Updating the firmware on the Sophos Firewall (Firmware Update)
In this guide, we will show you how to update your Sophos Firewall firmware to the latest version.
Info: In these instructions, we assume that you have a Sophos Firewall with valid Enhanced Support or that the appliance is new and you can still perform a free update, but more on this later. Before you follow these instructions and install an update on your firewall, create a backup first. You should never assume that everything will always work properly after an update. The update is installed on the second partition and there is an option to roll back, but better safe than sorry.
Topics
Download SFOS firmware manually
Before the new firmware can be installed on the firewall, it must first be downloaded via Sophos Central (if the firewall is registered in your account) or via the firmware download page.
- SFOS firmware image for hardware appliances (XG and XGS)
- SF300 = XG series
- SF310 = XGS series
- SFOS firmware images for software appliances (virtual machines)
- SFOS firmware for cloud appliances
Note: If you have Sophos Enhanced Support (automatically included with every license bundle), you can also download the latest firmware automatically via the GUI of your Sophos Firewall. Jump to the following section: Install SFOS firmware automatically .
Install SFOS firmware manually
The downloaded firmware can now be installed on the Sophos Firewall.
- Log in to your Sophos Firewall.
- Click on
Backup & Firmware
in the navigation. - Under the heading Firmware you will find a list of available versions. Click on the upload icon.
- The “Firmware Upgrade/Downgrade” pop-up window will then appear. Select the firmware from your computer and click
Upload Firmware
orUpload & Boot
.
The above steps are explained here again step by step with screenshots:


Note: Think carefully about which variant you choose. With Upload Firmware only the file is transferred from your computer to the firewall, while with Upload & Boot the firewall is started with the latest firmware afterwards.
HA Cluster Info: If you have set up an HA Cluster, we recommend that you always select the Upload & Boot
variant. As a result, the two firewalls are updated one after the other and there is “no” interruption in the network. First the passive firewall is updated and as soon as it is online again, the firmware update is installed on the primary firewall. The only interruption is the switch from the active to the passive firewall, where you normally lose 2-6 pings.
If you have chosen Upload Firmware, you can determine the time of the update yourself. Click on the icon with the two arrows under the Firmware section as soon as the time is right for the installation.

Install SFOS firmware automatically
If you have a valid Sophos Enhanced Support license, you can save yourself all the effort of the above steps. The Enhanced Support offers you automatic updates with one click directly in the GUI of your firewall.
Note: If you can’t wait for a new firmware version to be automatically displayed on your firewall after it is released, you can of course always update using the manual variant.
- Log in to your Sophos Firewall.
- Click on
Backup & Firmware
in the navigation. - Under the Latest Available Firmware section, click
Download
for the listed update. - Once the download is complete, you can start the installation by clicking
Install
.


Rollback to old version
After an update, it can happen that something does not work as desired. In this case, you have the option of switching back to the old version. All you need to do is click on the icon marked in the screenshot next to the current version. In an HA cluster, both appliances are also started with the selected version.

FAQ
Why are updates no longer free?
Only the first three updates are free of charge. After that, an Enhanced Support license is required to receive further updates. This change is intended to ensure that only customers with an active support license have access to ongoing improvements and security updates. Blogpost: Sophos Firewall Updates will no longer be free in future
What is an Enhanced Support license?
The Enhanced Support license provides access to updates and technical support. It is either included in every license bundle or can be purchased separately.
Without a valid Enhanced Support license, no further updates can be installed after the first three free updates, which may entail security risks.
Why can’t the v21 update be installed on the XG?
The v21 update and future versions are designed for the hardware architecture of the XGS appliances and are therefore not compatible with the XG series.
You should upgrade to an XGS appliance to continue receiving updates and security features.
XGS appliances offer a modernized hardware architecture with higher performance and support for future firmware updates, while XG appliances are obsolete and no longer receive new updates.