Back up and restore Sophos Switch
A reliable Sophos Switch backup is more than an enabled schedule. It must contain the intended configuration, remain available away from the switch, and be restorable during a planned maintenance window. There are two separate paths:
- Sophos Fusion: Manual or scheduled configuration backups are sent from the switch to Sophos Fusion. You can download the latest backup and restore either the latest or a specific backup already held in Fusion.
- Local web interface: Download the configuration as a
.cfgfile over HTTPS to an administration device or transfer it to a TFTP server. Both transports are also available for local restore.
Quick procedure
- Record the target switch, current management path, firmware version, and critical services.
- Confirm that every required change is already active on the switch.
- Request a current manual Fusion backup with an unambiguous tag, or export a local
.cfgfile. - In Fusion, also configure a schedule with frequency, time, retention count, and at least one tag.
- Download the latest Fusion backup as an offline copy and store every file securely.
- Before restoring, recheck the backup, target switch, and expected state.
- Run the restore, validate reachability and configuration, and return to a known state if results differ.
Understand scope and limitations
Scheduled Fusion backups contain settings configured on the switch since the previous scheduled or manual backup. Settings present on the device from every source are considered: Sophos Fusion, local configuration, CLI, and APIs. Fusion cannot identify the source of a setting inside the backup.
The effective state on the switch is decisive. A configuration made in Sophos Fusion but not yet synchronized to the switch is not included. Conversely, local changes are not synchronized to Sophos Fusion as central configuration. Their inclusion in a device backup does not turn them into Fusion-managed settings.
Additional limitations:
- Fusion explicitly downloads the latest backup of a switch.
- To restore an older state, that backup must still exist in Fusion’s backup history.
- Keep maximum of [number] backups per switch limits the number retained in Fusion and therefore does not replace a deliberately managed offline repository.
- The local workflow uses a
.cfgfile over HTTPS or TFTP. It is a separate restore path and is not documented as an import route for a backup downloaded from Fusion. - A backup alone does not prove that management, VLANs, uplinks, and endpoints work after restoration. Verify them afterward.
Prerequisites, permissions, and backup plan
For the cloud path, the switch must be registered, connected, and visible in the correct Sophos Fusion organization. Registration and licensing are separate: registration is possible without a valid subscription, but management through Sophos Fusion requires a valid Sophos Switch Support and Services subscription. See Register Sophos Switch in Sophos Fusion.
Sophos backup pages require sign-in to Sophos Fusion but specify neither an administrator role for backup operations nor a separate backup license. Do not assign a full-administrator role preemptively. With the intended account, verify that Backup, Request a backup, Schedule, Download latest backup, and the restore actions are visible; use only a role that actually covers the task in your permission model.
The local path requires web-interface access and a local Admin account; a local User account can only view settings. Local and Fusion roles are separate. Depending on the method, you also need a browser download or a TFTP server reachable by the switch.
Before backup or restore, record:
- serial number, model, location, and unique name of the target switch;
- current management IP, management VLAN, gateway, and a local or otherwise independent access path;
- current firmware and expected configuration state;
- last successfully synchronized Fusion configuration and known local, CLI, or API changes;
- critical uplinks, LAGs, VLANs, Layer 3 interfaces, STP role, PoE consumers, and management ports;
- maintenance window, expected outage, abort time, and responsible person;
- which backup is the starting point and which is the fallback.
For the Fusion path, the switch must receive tasks and return the completed backup. Before backing up, open My Products > Switches > Switches, confirm that the correct device is connected, and ensure no pending synchronization calls the expected state into question. See Operate Sophos Switch fleets, synchronization, sites, and stacks. Before restoring, at least one known readable backup must be available outside the target switch.
Use meaningful tags, such as the change reference and purpose, but no passwords or other secrets. These Sophos pages document neither backup-file encryption nor a complete content list. Do not assume file protection: keep downloads only in an access-controlled backup repository, define retention and deletion, and record a hash after download or copying for later integrity checks. Use an isolated administration path for TFTP; where browser access is available, the documented HTTPS option avoids the additional TFTP service.
Request a manual backup in Sophos Fusion
The documented UI path is My Products > Switches > Backup.
- Sign in to Sophos Fusion and open My Products > Switches > Backup.
