Reset Sophos Firewall to factory settings
A factory reset returns the configuration of the currently running SFOS firmware to factory defaults. It is appropriate when SFOS itself is intact, but the configuration must be deliberately discarded or an appliance must be prepared for a controlled rebuild.
⚠️ Don’t confuse this with a reimage: A factory reset removes the custom configuration and interrupts all traffic. Pattern signatures, reports, and logs remain on the device. The public SFOS 22 help contradicts itself about the SSMK, so the key must be stored externally beforehand. For a complete reinstall or secure cleanup, reinstall Sophos Firewall OS by USB.
Factory reset in six steps
- Confirm that a factory reset is required rather than a rollback, restore, or reimage.
- Store the current backup, backup password, SSMK, serial number, firmware build, and management details externally.
- Prepare local access to Port 1, console access, and an on-site contact.
- Trigger the reset in WebAdmin or with the button sequence that exactly matches the XGS model.
- Wait for the restart and setup assistant without turning off the appliance prematurely.
- Rebuild the firewall or restore the intended backup and test every function.
Don’t reset without a tested backup and a reachable local recovery path. If an investigation is still in progress, save the logs, timeline, and support data first; a factory reset removes the very configuration that may explain the issue.
Distinguish factory reset, rollback, and reimage
The three paths serve different purposes. A factory reset retains the installed firmware but resets its current configuration. A rollback starts the previous firmware partition with its configuration from that time. A reimage reinstalls SFOS and also removes local operational data that a factory reset deliberately retains.
A slow WebAdmin, one faulty service, or a full report file system is therefore not yet a reason for a factory reset. Check the specific service, storage state, and logs first. If only the built-in admin password is lost, serial password recovery resets that password without deleting the complete configuration.
What remains after the reset
SFOS 22 removes custom configurations, including custom signatures such as custom IPS signatures. Firewall rules are also removed; afterwards, only the automatically created Auto added firewall policy for MTA rule exists.
However, a factory reset is not a complete data wipe:
- Signatures updated through Pattern updates remain.
- Reports and logs remain.
- Sophos gives conflicting information about the Secure Storage Master Key (SSMK): the dedicated reset page says it isn’t cleared, while the general firmware page says it is removed. Store the key externally before the reset and verify its state afterward.
- The configuration of the currently running firmware partition is reset. The other firmware partition keeps its own configuration; a later rollback can activate it again.
These properties are useful for recovery, but unsuitable when an appliance is retired, transferred, or must be completely sanitized. That requires a reimage or the RMA or disposal procedure specified by Sophos.
Prepare the reset safely
Before the maintenance window, download a fresh Sophos Firewall backup. The recovery package also includes the backup password, current and previous SSMKs, current management IP, WAN details, interface assignment, licence and Central assignment, and the exact SFOS build.
For a remote appliance, normal WebAdmin access isn’t a recovery path. Factory defaults apply after the reset, and existing WAN, VPN, or Central paths may disappear. An on-site person, direct Port 1 access, or a serial console must therefore be genuinely available before starting.
Don’t reset a single HA member spontaneously. First document the roles, initial primary, firmware build, HA link, Central registration, and intended rebuild order. The complete process is covered under Sophos Firewall HA variants and maintenance.
Trigger the factory reset
In WebAdmin
The Boot with factory default configuration action is available under Backup & Firmware > Firmware. It closes current sessions and restarts the firewall with factory settings. The maintenance window and local recovery path must already be active before confirming it.
The similarly named Factory reset with default configuration language selection also resets the firewall. It changes the language of the default objects in the configuration database, not merely the WebAdmin display language. A restore also brings back the configuration language stored in the backup, so this selection is for initial deployment rather than a casual language change.
With the Reset button on an XGS appliance
The hardware sequence depends on the model. Confirm the model designation on the appliance before pressing the button.
XGS 116/116w and higher models:
- Press and hold the Reset button on the back for more than 10 seconds.
- Release the button and wait for the reset.
XGS 88/88w and XGS 108/108w, using only the Reset button:
- Press the Reset button for at least three seconds and release it.
- Press the Reset button for 21 seconds and release it.
- Press and hold the Reset button again until the status LED flashes red three times, after approximately 21 seconds.
- Release the button.
With a serial console connected, these models can instead be restarted and the Reset button held while the GRUB page is visible. Release the button only when Hard reset button is pressed, performing default factory reset appears.
XGS 87/87w and XGS 107/107w:
- Press and immediately release the Reset button.
- Wait three seconds.
- Press and hold the Reset button until the status LED flashes red three times.
- Release the button.
On XG Series, the rear button only restarts the appliance and does not perform a factory reset. Don’t try a button sequence intended for another model. If the label, revision, or LED behavior is unclear, the documented WebAdmin or console path is safer.
Return the firewall to service
After the restart, access the appliance locally through the intended initial connection and complete the setup assistant in a controlled manner. Only then decide whether to build a new configuration or restore a compatible backup.
During a restore, the management IP, interfaces, Device Access, routes, and services come from the backup. The password of the default admin account is not restored from the backup; the target firewall retains its current default-admin password.
Acceptance testing includes at least the active SFOS version, interfaces, WAN, DNS, DHCP, routing, SD-WAN, firewall rules, NAT, VPN, RED, HA, authentication, certificates, logging, and Sophos Central. A successful login alone does not prove that the production data path is restored.
If the reset behaves differently than expected
The button only restarts the appliance: Check the model and sequence first. This behavior is intentional on XG Series. Don’t experiment with increasingly long button presses.
Reports or logs are still present: This matches the documented factory-reset behavior. If local operational data must also be removed, use a reimage.
The old configuration returns after a rollback: Each firmware partition has its own configuration. Factory-resetting the active partition doesn’t automatically delete the configuration of the other partition.
WebAdmin is no longer reachable at the previous address: The initial connection applies after the reset. Check the cabling, client IP, Port 1, and local setup path instead of triggering further resets.
Checklist
- Distinguished factory reset from rollback, restore, and reimage.
- Stored the backup file, password, and SSMK externally.
- Tested local Port 1 or console access.
- Confirmed the exact XGS model and matching button sequence.
- Documented HA, licence, and Central consequences.
- Prepared setup, restore, and functional tests.
- Did not assume that reports, logs, and the second firmware partition are erased.