Update, roll back, and recover Sophos Switch firmware
A Sophos Switch can be updated centrally through Sophos Fusion or locally through its web interface. Normally, back up the configuration first, update one pilot switch, verify the data and management paths, and only then release the next group. A rollback selects an image already on the backup partition; it does not undo configuration changes. TFTP recovery is only for an emergency in which neither the active nor backup image starts.
Quick path and the right method
- Centrally managed, reachable switch: go to My Products > Switches > Switches, click Version, select Schedule an upgrade > Choose Schedule, set Now or Custom, and confirm with Save.
- Local update: download firmware in Sophos Fusion under Devices > Installers > Switches > Download firmware. Extract the appropriate
.sigfile from the ZIP archive and install it on the switch under Configure > Firmware > Firmware upgrade using HTTPS or TFTP. - Return to the existing backup image: in Sophos Fusion, click Version and use Schedule swap firmware > Choose Schedule. On a dual-image model, you can locally select the other partition for the next restart under Configure > Firmware > Dual image.
- No image starts: download the appropriate
.bixrecovery image under Devices > Installers > Switches > Download recovery image and use the model-specific TFTP recovery procedure.
Prepare the maintenance
Include these points in the change before the first upload:
- Identify the device: record model, serial number, serial-number prefix, current firmware, and management method. For a dual-image model, also record the active and backup partitions and their displayed image names.
- Back up the configuration: create a current backup before every local upgrade and verify its model and serial assignment. For a local HTTPS backup, choose Backup and HTTPS under Configure > Firmware > Backup and restore, confirm with Apply and Apply again, and store the resulting
.cfgfile securely outside the switch. Firmware rollback is not a substitute. - Check entitlement: firmware updates require Sophos Switch Support and Services. Fusion management and changes also require a valid subscription per deployed switch. Local forwarding does not prove entitlement to downloads or Fusion management.
- Choose the version deliberately: verify the target’s release and support status. A historical release note shows when a version appeared, not whether it is the right target today.
- Plan the window: account for outages to uplinks, LAGs, management, endpoints, and possibly PoE. Test redundant paths beforehand.
- Provide a return path: have local admin access, the switch IP, and an appropriate console cable where a console port exists. For CS101 models without one, prepare a directly attached computer as DHCP/TFTP system.
- Check network requirements: a Fusion update requires access to
jfrog-prod-use1-shared-virginia-main.s3.amazonaws.comand correct switch time. A blocked domain or wrong time can make it fail. - Choose a pilot: start with one representative, low-impact switch—not an entire site, stack, or group.
Local changes are not automatically synchronized to Fusion as configuration. Decide beforehand which system is authoritative, keep configuration changes there, and document emergency local changes separately. For day-to-day status and job states, see Operate Sophos Switch fleets, synchronization, sites, and stacks.
Check the initial state in Sophos Fusion
Under My Products > Switches > Switches, Version shows installed firmware. A green circle with an arrow means an upgrade is available, a clock means one is scheduled, and no icon means the firmware is current in this view.
Also check Status, Alerts, serial number, and model:
- Synchronized: connected and Fusion settings synchronized; suitable as a starting point, but not a functional test.
- Firmware too old: newer firmware was released over 180 days ago; Fusion blocks further policy pushes until update.
- State: Suspended in device Basic details: firmware is outdated and must be updated.
- Suspended as the fleet subscription status: central management is suspended because of licensing; this differs from firmware-related Suspended.
- Waiting for sync, Pending, Syncing, Out of sync, or Manual synchronization needed: resolve pending configuration jobs and their cause first.
The word Suspended alone is insufficient: record the page, column, and affected switch.
Stage the firmware update through Sophos Fusion
Plan and run the pilot
- Open My Products > Switches > Switches.
- Compare serial, model, status, and Version with the change.
- Click the pilot’s firmware version.
- Select Schedule an upgrade, then Choose Schedule.
- Set Custom for the approved window; use Now only for an explicitly planned immediate outage.
- Confirm with Save; a clock beside the version indicates the schedule.
- Monitor alerts and reachability. Do not make parallel local changes or start another update job.
- After restart, wait for reconnection and the expected version.
Accept the pilot and release waves
Verify at least:
- local management and, where applicable, Fusion are reachable;
- the displayed version is the approved target;
- Fusion returns to Synchronized, with no unexplained alert or blocked job;
- management VLAN, uplinks, LAGs, and STP match the documented state;
- one client per relevant VLAN/port class reaches the gateway, DNS, and an intended service;
- PoE devices are powered and reachable, and remaining budget is plausible;
- logs and monitoring show no new recurring fault.
Only then schedule the next small wave. Every switch needs its own success check; one reachable stack member proves nothing about the others.
Update firmware locally using HTTPS or TFTP
Download it from Fusion:
Devices > Installers > Switches > Download firmware
The ZIP contains two .sig files. CS101 and CS110/CS210 families use different images. Match model and image family, not merely a similar version string.
