Skip to content
Avanet

Check reserved ports on Sophos Firewall

Sophos Firewall reserves certain ports for internal system services. These ports remain reserved even when the corresponding service is not currently in use. A reserved port therefore cannot simply be assigned to another firewall feature.

This is particularly important when planning a custom port for WebAdmin, VPN Portal, SSL VPN, WAF, a proxy, or another local service. Before the change, compare the required port with the following SFOS 22 list.

⚠️ An available port is not a security authorization. Reachability, WAN IP address, protocol, Device Access, port sharing, upstream NAT, and firewall rules must still be planned and tested separately.

Reserved ports in SFOS 22

The following list corresponds to the public Sophos Firewall 22.0 help. Ranges include both endpoints.

PortPortPort
41122
232425
415358
109142161
179197198
273299300
414415417
418419464
500514546
547885886
9929941211
141517011723
181321212600
270927122718
272727362745
275427553001
330634003410
412844554500
450154325433
543455555685
5900–600060096060
606161776277
637967836789
783078318005
800980888089
809080918347
838490069090
909190929595
9687992211001–11010
253152531636878
391754307649093
65001–650396512365353

The list deliberately does not state which internal process uses every individual port. The product boundary is sufficient for port selection: if the required value appears here, choose another port. Restarting a service or disabling a suspected feature does not release it.

Select a custom port safely

  1. Document the intended WAN IP address, protocol, and port. TCP 8443 and UDP 8443 are different combinations.
  2. Check the port against the reserved list.
  3. Review existing local services and port sharing between WebAdmin, portals, WAF, and SSL VPN.
  4. If an upstream router or load balancer exists, check its NAT and listener configuration.
  5. Make the change in a maintenance window, test the service positively from the intended source zone, and test it negatively from a zone that must not have access.

Connections that the firewall itself establishes to Sophos services are a different question. The required destinations and ports are listed under Allow outbound Sophos services and ports.

Typical errors

The required port cannot be saved

First check whether the port is reserved. Then review active services and port sharing. A normal firewall rule cannot resolve a collision between local services.

The port is not reserved but cannot be reached externally

The error is then not automatically related to this list. Check Device Access or a Local Service ACL Exception, WAN IP address, protocol, upstream NAT, provider filtering, and the service that is actually running. An open TCP test does not yet prove a working login or VPN connection.

Old profiles stop working after a port change

Exported VPN profiles, saved URLs, monitoring, and port forwarding often contain the previous port. Update these dependencies after the change and test them with a new connection.

FAQ

Does a reserved port become available when its service is disabled?

No. Sophos reserves these ports even when the service is not in use.

Can a firewall rule release a reserved port?

No. Firewall rules control forwarded traffic. The reservation is part of the firewall’s local system configuration.