Transfer a Sophos Firewall license to a replacement device
When a Sophos Firewall is replaced, the paid subscription must move from the previous serial number to the new firewall. In Sophos Central, this operation is called Transfer subscriptions. It transfers the license, but neither the local configuration nor the Central management registration.
For a typical replacement, use this order:
- Verify the old and new serial numbers, models, Central account, and HA roles.
- Secure a current backup, the encryption password, and the Secure Storage Master Key.
- Claim the new firewall in the same Sophos Central account.
- For an RMA, check the offered automatic transfer; otherwise use Transfer subscriptions.
- Verify the subscription and expiry date on the destination firewall and synchronize the license in SFOS.
- Restore the configuration separately and test production operation.
⚠️ During an RMA transfer, Sophos warns that the old firewall will become unusable. The serial numbers, backup, and recovery path must therefore be correct before confirmation. A license transfer is not a configuration backup.
Choose the correct transfer first
Sophos Central offers several similarly named operations. They solve different tasks:
- Transfer subscriptions moves paid licenses between two firewalls in the same Central account. This article explains that workflow.
- Transfer firewalls moves the claim and license assignment to another Central account. For that, use Transfer Sophos Firewall to another Sophos Central account.
- Activate subscription redeems a new Subscription Key. This is described in Activate a Sophos Firewall license key.
- Backup and restore transfers the SFOS configuration. It is independent of the license transfer.
The serial number connects the hardware, claim, and license status. Before every step, clearly document the serial numbers of both firewalls. The display name or location alone isn’t a reliable check when devices are similar.
Prerequisites before the transfer
The destination firewall must first be claimed in the same Sophos Central account. Sophos also specifies three fixed limits for a manual subscription transfer: The firewalls must be the same model or one that Sophos accepts as equivalent, evaluation subscriptions can’t be transferred, and Hardware as a Service devices are excluded.
If the destination doesn’t appear under Transfer to, or model equivalence is unclear, don’t experiment with another serial number or a second account. First compare the license documents, both serial numbers, and the RMA or replacement order with the Sophos partner or Support.
Prepare the technical migration in parallel. This includes a current Sophos Firewall backup and restore test, required certificates, WAN credentials, a maintenance window, and a fallback plan. For HA, identify the Initial Primary, current Primary, and Auxiliary before the license step.
Transfer the subscription to the destination firewall manually
This workflow is suitable for a regular hardware replacement or when the automatic RMA transfer isn’t offered:
- Open the profile icon in Sophos Central.
- Go to Licensing > Firewall licenses.
- Find the source firewall by serial number and expand its details row.
- Select Transfer subscriptions.
- If required, select the option to show firewalls that already have paid licenses.
- Under Transfer to, select the destination firewall by its new serial number.
- Confirm with Finish. If subscriptions overlap, Central displays an additional confirmation dialog.
- Find the destination firewall again, expand its details, and verify the subscription and term.
A destination firewall that already has a license isn’t a reason to confirm the overlap dialog blindly. First establish which terms and modules are expected after the transfer. Stop the process and clarify the license assignment if the details conflict.
Claim an RMA replacement and check the license transfer
For an RMA recognized by Sophos, the license transfer can be offered while claiming the replacement device. In Sophos Central, open Licensing > Firewall licenses, select Claim firewall, enter the new serial number, and click Validate. The dialog warns that the license will be transferred to the replacement device and that the old firewall can no longer be used. Only after checking both serial numbers should the transfer be confirmed and Claim firewall executed.
The automatic dialog only appears when Central recognizes the matching RMA case. According to the SFOS 22 help, automatic transfer may not occur when the registrants don’t match, a serial number was recorded incorrectly in the RMA case, the replacement isn’t the same model, or the faulty device wasn’t registered. In that case, first claim the replacement and then carry out the manual subscription transfer in a controlled manner.
After the RMA transfer is complete, the faulty device is deregistered. Verify this state and the replacement firewall’s license details before returning it. The complete hardware workflow, including diagnosis, Support case, restore, and return, is described in Prepare a Sophos hardware defect, RMA, and replacement.
Apply a paid license to an existing virtual trial firewall
Sophos documents a special workflow for a virtual firewall with a trial serial number. Claim the newly purchased firewall with its new serial number in the same Central account. Then transfer the paid subscriptions from that new serial number to the existing virtual firewall with the trial serial number.
This doesn’t transfer the evaluation subscription to another device. Instead, the paid subscription moves to the existing VM, and the newly claimed serial number is deleted during the operation. The virtual firewall therefore doesn’t need to be reinstalled. Check source and destination serial numbers especially carefully before confirmation.
Assign the HA license correctly
For active-passive HA, the licenses belong to the Initial Primary, according to Sophos. If they were assigned to the Auxiliary by mistake, they must be transferred to the Initial Primary. The display name Primary alone isn’t sufficient because the current role can change after a failover.
Active-active and active-passive have different licensing requirements. First compare the serial numbers, Initial Primary, current status, and license model with Sophos Firewall HA variants and licensing. Don’t use a transfer as an attempt to repair an unclear HA state.
Validate the license and replacement device
After the transfer, verify the expected subscriptions and terms under the destination serial number in Sophos Central. On the firewall, check the license status under Administration > Licensing and run Synchronize if required. The required modules must appear as active or Subscribed.
Then perform the technical acceptance separately from the license check:
- Restore the backup on the intended firmware and destination model.
- Check interfaces, zones, routing, DNS, NAT, firewall rules, and VPN connections.
- Check Central management and reporting separately; a claim or license transfer doesn’t automatically register these services again.
- Wait for pattern and license synchronization, then verify protection modules with a controlled test.
- For an RMA, confirm that the faulty firewall is deregistered.
A visible expiry date in Central doesn’t prove a working traffic path. Conversely, an initially outdated display in SFOS doesn’t automatically mean that the transfer failed. Only synchronization, license details, and a real functional test together provide reliable acceptance.
When the license transfer doesn’t work
The destination firewall is missing from the list
First check whether the new firewall is claimed in the same Central account. Then verify the model, serial number, evaluation status, and HWaaS status. Don’t work around a missing or unclear model combination through an invented intermediate transfer.
The automatic RMA transfer doesn’t appear
Compare the RMA number and the old and new serial numbers with the Support case. If the registrant, model, or registration doesn’t match the case, a manual transfer may be required. Don’t return the old firewall until the claim, license details, and deregistration are resolved.
Central shows the license, but SFOS doesn’t
First run Synchronize under Administration > Licensing. If the status remains incorrect, check internet access, DNS, system time, and licensing.log. The detailed workflow is in Activate and synchronize Sophos Firewall licenses.
The replacement device has no configuration
This isn’t a license-transfer error. Transfer the configuration separately through backup and restore or as part of a planned migration. Stop the recovery if no compatible backup, password, and, where required, Secure Storage Master Key are available.