- Select the name of the switch to back up.
- Select Request a backup.
- Enter a unique value in Tag.
- Select Request a backup again.
- Fusion creates a task and sends it to the switch. Wait until the task completes and the configuration backup has been transferred to Sophos Fusion.
Clicking the button alone is not proof of backup. Only a completed task and a backup available in Fusion prove the transfer. Request a fresh backup before a risky change rather than relying only on the regular schedule.
Configure scheduled Fusion backups
- Open My Products > Switches > Backup.
- Select Schedule.
- Select Scheduled backups.
- Under Schedule settings, set:
- Frequency:
Daily,Weekly, orMonthly; - At: backup time;
- Keep maximum of [number] backups per switch: maximum backups retained per switch;
- Tags that get attached to each backup: at least one tag.
- Frequency:
- Select Save.
Match frequency to the rate of change. Set retention high enough that several bad or unnoticed changes cannot displace every known-good state. After saving, do not wait for an emergency: after the next scheduled time, confirm that a new, plausibly tagged backup was created.
Pause a schedule for one switch
- Under My Products > Switches > Backup, click the row for the switch.
- Select Actions > Pause schedules.
- Verify the target and details in the dialog.
- Confirm Pause schedules.
Document a pause and set a reactivation date. The described action does not delete a backup, but it prevents further scheduled backups and creates a recovery gap when changes occur.
Download the latest Fusion backup
- Open My Products > Switches > Backup.
- Click the row for the required switch.
- Select Actions > Download latest backup.
- Verify the switch and details in the dialog.
- Select Confirm.
Do not leave the file uncontrolled in the downloads folder. Move it to the protected repository, add the serial number, backup time, and tag to its filename or accompanying record, and capture its hash for later integrity checks. Do not edit it. A successful download neither proves suitability for the planned restore nor provides a documented upload path in Fusion.
Create a local .cfg backup
In the local web interface, open Configure > Firmware > Backup and restore.
- In the first selector, choose Backup.
- Choose the method:
- HTTPS: The backup is downloaded through the browser to the administration device.
- TFTP: Enter the IP address of the TFTP Server to which the switch sends the file.
- Select Apply.
- Trigger the backup by selecting Apply again.
- Confirm that the configuration arrived at the expected destination as a
.cfgfile.
For TFTP, first test server reachability, destination directory, and write permission on an isolated administration network. After transfer, move the file from the TFTP directory to the protected backup repository. With HTTPS, do not bypass browser warnings; verify the switch certificate and destination address.
Prepare a restore safely
Do not assume compatibility
The local Sophos guide describes uploading a .cfg file but provides no compatibility matrix for other models or firmware versions. The Fusion guide likewise describes restoring a backup from the selected switch’s history, not transferring it to any other device. This does not establish a cross-model or cross-version migration path.
For a normal restore, therefore use the same switch and documented firmware version. Before applying a local .cfg to a replacement device, another model, or different firmware, have Sophos confirm that exact combination or test it in a non-production environment. Without confirmation, do not use restore as a migration method.
Immediately before restoring:
- Match the serial number and target switch to the backup again. In Fusion, the serial number also opens the history of specific backups.
- Check backup time, tag, and expected changes. Do not automatically use the latest backup if it may already contain the faulty configuration.
- Back up the current state too, if the switch remains reachable.
- For local restore, check the filename and recorded integrity value. For Fusion restore, check the time and tag of the selected entry; the documented flow offers no comparison with a downloaded file.
- Keep console or local management access ready. An old configuration can restore previous management IP, VLAN, uplink, LAG, or routing values.
- Notify affected users and account for monitoring during maintenance.
- Keep a known-good alternative backup and previous management parameters at hand.
Restore a backup through Sophos Fusion
Latest backup
- Open My Products > Switches > Backup.
- Click the target switch row.
- Select Actions > Restore latest backup.
- In the dialog, select the checkbox to confirm that the switch will restart.
- Select Restore backup.
- Wait for the restart and loading of the latest backup configuration. Expect an outage and do not overlap the task with further configuration changes.
A specific existing backup
If you need a selected state rather than the latest one:
- Under My Products > Switches > Backup, click the switch serial number.
- In the displayed history, select the required backup by time and tag.
- Select Actions > Restore backup.
