Set up Let's Encrypt certificates on Sophos Firewall
The integrated Let’s Encrypt feature in Sophos Firewall 22 requests and renews certificates for public FQDNs. It uses HTTP-01 over IPv4. For every validation, the firewall creates a temporary WAF rule; while validation is in progress, web applications protected by WAF rules are unavailable through the firewall.
The configuration and assignment steps shown here apply to SFOS 22. The different renewal timing in SFOS 23 is explicitly covered in the renewal section.
⚠️ Issuance and renewal can therefore interrupt service. Carry out manually initiated changes in a controlled maintenance window for production WAF sites, and account for the version-dependent automatic renewal timing in your operations. The Sophos pages compared here do not document a setting for freely scheduling that automatic renewal. During validation, port
80must not be blocked or sent elsewhere by DNAT, firewall, GeoIP, or upstream rules.
Quick procedure
- Make every FQDN resolve publicly and consistently worldwide to the selected IPv4 address.
- Confirm that inbound HTTP on port
80reaches the firewall and that no DNAT applies to that address and port. - Go to Certificates > Let’s Encrypt, read the terms, and click Register account.
- Go to Certificates > Certificates, click Add, select Request Let’s Encrypt certificate under Action, and complete Name, Domains, and Hosted address.
- After clicking Save, assign the valid certificate to the intended service and test it externally.
- Check the expiry date, port 80 path, and
letsencrypt.logbefore the renewal window.
Uses and limitations
The integration suits services where the firewall presents the certificate, including WAF, WebAdmin, User Portal, the browser-based VPN Portal, Captive Portal, SPX portals, and hotspot sign-in. For the rest of a WAF publication, see Sophos Firewall WAF: Publish web servers securely.
Sophos documents these limits:
- Only public FQDNs and IPv4 are supported.
- Validation uses HTTP-01. This SFOS integration does not accept IP addresses or wildcard domains.
- Remote Access VPN, Site-to-Site VPN, and the Chromebook SSO authentication service cannot use these certificates. The browser-based VPN Portal certificate is a separate setting.
- For SFOS 22, Sophos specifies 90 days of validity and a renewal request when fewer than 30 days remain. In SFOS 23, renewal instead follows the certificate’s actual validity period: the firewall requests renewal once two-thirds of that period have elapsed. This allows the timing to adapt to changes in Let’s Encrypt certificate validity periods.
- Existing certificates stop renewing after Deregister account.
Sophos introduced the integration with SFOS 21. Sophos Firewall v21: The most important new features provides context for its original scope.
Create a wildcard certificate externally with DNS-01; see Create a Let’s Encrypt wildcard certificate. Manage certificates on Sophos Firewall covers imports, private keys, and CA chains. IPv6 support in Sophos Firewall 22 explains other IPv6 boundaries.
Prepare DNS and the network path
Every entry under Domains must meet the same conditions:
- Its public DNS record resolves to the firewall’s WAN IPv4 address or to an address that routes port
80to the firewall. - All public DNS providers return the same address. Region-dependent GeoDNS is unsuitable for this workflow.
- The DNS record should contain one IP address. Sophos only allows multiple addresses when they belong to other firewalls that route HTTP to the requesting firewall.
- Neither a firewall rule nor an upstream device may block inbound port
80. This includes GeoIP rules; Let’s Encrypt validates from many countries and does not publish fixed validation source ranges. - No DNAT may apply to port
80on the firewall’s WAN address. If a router owns the public IP in front of the firewall, that router must instead forward port80to the firewall’s WAN interface. - An SD-WAN route must not send outbound HTTP through a device that prevents access to Let’s Encrypt.
Keep the clock synchronized with NTP. Check DNS and port 80 from outside the local network before requesting a certificate; split DNS or NAT loopback can make an internal test misleading.
Register or deregister the account
- Open Certificates > Let’s Encrypt.
- Read the Subscriber Agreement and terms.
- Click Register account.
Clicking the button accepts the Subscriber Agreement. If the terms change, SFOS requires registration again. Until it is confirmed, new certificates cannot be created and existing ones are not renewed. Sophos sends an administrator email and shows a Control Center alert; configure email delivery under Administration > Notification settings.
Deregister account ends the registration. It does not necessarily remove every existing certificate, but future renewal stops. Confirm replacement certificates, assignments, and expiry dates before deregistering.
Request a certificate
- Open Certificates > Certificates and click Add.
- For Action, select Request Let’s Encrypt certificate.
- Enter a unique Name, such as
le-app-example-com. - Under Domains, add every required FQDN, such as
app.example.com. Do not enter an IP address or*.example.com. - Under Hosted address, select the public IPv4 address of the WAN interface to which the domains resolve.
- Click Save and account for the WAF outage.
- Under Certificates > Certificates, verify that the certificate is valid and trusted and has a plausible Valid until date.
If an FQDN is wrong, remove the failed request and create it again with the correct name. Fix DNS and the port 80 path before retrying rather than repeatedly submitting the same invalid request.
