Skip to content
Avanet

Set Up Sophos Firewall Cellular WAN and Test 4G/5G Failover

Cellular WAN usually serves as a backup link on a Sophos Firewall. At temporary sites, mobile broadband can also be the primary connection if the data plan, reception, latency, and operational risk are suitable. For 4G or 5G to take over reliably during an outage, more than the SIM and APN must be correct: Gateway monitoring, SD-WAN rules, firewall rules, and the return to the primary link must also be tested.

The reliable sequence is: Check the hardware and data plan, configure WWAN1, define the failover logic, and then test failover and failback with real application traffic.

Requirements and Planning

Before starting, the following are required:

  • a 4G/5G modem or Sophos module compatible with the firewall model and SFOS version
  • an active SIM with a suitable data plan, PIN, and APN
  • a provider username and password, if required
  • information about data volume, a public IP address, or CGNAT
  • adequate reception and correctly connected antennas
  • a list of services that must continue operating over the backup link
  • a test window during which the primary link may be intentionally interrupted

The Sophos USB compatibility list is only a reference, is no longer updated, and does not continuously test newer dongles. Check current model and module compatibility before purchasing. Long or poor-quality antenna cables can also negate the benefit of a better antenna position.

A limited mobile data plan should not take over all site traffic without controls. A CGNAT address or another address that is not publicly reachable prevents inbound connections to the firewall. A site-to-site IPsec tunnel can still use the mobile path as the initiator. NAT-T is always active on Sophos Firewall, but the remote peer, identities, and return route must be configured accordingly.

Cellular WAN is not supported in any Sophos Firewall HA mode and must be turned off on both devices before configuring HA. If HA and mobile failover are both required, a separate WAN design is necessary. For details, see Sophos Firewall HA Cluster Variants and Operations.

Only change hardware or the SIM while the firewall is turned off. The Sophos 5G module is not hot-swappable.

Set Up Cellular WAN

Prepare the Modem and SIM

Clarify the SIM status, PIN, APN, and provider profile before configuring the firewall. Business, consumer, and IoT data plans may use different APNs. Connect all antennas and position them for a stable connection, not merely detectable network reception.

Check the Interface

Network > Cellular WAN
Network > Interfaces

Turn on Cellular WAN and check whether the modem status, IP address, and gateway are shown. For a 5G module, first use Show recommended configuration and Load recommended configuration, then save the APN, optional credentials, and SIM PIN.

The firewall automatically creates the WWAN1 interface in the WAN zone, so existing WAN rules also apply to this interface. It also creates the dynamic host ##WWAN1. Configure Sophos Firewall Zones and Interfaces explains the fundamentals.

For 5G modules, only Network adapter (DHCP) is available under IP assignment. Dial-up (PPP) remains disabled. If WWAN1 does not appear, check hardware detection and logs before changing the APN or routing.

Define the Gateway and SD-WAN Behavior

Network > WAN link manager
Routing > SD-WAN profiles
Routing > SD-WAN routes

The general meaning of Active, Backup, ANY/ALL, failover rules and failback is explained in Configure and test Sophos Firewall WAN failover. This article focuses on the additional characteristics of the mobile path.

For simple internet failover, click Edit for the WWAN gateway in WAN link manager and select Type: Backup. New gateways are active by default and would otherwise participate in load balancing. Under Activate this gateway, specify whether the backup link takes over when any (ANY) or only all (ALL) active gateways fail.

Action on failback determines what happens when the primary link returns. Existing sessions can continue over WWAN until they time out while only new connections use the primary link again, or all connections can be re-established over the restored link. The second option can interrupt active sessions.

Configure selective routes, SLA checks, or different treatment of services through SD-WAN profiles and routes. Configure a Sophos Firewall SD-WAN Route explains the procedure in detail.

Health Checks can use Ping or TCP. An SD-WAN profile supports up to two Probe Targets; the second target serves as a fallback if the first does not respond. Prioritize critical applications during failover and limit data-intensive, nonessential services.

For a WWAN gateway, Sophos automatically creates a failover rule to 8.8.8.8 in addition to checking the leased gateway IP. This keeps the connection testable if the provider does not allow ping to the gateway address. Even so, verify whether this target complies with the local security policy.

If reply packets or firewall-generated traffic take a different path, see Check SD-WAN Routing for Reply Packets and System Traffic.

