Skip to content
Avanet

Reset Sophos Firewall to factory settings

A factory reset returns the configuration of the currently running SFOS firmware to factory defaults. It is appropriate when SFOS itself is intact, but the configuration must be deliberately discarded or an appliance must be prepared for a controlled rebuild.

⚠️ Don’t confuse this with a reimage: Every factory reset removes the custom configuration and interrupts all traffic. A standard reset leaves Pattern signatures, reports, and logs on the device; only the serial RESET menu offers additional deletion levels. The public SFOS 22 help contradicts itself about the SSMK. The backup, backup password, and current and previous SSMKs must therefore be stored externally first. For a complete reinstall, reinstall Sophos Firewall OS by USB.

Factory reset in six steps

  1. Confirm that a factory reset is required rather than a rollback, restore, or reimage.
  2. Store the current backup, backup password, current and previous SSMKs, serial number, firmware build, and management details externally.
  3. Prepare local access to Port 1, console access, and an on-site contact.
  4. Choose the correct reset path: WebAdmin, Device Console, serial RESET menu, or the button sequence that exactly matches the XGS Appliance model.
  5. Wait for the restart and setup assistant without turning off the appliance prematurely.
  6. Rebuild the firewall or restore the intended backup and test every function.

Don’t reset without a newly created, externally downloaded backup, the required keys, and a reachable local recovery path. Confirm beforehand that the target platform and version support the backup. If an investigation is still in progress, save the logs, timeline, and support data first; a factory reset removes the very configuration that may explain the issue.

Distinguish factory reset, rollback, and reimage

The three paths serve different purposes. A factory reset retains the installed firmware but resets its current configuration. A rollback starts the previous firmware partition with its configuration from that time. A reimage reinstalls SFOS and also removes local operational data that a factory reset deliberately retains.

A slow WebAdmin, one faulty service, or a full report file system is therefore not yet a reason for a factory reset. Check the specific service, storage state, and logs first. If only the built-in admin password is lost, serial password recovery resets that password without deleting the complete configuration.

What each reset path deletes

Every factory reset in SFOS 22 removes custom configurations, including network settings, passwords, users, groups, policies, VPN configurations, and custom signatures. Firewall rules are also removed; afterwards, only the automatically created Auto added firewall policy for MTA rule exists.

For a reset through WebAdmin, Device Management, or the XGS Appliance button:

  • Signatures updated through Pattern updates remain.
  • Reports and logs remain.
  • Sophos gives conflicting information about the Secure Storage Master Key (SSMK): the dedicated reset page, Device Management, and the WebAdmin action description say it isn’t cleared, while the general firmware section says it is removed. Store the key externally before the reset and verify its state afterward.
  • The configuration of the currently running firmware partition is reset. The other firmware partition keeps its own configuration; a later rollback can activate it again.

The serial RESET menu has three separate deletion levels. Option 1 deletes custom configurations. Option 2 also resets signatures updated through Pattern updates to the firmware’s default signatures. Option 3 resets those signatures too and additionally deletes reports, logs, and all personally identifiable information. According to the same Sophos page, the SSMK remains.

Option 3 is therefore more extensive than a standard factory reset, but Sophos only documents reimaging as deleting all firewall data. For retirement, transfer, or defined sanitization, don’t infer secure erasure from a reset option’s name; follow the reimage, RMA, or disposal procedure specified by Sophos.

Prepare the reset safely

Before the maintenance window, create and download a fresh Sophos Firewall backup. A manual or scheduled backup requires an SSMK to be set. Restoring requires both the Encryption password and the SSMK used when that backup was created; after a key change, this may be a previous SSMK. The recovery package also includes the current management IP, WAN details, interface assignment, serial number, Central status, and exact SFOS build.

Check compatibility before the reset, not during recovery. For backups from 19.5 MR4 and later, the backup-restore assistant is available for interface mapping when restoring to XGS Appliances, virtual firewalls, and cloud firewalls running 20.0 MR2 and later. Platform and version rules can still restrict the permitted restore target.

For a remote appliance, normal WebAdmin access isn’t a recovery path. Factory defaults apply after the reset, and existing WAN, VPN, or Central paths may disappear. An on-site person, direct Port 1 access, or a serial console must therefore be genuinely available before starting.

Don’t reset a single HA member spontaneously. First document the roles, initial primary, firmware version and build, HA link, Central registration, and intended rebuild order. Restore an HA backup to the current primary, never the auxiliary. The restore restarts the primary without failover, so it causes downtime even in active-passive mode; it then synchronizes the auxiliary and deregisters both firewalls from Sophos Fusion (formerly Sophos Central).

If the restored backup has no HA configuration, HA is disabled. Sophos’ narrative says that the auxiliary retains its previous configuration, while its summary says the auxiliary is reset to factory settings except for the peer administration port and dedicated HA link configuration. Don’t build a recovery plan around either interpretation. Sophos publishes a separate reimage and rebuild procedure for active-passive only, not active-active. The wider operational context is covered under Sophos Firewall HA variants and maintenance.

