs. Document WWAN1 settings and dependencies such as the gateway, SD-WAN routes, firewall rules, and NAT rules so they can be compared afterward.
  2. Supported 5G model on SFOS 23: Under Network > Cellular WAN, click Reset, then verify that the modem is detected again and reconnects.
  3. Model without Reset support: Use only a modem-specific AT restart procedure documented by the manufacturer or support. The query serialport caution above still applies; do not guess an AT command. Alternatively, shut down the firewall and only unplug and reconnect the modem after the firewall is powered off. Then power on the firewall and verify detection and reconnection. Never unplug the modem while the firewall is running: this can cause Cellular WAN connectivity problems.
  4. Under Network > Cellular WAN, check status, IP address, and gateway; under Network > Interfaces, compare the retained WWAN1 settings with the recorded state. Also check dependent configurations and representative application traffic. When operationally safe, perform the controlled failover and failback test described above.

For interpreting XML API responses, the SFOS 23 Cellular WAN reference adds status 203 with Message.WWANResetSuccessfully for reported reset success and 511 with Message.WWANResetFailed for reported reset failure; both mappings are absent from the SFOS 22 reference. These are XML API status values, not HTTP status codes. The identifiers are literal message keys in the reference, not verified runtime message wording. They establish neither a Reset request nor an additional Action value: the unchanged sample lists Enable/Disable/Query/Set. Even after reported success, perform the checks in step 4: status, IP address, gateway, and real application traffic must be correct. On reported failure, capture the actual response and relevant logs, then escalate after the checks described here rather than attempting an unlimited sequence of restarts.

If the connection remains absent, send current extracts from modemd.log, syslog.log, and networkd.log, together with the model, status, and steps already performed, to Sophos, the modem vendor, or the carrier instead of repeatedly restarting speculatively.

Operations

  • Test failover and failback at least quarterly and after relevant firmware or routing changes.
  • Monitor the gateway, SD-WAN status, data volume, and costs.
  • Document the SIM, PIN, APN, data plan, antenna position, and signal comparison.
  • Limit noncritical traffic during failover.
  • Assign responsibility for alerts, provider outages, SIM locks, and the return to normal operation.
  • Document replacement hardware and the support process.

FAQ

Why is the gateway active even though the site has no internet access?

An active gateway confirms only the monitored path. The SD-WAN route, firewall rule, NAT, DNS, and return path can still prevent traffic. Always test with real traffic and check the relevant logs.

Does Cellular WAN work in a Sophos Firewall HA cluster?

No. Cellular WAN is not supported in any HA mode and must be turned off on both devices before configuring HA. In this case, mobile failover requires a separate WAN design.

Which CLI command shows Cellular WAN details?

Under Option 4: Device Console, system cellular_wan show displays configuration, SIM, connection, and signal status. Signal status is included from SFOS 22.0 GA.