Check the Signal and Failover

Check Signal Status Through the CLI

After signing in through SSH, select Option 4: Device Console. The following command shows configuration, SIM, connection, and signal status:

system cellular_wan show

The command existed previously; from SFOS 22.0 GA, its output also includes signal status. Sophos does not publish universal thresholds for these values. Compare them during normal operation, after antenna changes, and during active failover. Strong fluctuations initially point to the radio path, antenna, provider, module, or SIM, but do not rule out simultaneous routing issues.

⚠️ Allow SSH access only from trusted administrator networks. Before use, review Connect to Sophos Firewall Using SSH and harden access as described in Device Access and Local Service ACL.

Test Failover and Failback

Before the test, ensure that a current configuration backup exists, document the primary and backup paths, inform affected users, and open Log Viewer and monitoring. When using SD-WAN, also enable the local SD-WAN logs under System services > Log settings.

  1. In the initial state, check the primary gateway, WWAN gateway, applied SD-WAN route, and data counters.
  2. Generate relevant test traffic, such as DNS, HTTPS, RDP, VPN, and an important business application.
  3. Intentionally disable the primary link or force its Health Check to fail.
  4. In WAN link manager or under Routing > SD-WAN routes, verify that WWAN1 takes over.
  5. In Log Viewer, check the SD-WAN module and the matched firewall rules.
  6. Under Network > Cellular WAN, check Status, IP address, Gateway IP, Bytes uploaded, Bytes downloaded, and Time duration.
  7. Test DNS, HTTPS, RDP, VPN, and the selected business applications again over WWAN1.
  8. Restore the primary link and verify the return path. In WAN link manager, the configured failback behavior must take effect; with SD-WAN, the return also depends on the strategy and SLA.
  9. Finally, verify the gateway, connections, and applications over the primary path again.

A successful ping proves only reachability, not that the required services work. The Policy Tester also does not consider SD-WAN routes and is therefore not proof of the actual path. Test a Firewall Rule with Log Viewer, Policy Test, and Packet Capture is still useful for firewall rules, logs, and packet captures.

Troubleshoot Problems

  • Modem or WWAN1 is missing: Check the hardware, power supply, USB port, firmware, and compatibility. modemd.log records the insertion or removal of WWAN USB devices, syslog.log records USB, modem, and PPP events, and networkd.log records modem-related network configuration.
  • The SIM does not connect: Check the PIN, APN, provider profile, SIM lock, and reception. Confirm the APN with the provider instead of guessing it.
  • The gateway is active, but no traffic passes: Check the applied gateway and SD-WAN route, firewall rule, NAT, DNS, and return path. dgd.log contains events for WAN gateways and link failover; SD-WAN Health Checks and route changes appear in the SD-WAN module in Log Viewer.
  • Applications are unstable: Mobile connections often have higher latency, packet loss, and fluctuations. Test real applications and, if necessary, measure throughput with iPerf between two endpoints. For VPN or fragmentation issues, also Check MTU and MSS.
  • VPN works only over the primary link: Inbound connections are not directly possible with CGNAT. Check whether the mobile side initiates the tunnel, the remote peer accepts dynamic addresses or suitable identities, and the return route is correct.

Identify Sophos Firewall Service Logs Correctly explains the purpose of each log file.

Operations

  • Test failover and failback at least quarterly and after relevant firmware or routing changes.
  • Monitor the gateway, SD-WAN status, data volume, and costs.
  • Document the SIM, PIN, APN, data plan, antenna position, and signal comparison.
  • Limit noncritical traffic during failover.
  • Assign responsibility for alerts, provider outages, SIM locks, and the return to normal operation.
  • Document replacement hardware and the support process.

FAQ

Why is the gateway active even though the site has no internet access?

An active gateway confirms only the monitored path. The SD-WAN route, firewall rule, NAT, DNS, and return path can still prevent traffic. Always test with real traffic and check the relevant logs.

Does Cellular WAN work in a Sophos Firewall HA cluster?

No. Cellular WAN is not supported in any HA mode and must be turned off on both devices before configuring HA. In this case, mobile failover requires a separate WAN design.

Which CLI command shows Cellular WAN details?

Under Option 4: Device Console, system cellular_wan show displays configuration, SIM, connection, and signal status. Signal status is included from SFOS 22.0 GA.