Trigger the factory reset

In WebAdmin

The Boot with factory default configuration action is available under Backup & Firmware > Firmware. It closes current sessions and restarts the firewall with factory settings. The maintenance window and local recovery path must already be active before confirming it.

The similarly named Factory reset with default configuration language selection also resets the firewall. It changes the language of the default objects in the configuration database, not merely the WebAdmin display language. A restore also brings back the configuration language stored in the backup, so this selection is for initial deployment rather than a casual language change.

In the Device Console

After signing in to the CLI, open 5. Device Management, select Reset to factory defaults, and confirm the warning. This path removes the same custom configurations as the standard WebAdmin reset; according to the current Device Management help, the SSMK, Pattern signatures, reports, and logs remain.

Through the serial console with a selectable deletion level

Use this path only after deciding exactly which deletion level is required:

  1. Connect the endpoint to the firewall’s RJ45 COM or micro-USB console port with a console cable.
  2. Open a serial terminal client on the detected COM port at 38400 baud.
  3. Enter RESET in uppercase.
  4. Select and confirm option 1, 2, or 3 according to the deletion effects described above.

⚠️ Option 3 additionally deletes reports, logs, and personally identifiable information. Don’t use it as a generic troubleshooting step. There is no undo for the deleted local data after confirmation.

With the Reset button on an XGS Appliance

The hardware sequence depends on the model. Confirm the model designation on the appliance before pressing the button.

XGS 116/116w and higher models:

  1. Press and hold the Reset button on the back for more than 10 seconds.
  2. Release the button and wait for the reset.

XGS 88/88w and XGS 108/108w, using only the Reset button:

  1. Press the Reset button for at least three seconds and release it.
  2. Press the Reset button for 21 seconds and release it.
  3. Press and hold the Reset button again until the status LED flashes red three times, after approximately 21 seconds.
  4. Release the button.

With a serial console connected, these models can instead be restarted and the Reset button held while the GRUB page is visible. Release the button only when Hard reset button is pressed, performing default factory reset appears.

XGS 87/87w and XGS 107/107w:

  1. Press and immediately release the Reset button.
  2. Wait three seconds.
  3. Press and hold the Reset button until the status LED flashes red three times.
  4. Release the button.

On XG Series, the rear button only restarts the appliance and does not perform a factory reset. Don’t try a button sequence intended for another model. If the label, revision, or LED behavior is unclear, the documented WebAdmin or console path is safer.

Return the firewall to service

After the restart, access the appliance locally through the intended initial connection and complete the setup assistant in a controlled manner. Only then decide whether to build a new configuration or restore a compatible backup.

During a restore, the backup replaces the current configuration, deletes the backup stored on the firewall, and restarts the device. The management IP, interfaces, Device Access, routes, and services then come from the backup. The password of the default admin account isn’t restored; the target firewall retains its existing default-admin password. Central registration is retained only when restoring to the same firewall; a different firewall or HA cluster must be registered again.

Acceptance testing includes at least the active SFOS version, interfaces, WAN, DNS, DHCP, routing, SD-WAN, firewall rules, NAT, VPN, RED, HA, authentication, certificates, logging, and Sophos Fusion. A successful login alone does not prove that the production data path is restored.

If the reset behaves differently than expected

The button only restarts the appliance: Check the model and sequence first. This behavior is intentional on XG Series. Don’t experiment with increasingly long button presses.

Reports or logs are still present: This matches the documented factory-reset behavior. If local operational data must also be removed, use a reimage.

The restore asks for a key although the backup password is correct: You also need the SSMK that was active when the backup was created. If the SSMK has since changed, use the matching previous key rather than triggering more resets.

The old configuration returns after a rollback: Each firmware partition has its own configuration. Factory-resetting the active partition doesn’t automatically delete the configuration of the other partition.

WebAdmin is no longer reachable at the previous address: The initial connection applies after the reset. Check the cabling, client IP, Port 1, and local setup path instead of triggering further resets.

Checklist

  • Distinguished factory reset from rollback, restore, and reimage.
  • Stored the backup file, Encryption password, and current and previous SSMKs externally.
  • Checked backup compatibility for the target platform and version.
  • Tested local Port 1 or console access.
  • Confirmed the exact XGS Appliance model and matching button sequence.
  • Documented HA, downtime, licence, and Central consequences.
  • Deliberately selected the deletion effect of option 1, 2, or 3 when using serial RESET.
  • Prepared setup, restore, and functional tests.
  • Did not assume that reports, logs, and the second firmware partition are erased.

FAQ

Does a Sophos Firewall factory reset really delete all data?

Not with a standard reset through WebAdmin, Device Management, or the XGS Appliance button: Pattern signatures, reports, and logs remain. In the serial RESET menu, options 2 and 3 reset Pattern signatures, and option 3 also deletes reports, logs, and personally identifiable information. The Sophos help contradicts itself about the SSMK, so always store it externally first. A complete reinstall is performed by reimaging.

Can the backup be restored after a factory reset?

Yes, if the backup, password, SSMK, target version, and platform are compatible. The management configuration from the backup also becomes active during the restore.

Does the Reset button factory-reset every Sophos Firewall?

No. The sequence depends on the XGS Appliance model; on XG Series, the button only restarts the appliance.