Skip to content
Avanet

Sophos Firewall Firmware Update: Preparation and Best Practices

A Sophos Firewall firmware update should only be approved once the upgrade path, backup, access, system health, HA, and recovery path are clear. Perform a Sophos Firewall firmware update explains the actual installation in WebAdmin or through Sophos Central.

⚠️ Before every update: A current backup, the Secure Storage Master Key belonging to that backup, and a specific rollback plan must be available. For SFOS 22 or later, also complete the SFOS 22 upgrade check.

Approval in ten points

A firmware change is ready when all ten questions can be answered with yes:

  1. The current version, target version, and supported upgrade path are documented.
  2. The release notes and known issues have been checked for the platform and configuration in use.
  3. The license and support entitlement permit the installation.
  4. A fresh backup, backup password, and matching Secure Storage Master Key are available.
  5. Free storage, system health, and, for affected XGS models, the SSD firmware meet the requirements.
  6. HA status, roles, and synchronization are healthy; both nodes meet the requirements.
  7. The maintenance window, owners, cutoff time, and rollback criteria are defined.
  8. Local or alternative management access is prepared.
  9. Tests for WAN, VPN, DNS, NAT, WAF, authentication, and critical applications are defined.
  10. Monitoring, communication, and change evidence are prepared.

If one of these points is missing, do not start the update under time pressure. Postponing a maintenance window is cheaper than an unplanned reimage or on-site visit.

Check the version, platform, and entitlement

Release notes and upgrade path

Before the change, compare the current SFOS version, target version, and supported path in the release notes. Also search the Sophos Known Issues for the platform, HA, VPN, routing, authentication, and the features actually in use.

Sophos Firewall may display a warning for an unsupported migration path. If the change is confirmed anyway, the firewall can start with the factory configuration and lose the existing configuration. Automatic rollback does not protect an unsupported upgrade path. Use only an approved path; for an incompatible version change, a reimage followed by a restore is the proper method.

⚠️ Platform limit: SFOS 21.0 GA and later versions do not support XG and SG Series hardware appliances. For these devices, plan a migration to XGS before upgrading.

Version-specific blockers should not be repeated as a long list in every firmware article. For SFOS 22, the separate upgrade check covers additional storage requirements, interface names, legacy remote access IPsec, STAS, SSD firmware, and platform support. For other target versions, their current release notes apply.

⚠️ Before the first upgrade to SFOS 21 or later: Go to Certificates > Certificate authorities and search for the reserved Let’s Encrypt CA names. An existing entry with exactly the same name can stop the migration because of NC-146082. Don’t delete the CA blindly; first secure and check the backup, private key, dependent certificates, and services.

License and support

Starting with SFOS 19.0 MR1, three free moves to GA, MR, or EAP versions are available without Enhanced Support or Enhanced Plus Support. Afterwards, the firmware can still be downloaded but not installed; Install is disabled.

Pattern updates, hotfixes, reimages, mandatory firmware upgrades, and assistant firmware upgrades are exempt from this support rule. Before the maintenance window, still verify that:

  • Administration > Licensing shows the expected license and support entitlement.
  • Sophos Central lists the correct firewall and serial number.
  • The target version and download are available.
  • Support access, contacts, and the escalation path are known.

If external access is needed for the change, test it beforehand. For Avanet, see Set up support access to Sophos Firewall.

Prepare backup, recovery, and evidence

Backup, SSMK, and firmware slots

Download a fresh configuration backup before the update and verify which Secure Storage Master Key belongs to it. Also record the backup password, administrator access, active firmware version, and target version in the change.

Sophos Firewall keeps no more than two firmware versions: one active and one inactive. Each partition has its own configuration state. A rollback therefore activates not only the previous firmware but also its configuration. Changes made after the upgrade can be lost when reverting.

Automatic rollback is available from SFOS 20.0 for certain configuration migration failures. It is a safety feature, but it does not replace a backup or root-cause analysis and is unavailable for an unsupported upgrade path.

The complete process is covered in Back up or restore Sophos Firewall. If a normal version change is not possible, see Reimage Sophos Firewall OS with a USB drive.

Define rollback criteria in advance

Before starting, define how long an issue will be analyzed and when recovery begins. A rollback makes sense when WAN, HA, central VPNs, or production-critical published services cannot be stabilized within the agreed window. For a single rule, object, or external service, targeted troubleshooting is often better.

For a normal maintenance release, a backup, screenshot of the firmware page, maintenance window, and test result are sufficient evidence. For larger changes, Sophos Firewall Config Studio helps compare configurations, while the audit trail records changes during the maintenance window.

Check system health, storage, and HA

Storage and SSD

Before a larger upgrade, check in WebAdmin that:

  • Control center shows no unresolved critical warnings.
  • Backup & Firmware > Firmware shows the expected firmware slots.
  • Diagnostics > Log viewer contains no recurring system or migration errors.
  • Relevant services are stable.
  • Firewall Health Check contains no open findings that affect the change.