Option A: HTTPS upload
- Extract the ZIP and provide the correct
.sig. - Open the local web interface and Configure > Firmware > Firmware upgrade.
- Choose HTTPS as Upgrade method and the intended Partition. Do not overwrite a working fallback image without reason.
- Use Select file, open the
.sig, select Apply, and confirm with the second Apply. - When upload completes, select Upgrade.
- Then choose Reboot or, if offered and planned, Continuous PoE Power. The latter preserves power only; see Plan and troubleshoot Sophos Switch PoE.
Option B: TFTP for several local devices
- Extract the model-appropriate
.sigfiles to the TFTP server’s shared directory. - Open Configure > Firmware > Firmware upgrade.
- Choose TFTP as Upgrade method and select the target Partition.
- Enter the internal server IP under TFTP Server and the exact
.signame under File Name. - Upload with Apply and Apply again, then run Upgrade.
- Finish with Reboot or Continuous PoE Power.
TFTP distributes the image but does not replace model checks or piloting. Offer it only on an isolated management network during the window. Sophos recommends clearing the browser cache afterward. Perform the same validation as for a Fusion update.
Roll back safely to the backup image
Rollback is appropriate when new firmware boots but causes a reproducible problem and the prior working version remains on the backup partition. Record symptoms, current version, affected functions, and time first. Do not roll back if the older version is outside the approved support path or would reopen a known vulnerability.
Swap through Sophos Fusion
- Open My Products > Switches > Switches and click the affected switch’s current firmware version.
- Select Schedule swap firmware.
- Open Choose Schedule, deliberately set Now or Custom, and confirm with Save.
- Observe the restart, then recheck version, Fusion status, and the faulty function.
Swap firmware selects an older version stored on the backup partition. It neither downloads an arbitrary version nor restores configuration.
Switch partition locally
Under Configure > Firmware > Dual image, the switch shows Flash partition, Status (Active or Backup), Image name, Image size(Byte), and Created time. Select the desired partition under Active and use Apply for the next restart. Check Image name first.
Dual Image is documented for:
CS110-24,CS110-24FP,CS110-48,CS110-48P,CS110-48FPCS210-8FP,CS210-48FPCS1010-8FP
These models normally boot the active partition and automatically use the backup if it is corrupt. This cannot help if both images are corrupt. Do not assume dual-image rollback for other models.
Recover corrupt firmware by TFTP
Recovery is the escalation path when neither image boots and the switch enters bootloader mode. It uses .bix, not the normal .sig. The bootloader locates TFTP by BOOTP, downloads the image, and restarts automatically. It stops after five failed searches; after a successful find, writing and restart take about five to ten minutes.
Identify the correct recovery image
- Open Devices > Installers > Switches > Download recovery image in Fusion.
- Download and extract the ZIP unchanged.
- Match the model and first three serial-number characters:
| Model | Serial-number prefix |
|---|---|
CS101-8 | W10 |
CS101-8FP | W11, W40 |
CS110-24 | W12 |
CS110-24FP | W13, W33 |
CS110-48 | W14 |
CS110-48P | W15, W35 |
CS110-48FP | W16, W36 |
CS210-8FP | W20, W41 |
CS210-24FP | W21 |
CS210-48FP | W22, W43 |
CS1010-8FP | W44 |
The filename follows CS-RTL<SERIES>_fw_<MODEL>_<HARDWARE_ID>_<VERSION>.bix. Series 838x covers CS101-8 and CS101-8FP without console ports; the others use 93xx and have one. Model and prefix must match the supplied table. If several files are listed for exactly the same pair, Sophos says any listed file may be used. Never select by a similar major version alone.
Recover 838x without a console port
Use a directly attached Windows computer as DHCP/TFTP server on an isolated network because the firewall is temporarily disabled and TFTP is unsecured.
- Set its Ethernet port to
172.16.16.20/24. - Disable Windows Firewall under Control Panel > System and Security > Windows Defender Firewall > Turn Windows Defender Firewall on or off.
- In Tftpd64 Settings > DHCP, set:
- IP pool start address:
172.16.16.220 - Size of pool:
10 - Boot File: exact
.bixfilename - Def. router (Opt 3):
172.16.16.220 - Mask (Opt 1):
255.255.255.0 - Additional Option: option
66with172.16.16.20 - Bind DHCP to this address:
172.16.16.20 - Ping address before assignation: off
- IP pool start address:
- In Settings > TFTP, set Base Directory to the extracted folder, TFTP security:
None, enable PXE compatibility and Allow ‘\’ as virtual root, and set Bind TFTP to this address:172.16.16.20. - Under GLOBAL, enable TFTP Server and DHCP Server, then OK.
