Updating the firmware on the Sophos Firewall (Firmware Update)
In this guide, we will show you how to update your Sophos Firewall firmware to the latest version.
Info: In this guide, we assume that you are using a Sophos Firewall with SFOS and that it is linked to a valid Sophos ID. Before you follow these instructions and install an update on your firewall, make sure you create a backup first. You should never assume that everything will always work properly after an update. The update is installed on the second partition and there is an option to roll back, but better safe than sorry.
Updates not free of charge: Only the first three updates are free, after that an Enhanced Support license is required, which is included in each license bundle or must be purchased separately. Read more about this update policy change in this blog post: Sophos Firewall updates no longer free of charge
Download SFOS firmware manually
Before the new firmware can be installed on the firewall, it must first be downloaded via Sophos Central (if the firewall is registered in your account) or via the firmware download page.
- SFOS firmware image for hardware appliances (XG and XGS)
- SF300 = XG series
- SF310 = XGS series
- SFOS firmware images for software appliances (virtual machines)
Note: If you have Sophos Enhanced Support (automatically included with every license bundle), you can also download the latest firmware automatically via the GUI of your Sophos Firewall. Jump to the following section: Install SFOS firmware automatically .
Install SFOS firmware manually
The downloaded firmware can now be installed on the Sophos Firewall.
- Log in to your Sophos Firewall.
- Click on
Backup & Firmware
in the navigation. - Under the heading Firmware you will find a list of the available versions. Click on the upload icon.
- The “Firmware Upgrade/Downgrade” pop-up window will then appear.
Select the firmware from your computer and click
Upload Firmware
orUpload & Boot
.
The above steps are explained here again step by step with screenshots:
Note: Think carefully about which option you choose. With Upload Firmware, only the file is transferred from your computer to the firewall, whereas with Upload & Boot, the firewall is started immediately afterwards with the latest firmware.
HA Cluster Info: If you have set up an HA Cluster, we recommend that you always select the Upload & Boot
variant. As a result, the two firewalls are updated one after the other and there is “no” interruption in the network. First the passive firewall is updated and as soon as it is online again, the firmware update is installed on the primary firewall. The only interruption is the switch from the active to the passive firewall, where you normally lose 2-6 pings.
If you have opted for Upload Firmware, you can determine the time of the update yourself. Click on the icon with the two arrows under the Firmware heading as soon as the time is right for the installation.
Install SFOS firmware automatically
If you have a valid Sophos Enhanced Support license, you can save yourself all the effort of the steps above. Enhanced Support offers you automatic updates with one click directly in the GUI of your firewall.
Note: If you can’t wait for a new firmware version to be automatically displayed on your firewall after it is released, you can of course always update using the manual variant.
- Log in to your Sophos Firewall.
- Click on
Backup & Firmware
in the navigation. - Under the Latest Available Firmware section, click
Download
for the listed update. - Once the download is complete, you can start the installation by clicking
Install
.
Rollback to old version
After an update, it can happen that something does not work as desired. In this case, you have the option of switching back to the old version. All you need to do is click on the icon marked in the screenshot next to the current version. In an HA cluster, both appliances are also started with the selected version.