- Continue only if selection and target match the change.
This interface selects a backup already present in Fusion. Do not assume that a previously downloaded backup can be uploaded again.
Restore a local .cfg file
Open Configure > Firmware > Backup and restore in the local web interface.
- In the first selector, choose Restore.
- Choose the method:
- HTTPS: Select Select file, choose the local
.cfgfile, and confirm with OK. - TFTP: Enter the TFTP server IP address and the backup filename.
- HTTPS: Select Select file, choose the local
- Select Apply.
- Trigger the restore by selecting Apply again.
- Make no further changes until the operation ends and the switch is reachable through the management parameters expected from the backup.
The local vendor guide specifies neither a universal restart step nor a progress indicator for this workflow. Do not force a restart or interrupt power. If the session drops, first try the management address and management VLAN from the restored configuration before declaring failure.
Validation after restore
A reachable web interface is not enough. Systematically compare the restored state with the backup documentation:
- Management: Test expected IP, gateway, and DNS; for Fusion, also check connection and synchronization status.
- Identity and state: Compare serial number, device name, location, firmware, and the selected backup’s time and tag.
- Uplinks: Check link state, speed, LAG/LACP membership, and STP state; watch for loops or unexpectedly blocked paths.
- VLAN and Layer 3: Sample-test tagged/untagged assignment, PVID, management VLAN, VLAN interfaces, routes, and DHCP.
- Access and PoE: Test representative endpoints, authentication, and critical PoE devices.
- Operations: Check alerts, logs, monitoring, and reachability of central services.
- Persistence: Once stable, reread the effective configuration. Restart again only when operationally planned and approved.
- New baseline: After acceptance, create a new manual backup with an unambiguous post-restore tag and refresh the offline copy if required.
Record the outage start and end, backup used, every test result, and deviations. Close the change only after successful data-path and management tests.
Troubleshooting
Fusion backup is not created
- Confirm that the correct switch was selected and Request a backup was confirmed a second time.
- Wait for the created task to complete; a permanently open or failed task is not a backup.
- Confirm that the switch is connected to Fusion and can receive tasks.
- Confirm that expected Fusion changes had synchronized to the switch. Unsynchronized changes are absent even from a subsequently available backup.
- If cloud backup remains unavailable but local access exists, immediately create a local
.cfgbackup rather than proceeding without protection.
Scheduled backup is missing
- Check Scheduled backups, Frequency, At, retention count, and at least one tag.
- Ensure Pause schedules has not paused the schedule for that switch.
- Check the switch’s Fusion connection around the scheduled time.
- Request and download a manual backup until resolved.
Download does not contain the required state
Download latest backup downloads only the latest backup. For an older state, open backup history through the serial number and check whether it remains in Fusion. If retention removed it, the Fusion workflow cannot recover it from an arbitrary offline file. Retain older approved states separately in time.
TFTP backup or restore fails
- Check the TFTP server IP address and, for restore, the exact filename.
- Check reachability from the switch management network, server service, file path, and permissions.
- Investigate firewall or ACL blocks on the isolated transfer path.
- If local browser access works, switch to the documented HTTPS method.
Switch is unreachable after restore
- Use the management IP, VLAN assignment, gateway, and uplink values from the restored state, not only the pre-restore values.
- Check link, LAG, and STP at the peer.
- Use the prepared local or console access and capture the actual device state.
- After a Fusion restore, allow the restart to finish and check task status.
- Do not blindly reapply the same state. If configuration is the cause, follow the fallback procedure and choose an older known-good backup.
Fallback and controlled abort
If management or production paths fail after the validation deadline:
- Capture current state, LEDs, peer status, reachability, and logs without further uncoordinated changes.
- Access the switch through the independent management path.
- In Fusion, use the serial number to select a specific, older, known-good backup and restore it through Actions > Restore backup. Alternatively, apply the known-good local
.cfgover HTTPS or TFTP. - Expect another outage and repeat full validation.
- If the known state also fails, stop restore attempts, verify physical topology and the management parameters belonging to the backup, and escalate with the captured task and error data.
A factory reset is not a normal backup fallback and does not belong in this procedure. A configuration that remains only on the target switch is not an adequate fallback either. A sound completion consists of a validated device state, a new backup, and at least one protected offline copy.