Skip to content
Avanet

Replace corrupt Sophos Firewall firmware with SFLoader

If the active firmware is corrupt and WebAdmin no longer starts, SFLoader can transfer a compatible firmware image to the firewall through temporary browser access. This path doesn’t repair an ordinary configuration error. It is a recovery procedure for appliances on which SFLoader is actually available.

⚠️ Important: SFLoader isn’t available on XGS appliances. Restore an XGS with corrupt firmware using the USB reimage procedure. If Factory rather than Migrate is selected later in SFLoader, the firewall starts with the factory configuration. Don’t make this decision under pressure without a verified backup, password, and SSMK.

SFLoader in twelve steps

  1. Obtain a matching, compatible .gpg firmware image from Firewall Installers.
  2. Have the backup, backup password, SSMK, management details, and local recovery access ready.
  3. Connect the endpoint to the firewall’s serial port with a console cable and verify the terminal connection.
  4. Restart the firewall, select SFLoader in the boot menu with the arrow keys, and press Enter.
  5. If the loader is outdated, first run 4 Upgrade Loader. Visible menu options aren’t automatically supported.
  6. Select 1 Load New Firmware.
  7. Configure network access under 1 Network Device, select 1 Port1, and set an address using 1 Enable DHCP or 2 Manual IP settings.
  8. Select Upload firmware using your desktop browser.
  9. On the connected endpoint, open http://<SFOS device IP address>, select the .gpg image with Choose file, confirm with Open, and transfer it with Send.
  10. In the serial SFLoader session, select the firmware to overwrite and confirm Overwrite.
  11. Deliberately choose Migrate for the configuration of the firmware that isn’t being overwritten, or Factory for the factory configuration, and confirm with OK.
  12. Complete the confirmations with Enter, wait for the restart, and sign in with the password of the migrated configuration or, after Factory, with admin.

The decisive moment isn’t the upload, but step 11. Migrate attempts to apply the configuration from the other firmware partition to the new image. Factory discards this path and starts with the default configuration. If it isn’t clear which partition will be overwritten or which configuration must be retained, stop before Overwrite or Factory.

When SFLoader is appropriate

SFLoader is appropriate when the firmware is corrupt, WebAdmin is no longer accessible, and the appliance’s boot menu offers the loader. For a regular upgrade, downgrade, or rollback, the normal SFOS firmware procedure remains the more controlled path.

The recovery paths differ significantly:

  • WebAdmin accessible: upload a compatible image normally and boot it in a planned manner.
  • Previous firmware partition functional: assess a controlled rollback.
  • SFLoader present, WebAdmin unavailable: replace the corrupt firmware using SFLoader.
  • XGS or a complete reinstallation required: use a USB flash drive to reimage.
  • Only reset the configuration: assess the separate factory reset procedure.

SFLoader doesn’t update automatically. An older loader may still show menu items that are no longer supported for the platform or firmware in use. If required for the current image, run 4 Upgrade Loader first; a visible menu item alone isn’t approval.

Prepare the recovery

The firmware image must match the appliance and active version path. Obtain the file only from the official Firewall Installers area. A .gpg image found by chance in an old download folder isn’t a reliable recovery file.

Before the restart, document the following wherever still possible:

  • model, serial number, active firmware version, and previous firmware version
  • HA role and state of the affected node
  • backup file, encryption password, and matching SSMK
  • management IP address, port assignment, WAN access, and local console access
  • intended Migrate or Factory decision and recovery path

In an HA cluster, SFLoader isn’t a normal orchestrated cluster upgrade. Work only on the node that is actually affected, record roles and firmware versions beforehand, and don’t put both devices into recovery at the same time. After startup, verify cluster state, roles, and synchronization again.

Configure serial and temporary network access

SFLoader is operated through the serial console. After the restart, select SFLoader in the boot menu. If the menu doesn’t respond, check the terminal connection, console cable, and serial port instead of repeatedly powering the appliance off abruptly.

