Skip to content
Avanet

Migrate a Sophos UTM license to Sophos Firewall

A Sophos UTM license can be migrated to Sophos Firewall OS (SFOS) in two different ways. The first converts an SG Series appliance running UTM 9.x to SFOS and migrates the full UTM license. The second applies a virtual UTM license to an existing virtual SFOS appliance. The SFOS appliance requires a separately purchased virtual Base License first. Converting a software appliance is outside this guide because it requires a different installer and deployment path.

⚠️ Both license migrations are irreversible. Once you confirm the full migration or apply the UTM license to the firewall, that license can no longer be used on UTM. An SFOS backup cannot reverse this action. This procedure explicitly does not apply to migration onto an XGS Appliance; contact Sophos Sales or use the Sophos Migration Center for that path.

License migration does not migrate configuration. Treat rules, objects, VPNs, certificates, interfaces, and services as a separate migration project and recreate them on SFOS.

Preserve evidence and a fallback before migration

Before changing anything, record at least the serial number, UTM License ID, SG model or virtual-machine resources, active subscriptions, and expiry dates. In the MyUTM Licensing Portal, open the relevant license under License Management and save it using Actions > Download License File. The file must belong to the SG appliance being converted; Sophos warns that using a license file for the wrong model during conversion can cause service disruption.

Apply any unused new or renewal license key to UTM first, then wait at least one day for Sophos records to synchronize. The change record should also contain a current UTM configuration backup, exported certificates and keys, WAN credentials, tested local admin access, and a maintenance window. The UTM backup provides evidence and a fallback before full license conversion. To return during the SFOS trial, reinstall UTM and restore this separately preserved UTM backup; an SFOS backup cannot be restored to UTM or reverse the license conversion.

The SG path also requires access to the appliance, MyUTM, and Sophos Fusion (formerly Sophos Central), internet access, and at least a 4 GB USB drive, USB keyboard, and VGA monitor. The Sophos migration instructions state a 1 GB minimum; using 4 GB also satisfies the more conservative requirement in the reimage guide linked below. The virtual path requires the UTM license file and the serial number of the separately purchased SFOS virtual Base License.

Path A: Fully convert an SG Series UTM 9.x appliance to SFOS

According to Sophos, this path is for an SG Series UTM 9.x appliance with a full UTM license. A UTM trial license can’t be converted. If you need to evaluate SFOS while retaining the option to return to UTM, install the 30-day SFOS trial instead of selecting full migration. Returning requires reinstalling UTM and restoring the separately preserved UTM backup; an SFOS backup cannot be restored to UTM. You can trigger full migration during the trial. After selecting full migration, there is no generic rollback to the UTM license.

  1. Obtain the .iso Sophos labels Hardware Installers: Firewall OS for XGS Series from the Sophos download page or Sophos Fusion under My Environment > Installers > Firewall Protection > Download installers.
  2. Create the installation media and reinstall the appliance. Reimage Sophos Firewall OS covers that process. Reimaging erases the existing system and configuration.
  3. When Firmware installed. Press y to reboot when done. appears, remove the USB drive, press Y, then press Enter.
  4. Connect an admin computer to the LAN port and initially sign in with username admin and password admin. You must change the default password.
  5. Select I would like to migrate my UTM 9 license now, use Browse to select the verified UTM license file, and click Continue.
  6. On License Migration & Renewals, click Login, sign in, and only after a final check select Yes - Proceed with Registration on Important Information About Your License.
  7. Complete the CAPTCHA and click Continue. On the details page that follows, verify the assignment again, then click Confirm Registration + Evaluation License.
  8. On Registration Successful, click Initiate License Synchronization. Complete Basic Setup and the Network Configuration Assistant.
  9. Under Administration > Licensing, compare the result with the expected converted entitlements below and use the change record to identify the original UTM inputs.

Software appliances are deliberately outside this SG procedure. Don’t experiment with the hardware image; confirm the official installer and deployment path for the platform with Sophos Support before converting a license.

Path B: Apply a virtual UTM license to a virtual SFOS appliance

This path doesn’t reimage the virtual appliance. It applies an existing virtual UTM license to a virtual Sophos Firewall. The UTM license does not include an SFOS virtual Base License. Purchase that Base License separately and associate its serial number with the virtual SFOS appliance.

