Check reserved ports on Sophos Firewall
Sophos Firewall reserves certain port numbers for internal system services. They remain reserved even when the corresponding service is not in use. If the required port appears in the list below, choose a different one for the local firewall function.
This matters when planning a custom port for WebAdmin, User Portal, VPN Portal, SSL VPN, WAF, a proxy, or another service on the firewall. The reservation is only the first check: an unreserved port may already be used by another service or may open an unexpected access path through port sharing.
⚠️ An unreserved port is not a security authorization. Reachability, WAN IP address, protocol, Administration > Device access, port sharing, and upstream NAT must still be planned and tested separately. Forwarded traffic also needs the appropriate firewall rules; those rules don’t control access to local system services.
Reserved ports in SFOS 22
The following list matches the Sophos Firewall 22.0 state checked on September 4, 2026. Ranges include both endpoints.
| Port | Port | Port |
|---|---|---|
4 | 11 | 22 |
23 | 24 | 25 |
41 | 53 | 58 |
109 | 142 | 161 |
179 | 197 | 198 |
273 | 299 | 300 |
414 | 415 | 417 |
418 | 419 | 464 |
500 | 514 | 546 |
547 | 885 | 886 |
992 | 994 | 1211 |
1415 | 1701 | 1723 |
1813 | 2121 | 2600 |
2709 | 2712 | 2718 |
2727 | 2736 | 2745 |
2754 | 2755 | 3001 |
3306 | 3400 | 3410 |
4128 | 4455 | 4500 |
4501 | 5432 | 5433 |
5434 | 5555 | 5685 |
5900–6000 | 6009 | 6060 |
6061 | 6177 | 6277 |
6379 | 6783 | 6789 |
7830 | 7831 | 8005 |
8009 | 8088 | 8089 |
8090 | 8091 | 8347 |
8384 | 9006 | 9090 |
9091 | 9092 | 9595 |
9687 | 9922 | 11001–11010 |
25315 | 25316 | 36878 |
39175 | 43076 | 49093 |
65001–65039 | 65123 | 65353 |
Sophos publishes these reservations as port numbers and gives no protocol-specific exception. Do not try to work around a reservation by switching from TCP to UDP. Restarting a service or disabling a suspected feature does not release the number either.
Reserved, unique, or shared?
These checks address different problems:
For collision checks, the protocol and port form the combination: TCP 8443 and UDP 8443 are different combinations. A product reservation, by contrast, applies to the port number itself.
- Reserved: No local firewall function can take a number from the list above.
- Must be unique: Web admin console and User portal each require a unique port. Their defaults are TCP
4444and TCP4443. - Restricted port sharing: WAF, VPN Portal, and SSL VPN may share port combinations only under Sophos’s restrictions. If VPN Portal and SSL VPN use the same port and protocol, login security settings do not work and VPN Portal becomes reachable from SSL VPN’s allowed zones. WAF must differ from VPN Portal and SSL VPN in at least its WAN IP address, port, or protocol.
See port sharing between WebAdmin, portals, WAF, and SSL VPN for the full decision guide. The reserved-port list does not replace this collision check.
Change and verify a custom port
1. Record the current state and dependencies
Before the change, record the current port, protocol, WAN IP address, and the zones allowed in Administration > Device access. Also inventory upstream NAT/listener rules, saved URLs, monitoring checks, and distributed VPN profiles. This provides an exact route back to the previous state.
The main port fields are located at:
- Administration > Admin and user settings > Admin console HTTPS port
- Administration > Admin and user settings > User portal HTTPS port
- Administration > Admin and user settings > VPN portal HTTPS port
- Remote access VPN > SSL VPN > SSL VPN global settings > Protocol and Port
A candidate such as TCP 10443 is only an adaptable example. It is not in the SFOS 22 list, but it must still be checked against all configured local listeners, port-sharing conditions, and upstream devices.
2. Check access and port sharing before saving
For direct access to local management services, Administration > Device access controls the allowed zones. A normal firewall rule cannot grant this access or resolve a collision between local services. To permit only a specific host or network, use a Local service ACL exception rule rather than broad zone access.
⚠️ Separate web-proxy path: SFOS treats HTTP and HTTPS requests from the firewall’s web proxy as internal, not as requests from the client zone. Denying the service for that zone under Administration > Device access therefore does not isolate this proxy path. Users with proxy access may be able to reach local HTTPS services such as WebAdmin or the portals through it. This concerns reachability, not a bypass of sign-in or SSL VPN tunnel access. The portal overview explains this Device Access exception.
For SSL VPN, also check Override hostname, WAN forwarding, and existing client configurations. The global SSL VPN settings are included in the imported .ovpn file, so affected clients need an updated configuration after a port change.
3. Test positively, negatively, and at application level
After saving, test the actual service rather than only checking for an open TCP port:
- Connect from an allowed source zone using the complete new URL or a newly imported VPN configuration.
- Verify the sign-in or tunnel establishment and the required function.
- Run a negative test from a disallowed zone. Especially with a shared port and protocol, confirm that no second local service has become reachable unexpectedly.
- Update monitoring, bookmarks, and upstream forwarding to the new value, then test again.
A value accepted by the interface only proves that the setting could be saved. It does not prove external reachability or a successful sign-in or VPN connection.
The positive and negative tests for direct access remain necessary. If clients can use the firewall’s web proxy, also test the complete new HTTPS URL of the WebAdmin or portal service actually changed through that specific proxy: from the actual client zone and against the intended access expectation. Record whether the service is reachable through the proxy and whether this matches the planned allow or deny. A rejected direct connection does not prove isolation of this separate path; a reachable sign-in page does not yet prove a successful sign-in.
4. Restore the previous state if validation fails
If the application-level test fails, enter the previously recorded port and original protocol in the same field. Restore NAT/listener rules, profiles, URLs, and monitoring to their old values, then repeat the positive and negative tests. A rollback should restore the complete previous state, not merely use another reachable replacement port.
Connections that the firewall itself establishes to Sophos services are a different question. See allow outbound Sophos services and ports for the required destinations and ports.
Typical errors
The required port cannot be saved
First check the port number, including all three ranges, against the reserved list. Then review active local services and port sharing. An available TCP socket test or a normal firewall rule cannot override a product reservation.
The port is not reserved but cannot be reached externally
The error is then not automatically related to this list. Check Administration > Device access, existing local service ACL exceptions, WAN IP address, protocol, upstream NAT, provider filtering, and the service that is actually running. For SSL VPN, Override hostname must match an address clients can reach.
Old profiles stop working after a port change
Exported VPN profiles, saved URLs, monitoring, and port forwarding may still contain the previous port. Update these dependencies or restore all of them to the recorded old value during rollback.