For the image upload, SFLoader provides temporary HTTP access through Port1. Under 1 Network Device > 1 Port1, obtain the address through DHCP or set it statically with 2 Manual IP settings. The endpoint and Port1 must then be able to reach each other directly or through a deliberately prepared local network.

Open the upload page explicitly over HTTP:

http://<SFOS device IP address>

<SFOS device IP address> is a placeholder. Replace it with the Port1 address shown in SFLoader or set manually. This local recovery path doesn’t require internet access, a proxy, or broad production network access.

Transfer firmware and select the configuration

After selecting Upload firmware using your desktop browser, choose the compatible .gpg image on the local upload page with Choose file and transfer it with Send. Don’t disconnect power, the serial connection, or the network link during the transfer.

After the transfer is complete, continue in the serial session. Select the firmware to overwrite and confirm Overwrite. Two fundamentally different paths are then available:

Migrate

Migrate loads the configuration from the firmware partition that isn’t being overwritten and migrates it into the new image. This path is appropriate when the configuration state there is known and intended as the starting point. After the restart, use the password of that migrated configuration.

Factory

Factory starts the new image with the factory configuration. This path is more destructive and must not be used as a quick test. After startup, the default password is admin; Basic Setup or a controlled restore is then required. The backup and restore guide explains why the file, password, and SSMK are required together.

Verify success after the restart

A completed upload doesn’t yet prove that the firmware and configuration are usable. After the restart, first confirm the active version, sign-in, and selected configuration path. Then run the operational tests:

  • management access through the intended port and expected IP address
  • interfaces, zones, gateways, DNS, and NTP
  • firewall, NAT, SD-WAN, and routing paths
  • IPsec, remote access, RED, and other site connections
  • in HA, roles, status, firmware versions, and synchronization
  • licensing, patterns, hotfixes, logs, and the Sophos Central connection

For Migrate, also verify that configuration migration, certificates, secrets, and dependent services work completely. For Factory, commission the device like an unconfigured firewall; don’t release production cables or tunnels until the restore or Basic Setup has been verified.

Safely isolate common errors

SFLoader is missing from the boot menu

On XGS, this is expected product behavior rather than a hidden menu error. Don’t experiment with old loader instructions there; use the reimage path. On another appliance, verify the model and official recovery path again.

Upload page isn’t accessible

Check the address and subnet mask from SFLoader, the link on Port1, the endpoint address, and the explicit http:// request. A browser proxy or endpoint VPN can interfere with local access. Don’t connect the firewall broadly to the production network merely to make the recovery page accessible.

Firmware is rejected

The image may be incompatible or corrupt. Recheck the model, serial number, and version path under Firewall Installers, then download a fresh file from Sophos. Don’t rename an image or force an undocumented loader option.

Migration or startup fails

Don’t repeatedly switch between Migrate, Factory, and different images. Save the console output, selected partition, image filename, model, serial number, and time. Then open a Sophos support case with the documented recovery sequence.

Checklist

  • SFLoader is available on the affected appliance; XGS is excluded.
  • The compatible .gpg image comes from Firewall Installers.
  • The serial console and local access to Port1 work.
  • If required, 4 Upgrade Loader was run before the firmware upload.
  • The firmware to overwrite and the Migrate or Factory decision are documented.
  • Backup, password, SSMK, and management details are available.
  • Upload, restart, active firmware, and sign-in were confirmed.
  • Network, VPN, HA, licensing, patterns, and logs were tested in practice.
  • If the result was unclear, further overwrite attempts were stopped and evidence was saved.

FAQ

Can SFLoader be used on an XGS Firewall?

No. Sophos doesn’t provide SFLoader on XGS. For corrupt XGS firmware, reimaging with a bootable USB flash drive is the intended recovery path.

What is the difference between Migrate and Factory?

Migrate applies the configuration from the firmware partition that isn’t being overwritten to the new image. Factory starts with the default configuration and then requires Basic Setup or a controlled restore.