Skip to content
Avanet

Replace corrupt Sophos Firewall firmware with SFLoader

If the active firmware is corrupt and WebAdmin no longer starts, SFLoader can transfer a compatible firmware image to the firewall through temporary browser access. This path doesn’t repair an ordinary configuration error. It is a recovery procedure for appliances on which SFLoader is actually available.

⚠️ Important: SFLoader isn’t available on XGS Appliances. Restore an XGS Appliance with corrupt firmware using the USB reimage procedure. SFLoader overwrites the selected firmware partition. Factory additionally starts the new image with the factory configuration. Don’t begin without a verified recovery path; a backup can only be restored if you also have its encryption password and, if that backup uses one, the matching SSMK.

SFLoader in twelve steps

  1. Obtain the compatible .gpg firmware image using Sophos’s Download firmware workflow for the active firewall.
  2. Confirm that SFLoader is available on the appliance and, for a version change, that a valid support entitlement or one of the three free firmware upgrades remains.
  3. Prepare the recovery path, management details, and local access. Connect the endpoint to the firewall’s serial port with a console cable and verify the terminal connection. If Factory is possible, also verify the backup, backup password, and SSMK if required.
  4. Restart the firewall, select SFLoader in the boot menu with the arrow keys, and press Enter.
  5. In SFLoader, first run 4 Upgrade Loader. Firmware updates don’t update the loader automatically, and visible menu options aren’t automatically supported.
  6. Select 1 Load New Firmware.
  7. Configure network access under 1 Network Device, select 1 Port1, and set an address using 1 Enable DHCP or 2 Manual IP settings.
  8. Select Upload firmware using your desktop browser.
  9. On the connected endpoint, open http://<SFOS device IP address>, select the .gpg image with Choose file, confirm with Open, and transfer it with Send.
  10. In the serial SFLoader session, select the firmware to overwrite and confirm Overwrite.
  11. Deliberately choose Migrate for the configuration of the firmware that isn’t being overwritten, or Factory for the factory configuration, and confirm with OK.
  12. Complete the confirmations with Enter, wait for the restart, and sign in with the password of the migrated configuration or, after Factory, with admin.

The decisive moment isn’t the upload, but the point before Overwrite and the choice in step 11. Migrate attempts to apply the configuration from the other firmware partition to the new image. Factory discards that migration path and starts with the default configuration. SFLoader can’t simply undo an overwrite. If it isn’t clear which partition will be overwritten, whether the other partition can boot, or which configuration must be retained, stop before Overwrite.

When SFLoader is appropriate

SFLoader is appropriate when the firmware is corrupt, WebAdmin is no longer accessible, and the appliance’s boot menu offers the loader. For a regular upgrade, downgrade, or rollback, the normal SFOS firmware procedure remains the more controlled path.

The recovery paths differ significantly:

  • WebAdmin accessible: upload a compatible image normally and boot it in a planned manner.
  • Previous firmware partition functional: assess a controlled rollback.
  • SFLoader present, WebAdmin unavailable: replace the corrupt firmware using SFLoader.
  • XGS Appliance or a complete reinstallation required: use a USB flash drive to reimage.
  • Only reset the configuration: assess the separate factory reset procedure.

SFLoader doesn’t update automatically. An older loader may still show menu items that are no longer supported for the platform or firmware in use. Run 4 Upgrade Loader before the upload; a visible menu item alone isn’t approval. The menu sequence in this runbook fully captures the supported procedure.

Prepare the recovery

The firmware image must match the appliance and active version path. For an active firewall, Sophos directs you to Sophos Central > Licensing > Firewall licenses, where you select the firewall and its available firmware download. Don’t use the general Firewall Installers page: Sophos labels those files as new-installation images and warns that installing them on an existing device wipes its data and settings. A .gpg image found by chance in an old download folder isn’t a reliable recovery file.

Starting with SFOS 19.0 MR1, moving to another firmware version generally requires Enhanced Support or Enhanced Plus Support. Without a support entitlement, three free firmware upgrades are available; once they are used, the image can still be downloaded but can’t be installed, including through SFLoader. Sophos states that this restriction applies to a version change. Don’t confuse it with a full reimage, for which Sophos doesn’t require a support entitlement.

Before the restart, document the following wherever still possible:

  • model, serial number, active firmware version, and previous firmware version
  • target-image compatibility and entitlement for a version change
  • HA role and state of the affected node
  • backup file, encryption password, and matching SSMK if that backup uses one
  • management IP address, port assignment, WAN access, and local console access
  • intended Migrate or Factory decision and recovery path

In an HA cluster, SFLoader isn’t a normal orchestrated cluster upgrade. The public SFLoader instructions don’t define a standalone HA recovery procedure. Record roles, firmware versions, and console output, then coordinate the intervention with Sophos or your support partner before Overwrite. Never place both nodes into recovery at the same time. After startup, verify cluster state, roles, firmware versions, and synchronization again.

Configure serial and temporary network access

SFLoader is operated through the serial console. Depending on the appliance, use a micro-USB cable or a USB-to-RJ45 or RJ45-to-DB9 console cable. On Windows, identify the assigned port under Device Manager > Ports (COM & LPT). Configure the terminal emulator with that COM port, 38400 baud, 8 data bits, 1 stop bit, no parity, and no flow control.

