Check reserved ports on Sophos Firewall
Sophos Firewall reserves certain ports for internal system services. These ports remain reserved even when the corresponding service is not currently in use. A reserved port therefore cannot simply be assigned to another firewall feature.
This is particularly important when planning a custom port for WebAdmin, VPN Portal, SSL VPN, WAF, a proxy, or another local service. Before the change, compare the required port with the following SFOS 22 list.
⚠️ An available port is not a security authorization. Reachability, WAN IP address, protocol, Device Access, port sharing, upstream NAT, and firewall rules must still be planned and tested separately.
Reserved ports in SFOS 22
The following list corresponds to the public Sophos Firewall 22.0 help. Ranges include both endpoints.
| Port | Port | Port |
|---|---|---|
4 | 11 | 22 |
23 | 24 | 25 |
41 | 53 | 58 |
109 | 142 | 161 |
179 | 197 | 198 |
273 | 299 | 300 |
414 | 415 | 417 |
418 | 419 | 464 |
500 | 514 | 546 |
547 | 885 | 886 |
992 | 994 | 1211 |
1415 | 1701 | 1723 |
1813 | 2121 | 2600 |
2709 | 2712 | 2718 |
2727 | 2736 | 2745 |
2754 | 2755 | 3001 |
3306 | 3400 | 3410 |
4128 | 4455 | 4500 |
4501 | 5432 | 5433 |
5434 | 5555 | 5685 |
5900–6000 | 6009 | 6060 |
6061 | 6177 | 6277 |
6379 | 6783 | 6789 |
7830 | 7831 | 8005 |
8009 | 8088 | 8089 |
8090 | 8091 | 8347 |
8384 | 9006 | 9090 |
9091 | 9092 | 9595 |
9687 | 9922 | 11001–11010 |
25315 | 25316 | 36878 |
39175 | 43076 | 49093 |
65001–65039 | 65123 | 65353 |
The list deliberately does not state which internal process uses every individual port. The product boundary is sufficient for port selection: if the required value appears here, choose another port. Restarting a service or disabling a suspected feature does not release it.
Select a custom port safely
- Document the intended WAN IP address, protocol, and port. TCP
8443and UDP8443are different combinations. - Check the port against the reserved list.
- Review existing local services and port sharing between WebAdmin, portals, WAF, and SSL VPN.
- If an upstream router or load balancer exists, check its NAT and listener configuration.
- Make the change in a maintenance window, test the service positively from the intended source zone, and test it negatively from a zone that must not have access.
Connections that the firewall itself establishes to Sophos services are a different question. The required destinations and ports are listed under Allow outbound Sophos services and ports.
Typical errors
The required port cannot be saved
First check whether the port is reserved. Then review active services and port sharing. A normal firewall rule cannot resolve a collision between local services.
The port is not reserved but cannot be reached externally
The error is then not automatically related to this list. Check Device Access or a Local Service ACL Exception, WAN IP address, protocol, upstream NAT, provider filtering, and the service that is actually running. An open TCP test does not yet prove a working login or VPN connection.
Old profiles stop working after a port change
Exported VPN profiles, saved URLs, monitoring, and port forwarding often contain the previous port. Update these dependencies after the change and test them with a new connection.