After signing in through SSH, open Device Management > Advanced Shell and check the free storage:

df -kh

If a partition is almost full, do not blindly delete files, logs, or reports in the Advanced Shell. First identify the cause and use the documented cleanup method. See Check Sophos Firewall storage and manage reports.

SFOS 22 may require additional storage. Some XGS models must also receive an SSD firmware update first; WebAdmin displays a notification when this is required. In an HA cluster, each node is assessed separately. If one appliance does not meet the requirements, it can block the entire upgrade.

For older appliances or I/O, database, and reporting issues, also check SSD health with SMART. Without a specific finding, manual changes to databases or file systems are not a useful preparation step.

HA cluster

HA does not need to be disabled for a normal firmware update. Before approval, however, both appliances must be connected, synchronized, and clearly identifiable as primary and auxiliary. An HA update still needs a maintenance window because failover can briefly interrupt individual sessions, VPN tunnels, or pings.

Before starting, document:

  • Roles, HA status, and synchronization.
  • HA link health.
  • Firmware, storage, and SSD requirements for both nodes.
  • Alternative management access.
  • Expected failover and possible brief interruptions.

Do not update the auxiliary appliance separately. The implementation article explains the exact sequence of auxiliary update, failover, and update of the previous primary. Additional HA scenarios are covered in Sophos Firewall HA cluster: variants and maintenance.

Pattern updates are installed on the primary and then synchronized to the auxiliary. Hotfixes and their status must be considered separately and checked on both devices after the maintenance window.

Plan the maintenance window, Central, and tests

Maintenance window and access

A maintenance window covers more than the installation time:

  • Start time, latest cutoff, and rollback decision.
  • Owners for the firewall, network, servers, applications, and support.
  • Local contact, out-of-band access, or a second management path.
  • Communication path if WAN or remote access fails.
  • Maintenance mode for monitoring and alerting.
  • Test sequence for the most important business processes.

For remote sites, do not rely solely on Sophos Central or the existing VPN connection. If that exact path fails during the update, a defined access or escalation route must remain available.

Schedule firmware through Sophos Central

Central-managed firmware upgrades are prepared and monitored under My Products > Firewall Management > Firewalls. The Task Queue is for group policies and MDR/API configuration tasks and does not show firmware upgrades.

Only target versions that have reached the Available to all phase of the release process can be installed through Central. Scheduled updates start according to the timezone set on the firewall, not the administrator’s browser time. For international sites, record the timezone, local maintenance window, and target version in the change.

A status icon spins next to the firewall during the upgrade and disappears when it finishes. The active firmware version must still be checked locally afterwards. If an automatic rollback occurs, Central shows a corresponding message next to the firmware version.

Real functional tests

A ping alone does not prove that the firewall works correctly after the update. Define specific tests in advance with source, destination, and expected result:

  • Internet access and DNS resolution.
  • DHCP, VLANs, WAN uplinks, and SD-WAN routes.
  • Site-to-site VPN, remote access VPN, and RED.
  • Firewall rules, NAT, and published services.
  • WAF, Web Protection, and TLS Inspection.
  • LDAP, RADIUS, Microsoft Entra ID, and other central authentication.
  • Mail flow and business-critical applications.
  • Syslog, SIEM, and monitoring.

Validate after the update

After the restart, first check the active version and expected inactive slot under Backup & Firmware > Firmware. Then:

  • Check Control center for new warnings or an automatic rollback.
  • Verify interfaces, WAN, SD-WAN, HA roles, and synchronization.
  • Validate VPNs, RED, DNS, DHCP, rules, NAT, WAF, and authentication with the prepared tests.
  • Check pattern and hotfix status.
  • Verify Sophos Central synchronization as well as monitoring, syslog, and SIEM.
  • Record the result, times, deviations, and any follow-up work in the change.

If a single function fails, first use Log Viewer, Policy Test, Packet Capture, and the relevant service logs. See Test a firewall rule with Log Viewer, Policy Test, and Packet Capture and Sophos Firewall troubleshooting: services and logs.

FAQ

How often should Sophos Firewall firmware updates be installed?

Security fixes and maintenance releases should not be left pending unnecessarily. A planned schedule with a release notes review, test plan, and rollback plan is better than spontaneous updates.

Is a backup required before every firmware update?

Yes. Even when rollback is available, a fresh backup and the matching Secure Storage Master Key should be ready.

Can a firmware update be installed without Enhanced Support?

Starting with SFOS 19.0 MR1, three free GA, MR, or EAP moves are available without support. Afterwards, the firmware can be downloaded but not installed.

Must HA be disabled before a firmware update?

No. However, the cluster must be connected and synchronized, both nodes must meet the requirements, and a maintenance window is still required.

What is the difference between rollback and reimage?

A rollback starts an existing compatible firmware partition with its configuration state. A reimage installs Sophos Firewall OS from scratch and requires a restore afterwards.