- Connect directly; keep
.bixin the TFTP base directory. Restart the switch and monitor DHCP/BOOTP and download in Log viewer. - Do not disconnect power or Ethernet during download, writing, or restart. Recovery is complete only when
https://172.16.16.220responds. - Stop TFTP/DHCP, re-enable the firewall, and restore the computer’s addressing.
Recover 93xx with a console port
- Set a directly attached Windows computer to
172.16.16.20/24on an isolated network and disable its firewall for the window. - In Tftpd64 Settings > TFTP, use the same Base Directory, TFTP security: None, PXE compatibility, Allow ‘\’ as virtual root, and Bind TFTP to this address: 172.16.16.20. Under GLOBAL, enable only TFTP Server.
- Attach Ethernet and serial console. Set the terminal to
115200baud,8data bits, parityNone,1stop bit, and Flow ControlNone. - Log in as
adminwith the unique password on the device or packaging label. - Select bootloader option
5and verify switch IP172.16.16.239. - Select option
1and enter TFTP server172.16.16.20. - Select option
3, then1, to update partition 1. - Enter the exact
.bixfilename and press Enter. Monitor the log and do not interrupt power or connectivity. Recovery is complete only whenhttps://172.16.16.239responds. - Stop TFTP, re-enable the firewall, and remove temporary addressing.
Return to production after recovery
The recovery image contains only minimal software for booting and connecting; it is not the normal target state.
- Download current approved firmware under Devices > Installers > Switches > Download firmware and extract the appropriate
.sig. - Open Configure > Firmware > Firmware upgrade.
- Choose HTTPS, then Partition 1(Active), open the file with Select file, and run Apply, Apply, and Upgrade.
- Restart with Reboot or Continuous PoE Power.
- Check reachability, target version, uplinks, VLANs, and attached devices.
- For Fusion reconnection, open My Products > Switches > Switches, select the serial number, and run Remove from Sophos Fusion. Then register the same switch again as described in Register Sophos Switch in Sophos Fusion.
- Revalidate registration, subscription, Synchronized, and real network operation. Restore a backup only after checking model, firmware, and intended configuration authority.
Use Remove from Sophos Fusion only here, after the device boots locally and is updated—not as a repair for a failed download.
Troubleshoot by symptom
Fusion update fails
- Open and record the Fusion upgrade alert.
- Verify DNS and firewall, proxy, or TLS-inspection access to
jfrog-prod-use1-shared-virginia-main.s3.amazonaws.com. - Check switch time, time zone, and SNTP.
- Separate subscription state from firmware or connection failure.
- Reschedule only after fixing the cause; do not create duplicate jobs.
Local upload does not start
- Check file type:
.sigfor updates,.bixfor bootloader recovery. - Check model family and image; CS101 differs from CS110/CS210.
- For TFTP, verify server IP, File Name, base directory, and management-network reachability.
- Allow enough processing time; lack of visible progress is not a reason to interrupt power while writing.
Switch boots but networking is impaired
Record version, partition, and boot time; separately test uplink, LAG, STP, VLANs, management, and PoE. If reproducible and a known-good image remains on backup, consider a controlled swap in the same window, then validate fully. Otherwise, do not experimentally overwrite images; escalate with alerts, timestamps, serial, versions, and symptoms.
Recovery cannot find TFTP
- On 838x, ensure DHCP and TFTP bind to
172.16.16.20, option 66 is correct, and the computer is directly connected. - On 93xx, check switch
172.16.16.239, server172.16.16.20, serial settings, and bootloader selections. - Check exact filename, base directory, and local firewall.
- Recovery stops after five BOOTP searches; correct settings, then deliberately restart it.
When to escalate to Sophos Support
Stop further write or restart attempts if neither image starts, the exactly matched recovery image cannot be loaded or written, the switch is unreachable at the documented address after successful TFTP, or hardware failure is suspected. Also escalate if an update fails again after correcting domain access, time, licensing, and image mapping.
Collect tenant, model, full serial and prefix, current and target versions, active/attempted partition, timestamp with time zone, Fusion alert, local and TFTP/DHCP logs, exact .sig or .bix, steps taken, and uplink, PoE, and LED state. Remove secrets and customer data. See Open a support ticket with Sophos. Without valid Support and Services entitlement, involve the licensing/contract partner; do not use unofficial images or undocumented bootloader commands.
Understand firmware support and lifecycle
Sophos distinguishes Feature Releases and Maintenance Releases. Expected cadence is six to twelve months and one to three months respectively; these are expectations, not fixed dates. New features may require manual reconfiguration, and older models or revisions may leave a new development branch.
Sophos maintains the current Feature Release branch and one other branch chosen by Sophos. The support target is the last two Maintenance Releases of each maintained Feature Release, although support may still require an upgrade for a defect or vulnerability. A Feature Release’s expected support window is about 24 months but varies; EOL notice is normally 90 days.
This is not a model-specific hardware retirement calendar. Check firmware approval and model lifecycle separately before updating, renewing, or replacing hardware. See the Sophos Product Lifecycle calendar.