During SFOS setup

  1. Open WebAdmin at https://<SFOS-IP>:4444, verify that the certificate warning is for the default locally signed certificate, and continue to Welcome to Sophos Firewall.
  2. Accept the Sophos End User Terms of Use and click Start setup.
  3. Deselect Install the latest firmware automatically during setup (recommended), click Continue, set the firewall name and time zone, then click Continue again.
  4. Select I have an existing serial number and enter the serial number of the purchased SFOS virtual Base License.
  5. Under UTM 9 users, click Browse, upload the UTM license file, and click Continue.
  6. On Claim your firewall with Sophos Central, click Claim in Sophos Central. The button opens Sophos Fusion; sign in at fusion.sophos.com, verify the detected serial number, and confirm Claim firewall with Claim and migrate.
  7. Back in SFOS on Basic setup is complete, choose Skip to finish or use Continue for additional settings.

Later in Sophos Fusion

If the virtual firewall is already claimed, open the profile icon in Sophos Fusion and select Licensing > Firewall licenses. Find the firewall by serial number, expand its row, and click Migrate UTM 9 license. Under Upload UTM 9 license file, click Choose, upload the verified file, and confirm with Finish. Then open Administration on the firewall and click Synchronize.

Expected entitlements after conversion

After migration, expect Enhanced Support. For an SG migration, also expect an SFOS Base License in addition to the converted licenses. Sophos explicitly states that the Base License is migrated even when the UTM license has no active subscriptions. This does not apply to the virtual path: a virtual UTM Base License is not migrated, so the separately purchased SFOS virtual Base License remains the base entitlement. In both paths, Sophos grants trial licenses for all other SFOS licenses for the remaining UTM license term, in addition to the licenses mapped below.

UTM license and componentsExpected SFOS license and components
Essential Firewall: Firewall; Wireless: WirelessBase Firewall: Firewall, VPN, Wireless
Network: VPN, ATP, IPSNetwork: RED/HTML5, ATP, IPS, Security Heartbeat
Web: URL, AV, Application controlWeb: URL, AV, Application control
Email: AS, AV, SPX, DLPEmail: AS, AV, SPX, DLP
Web server: WAF, AV, Reverse proxyWeb server: WAF, AV, Reverse proxy
EndpointCloud endpoint
SandstormZero-Day Protection

BasicGuard is the term exception: it converts to Xstream Protection plus Email Protection and Web Server Protection, and its remaining term is halved. For the virtual path covered here, use the UTM user/IP level to verify the converted SFOS model and resource limit:

UTM users/IPsSFOS modelSFOS license limit
10SFv1C4Maximum 1 core and 4 GB RAM
25SFv1C4Maximum 1 core and 4 GB RAM
50SFv2C4Maximum 2 cores and 4 GB RAM
75SFv2C4Maximum 2 cores and 4 GB RAM
100SFv4C6Maximum 4 cores and 6 GB RAM
150SFv4C6Maximum 4 cores and 6 GB RAM
250SFv6C8Maximum 6 cores and 8 GB RAM
500SFv8C16Maximum 8 cores and 16 GB RAM
750SFv8C16Maximum 8 cores and 16 GB RAM
1000SFv16C24Maximum 16 cores and 24 GB RAM
1500SFv16C24Maximum 16 cores and 24 GB RAM
2500SFvUNLUnlimited cores and RAM
UNLSFvUNLUnlimited cores and RAM

Verify the result and stop on discrepancies

In SFOS, Administration or Administration > Licensing must show the Base License, converted modules, trial licenses, support package, term, and—where applicable—the virtual model listed in the expected state above. In Sophos Fusion, expand the serial number under Firewall Management > Firewall Licenses or Licensing > Firewall licenses and verify the same assignment. Both views must agree with each other; use the pre-change evidence as the conversion input, not as a requirement for unchanged modules, model, or terms.

If the Sophos Fusion route shows the license only in Sophos Fusion, first check internet connectivity and the claim in Sophos Fusion, then click Synchronize again. If you see the wrong serial number or model, an unexpected term, or different modules, don’t attempt another registration, reinstall, or second license migration. Preserve the UTM license file, License ID, both serial numbers, screenshots of the license details, and the time, then escalate to Sophos Support or your licensing partner. There is no general self-service rollback after a confirmed full migration.

Migrate configuration separately

Start configuration migration only after the license check succeeds. UTM-to-SFOS rules and objects must be planned again; Config Studio can document and compare later SFOS states, but it doesn’t automatically convert UTM configuration. Before further SFOS changes, create a Sophos Firewall backup and understand the restore path. Activate additional SFOS subscription keys separately as described in Activate a Sophos Firewall license key.