Assign the certificate
Issuance alone does not change a service. SFOS 22 documents these assignments:
- WAF: Edit the WAF rule under Rules and policies > Firewall rules, turn on HTTPS, and select the certificate under HTTPS certificate. Its domains populate the rule. Saving a WAF rule restarts all web server protection rules and drops their live connections.
- WebAdmin, User Portal, VPN Portal, Captive Portal, and SPX portals: Go to Administration > Admin and user settings > Admin console and end-user interaction > Certificate and select the certificate for the relevant service.
- Hotspot: Go to Wireless > Wireless settings > Hotspot settings, choose it under Login page certificate, and click Apply. This certificate is used when Redirect to HTTPS is enabled for the hotspot.
Then open the real FQDN from outside. The certificate name, SNI, WAF domains, and certificate actually served must agree. For SMTP TLS or another feature, only use a certificate selector shown in that feature’s SFOS 22 page; the portal assignments above do not automatically apply to it.
Assign, delete, or roll back safely
Before changing an assignment, record the previous certificate and every affected assignment, take a current configuration backup, and keep an external test path available. Where possible, assign the new certificate to one service first and test that service with its real FQDN. If the test fails, select the previous certificate again in the same service configuration and confirm with Save or Apply. For WAF, remember that this again restarts all web server protection rules and drops active connections.
Do not delete the previous certificate until every affected service has passed an external test and certificate expiry and renewal ownership are clear. Before deletion, change every known service reference to the new certificate or another valid certificate. Treat backup restore as the last rollback option, not the first: it replaces the entire running configuration and restarts the firewall.
Renewal, HA, and backup
Renewal timing depends on the SFOS version: SFOS 22 requests renewal when fewer than 30 days remain; SFOS 23 requests it after two-thirds of the certificate’s actual validity period have elapsed. For operational checks, inspect the specific certificate and its validity period rather than assuming a 30-day threshold for SFOS 23. Both versions still require the working DNS, IPv4, and port 80 path used for initial issuance. Recheck the path after DNS, provider, NAT, GeoIP, SD-WAN, WAF, or firmware changes. A currently valid certificate does not prove that the next validation will work.
Sophos describes backups as encrypted copies of the entire firewall configuration. Take a current backup before certificate or WAF changes. Restoring it replaces the running configuration and restarts the firewall, so check account status, certificates, service assignments, and external delivery afterward.
In an HA cluster, restore a backup to the current primary, never the auxiliary. The primary restarts without failover, causing downtime in both active-passive and active-active HA. If the backup contains the HA configuration, the primary then synchronizes the restored configuration to the auxiliary. If it does not contain an HA configuration, HA is disabled and the auxiliary initially retains its previous configuration; follow Sophos’s documented recovery workflow for that case. Sophos does not document additional Let’s Encrypt-specific account or renewal behavior on the Let’s Encrypt page. After a restore or role change, verify certificate status and perform an external TLS test rather than relying on assumptions.
Validate and troubleshoot
After issuance and every renewal, check:
- public DNS from several regions;
- the entry under Certificates > Certificates;
- the affected service from outside the LAN;
- FQDN, SANs, issuer, expiry, and the full intermediate chain;
- Log viewer, plus
tail -f /log/reverseproxy.logfor WAF; - issuance and renewal events in
letsencrypt.log.
From an external administrator computer, this read-only command shows the certificates sent by the service. Replace app.example.com twice with the real FQDN:
openssl s_client -connect app.example.com:443 -servername app.example.com -showcerts </dev/null
The output must contain the server certificate and required intermediate certificates. The root trust anchor is normally not sent. A second check uses that computer’s trust store:
curl -Iv https://app.example.com/
In the Advanced Shell, follow the official Let’s Encrypt log; press Ctrl+C to stop:
tail -f /log/letsencrypt.log
Sophos lists tail -f /log/vpncertificate.log for general certificate operations and tail -f /log/reverseproxy.log for WAF. SFOS 22.0 MR2 Build 546 added support for YE Root, YE1, YE2, YR Root, YR1, and YR2. If only older clients fail after renewal, inspect their trust stores. If the server omits an intermediate, first check firmware, service assignment, and upstream proxies, then escalate to Sophos Support with the test output.
Common failures can be narrowed down as follows:
- Request fails immediately: Check the public FQDN, globally consistent DNS response, and IPv4 destination.
- Port 80 reaches another system: Remove or correct DNAT on the firewall; if there is an upstream router, check its forwarding to the firewall.
- Failure depends on region: Check GeoIP and provider filters. Do not restrict access to presumed Let’s Encrypt IP lists.
- Failure after a routing change: Check the outbound HTTP SD-WAN route.
- Old certificate is served: Check the service assignment and any upstream load balancer or reverse proxy.
- Renewal does not happen: Check remaining validity, registration, changed terms, and the unchanged HTTP-01 path.
- A dynamic-IP certificate created during EAP does not renew in GA: Delete and recreate this specific certificate in the GA build, as Sophos instructs.
FAQ
Why must port 80 be open?
80; Let’s Encrypt may follow redirects to HTTPS, but the first connection must reach port 80.