On macOS, use ls /dev/tty.* to identify the port, then start the session with a command such as screen /dev/tty.usbserial-AD0K15UY 38400, replacing the example port with the detected one. If micro-USB and RJ45 serial cables are connected together, micro-USB takes priority; connect only the required cable to keep the recovery path unambiguous. After the restart, select SFLoader in the boot menu. If the menu doesn’t respond, check the driver, terminal connection, console cable, and serial port instead of repeatedly powering the appliance off abruptly.

For the image upload, SFLoader provides temporary HTTP access through Port1. Under 1 Network Device > 1 Port1, obtain the address through DHCP or set it statically with 2 Manual IP settings. The endpoint and Port1 must then be able to reach each other directly or through a deliberately prepared local network.

Open the upload page explicitly over HTTP:

http://<SFOS device IP address>

<SFOS device IP address> is a placeholder. Replace it with the Port1 address shown in SFLoader or set manually. This local recovery path doesn’t require internet access, a proxy, or broad production network access.

Transfer firmware and select the configuration

After selecting Upload firmware using your desktop browser, choose the compatible .gpg image on the local upload page with Choose file and transfer it with Send. Don’t disconnect power, the serial connection, or the network link during the transfer.

After the transfer is complete, continue in the serial session. Select the firmware to overwrite and confirm Overwrite. Two fundamentally different paths are then available:

Migrate

Migrate loads the configuration from the firmware partition that isn’t being overwritten and migrates it into the new image. This path is appropriate when the configuration state there is known and intended as the starting point. After the restart, use the password of that migrated configuration.

Factory

Factory starts the new image with the factory configuration. This path is more destructive and must not be used as a quick test. After startup, the default password is admin; Basic Setup or a controlled restore is then required. The backup and restore guide explains when the SSMK is required in addition to the file and password.

Recovery path and limits

After Overwrite, SFLoader doesn’t provide a guaranteed one-click rollback. The partition that wasn’t overwritten may still contain its own firmware and configuration, but only rely on it if you confirmed its version, bootability, and associated configuration beforehand. Factory isn’t a preview mode. If there is neither a known bootable second partition nor a compatible backup that you can fully decrypt, a failed startup leaves only the recorded evidence for Sophos Support or a full reimage. Reimaging deletes all data on the firewall.

Verify success after the restart

A completed upload doesn’t yet prove that the firmware and configuration are usable. After the restart, first confirm the active version, sign-in, and selected configuration path. Then run the operational tests:

  • management access through the intended port and expected IP address
  • interfaces, zones, gateways, DNS, and NTP
  • firewall, NAT, SD-WAN, and routing paths
  • IPsec, remote access, RED, and other site connections
  • in HA, roles, status, firmware versions, and synchronization
  • licensing, patterns, hotfixes, logs, and the Sophos Fusion connection

For Migrate, also verify that configuration migration, certificates, secrets, and dependent services work completely. For Factory, commission the device like an unconfigured firewall; don’t release production cables or tunnels until the restore or Basic Setup has been verified.

Safely isolate common errors

SFLoader is missing from the boot menu

On XGS Appliance, this is expected product behavior rather than a hidden menu error. Don’t experiment with old loader instructions there; use the reimage path. On another appliance, verify the model and official recovery path again.

Upload page isn’t accessible

Check the address and subnet mask from SFLoader, the link on Port1, the endpoint address, and the explicit http:// request. A browser proxy or endpoint VPN can interfere with local access. Don’t connect the firewall broadly to the production network merely to make the recovery page accessible.

Firmware is rejected

The image may be incompatible or corrupt. Recheck the firewall identity and available firmware under Sophos Central > Licensing > Firewall licenses, then download a fresh file from Sophos. Don’t rename an image or force an undocumented loader option.

Migration or startup fails

Don’t repeatedly switch between Migrate, Factory, and different images. Save the console output, selected partition, image filename, model, serial number, and time. Then open a Sophos support case with the documented recovery sequence.

Checklist

  • SFLoader is available on the affected appliance; XGS Appliance is excluded.
  • The compatible .gpg image was obtained through Sophos’s download workflow for the active firewall, not from the new-installation images on Firewall Installers.
  • The serial console and local access to Port1 work.
  • 4 Upgrade Loader was run before the firmware upload.
  • The firmware to overwrite and the Migrate or Factory decision are documented.
  • If a restore may be required, the backup, password, and SSMK where applicable are available; management details are documented.
  • Upload, restart, active firmware, and sign-in were confirmed.
  • Network, VPN, HA, licensing, patterns, and logs were tested in practice.
  • If the result was unclear, further overwrite attempts were stopped and evidence was saved.

FAQ

Can SFLoader be used on an XGS Appliance?

No. Sophos doesn’t provide SFLoader on XGS Appliance. For corrupt XGS Appliance firmware, reimaging with a bootable USB flash drive is the intended recovery path.

What is the difference between Migrate and Factory?

Migrate applies the configuration from the firmware partition that isn’t being overwritten to the new image. Factory starts with the default configuration and then requires Basic Setup or a controlled restore.