Perform a Sophos Firewall Firmware Update
This article shows how to perform a Sophos Firewall firmware update: obtain the image, install it in WebAdmin, schedule an update through Sophos Central, and roll back to the previous firmware if necessary.
The upgrade path, backup, HA status, test plan, and rollback criteria should already be clear. See Sophos Firewall Firmware Update: Preparation and Best Practices. Before moving to SFOS 22 or later, also complete the SFOS 22 upgrade check.
⚠️ Check the platform: SFOS 21.0 GA and later versions no longer support XG and SG hardware appliances. For these devices, determine before the update whether a migration to XGS is required.
Firmware update in seven steps
- Check the active version, target version, and supported upgrade path.
- Create a fresh backup and have the Secure Storage Master Key available.
- Under
Backup & Firmware > Firmware, check the active and inactive firmware slots. - Download the target version directly or upload a suitable image.
- Start the version change with
InstallorUpload & Boot. - After the restart, check the active version and, for HA, both appliances.
- Verify WAN, VPN, DNS, NAT, published services, and logging with real tests.
The firewall terminates existing sessions and restarts when changing versions. A maintenance window is also required for HA because individual sessions, VPN tunnels, or pings may be briefly interrupted during failover.
Check before starting
Before uploading, confirm at least the following:
- The current version, target version, and supported upgrade path are documented.
- A current firewall backup, backup password, and Secure Storage Master Key are available.
- HA status and synchronization are healthy if a cluster is used.
- Remote sites have an alternative access method, such as a local contact, out-of-band access, or management VPN.
- The release notes and Known Issues for the target version have been checked for relevant platform, VPN, interface, and migration notes.
Starting with SFOS 19.0 MR1, three free moves to GA, MR, or EAP versions are available without Enhanced Support or Enhanced Plus Support. After that, firmware can still be downloaded but not installed; Install is disabled. Pattern Updates, hotfixes, reimage, Mandatory Firmware Upgrades, and Assistant Firmware Upgrades are exempt.
Sophos Firewall shows no more than two firmware versions: one active and one inactive. The inactive version is either the previous version or a compatible image uploaded manually. Each partition has its own configuration. A later rollback therefore also activates the configuration of the previous partition.
Obtain SFOS firmware
For registered firewalls, the image can be obtained from Sophos Central through the profile menu under Licensing > Firewall licenses. Expand the firewall, select the appropriate firmware under Downloads, and, if necessary, use Other downloads to open the platform type.
Official download pages:
- Hardware appliances: SFOS firmware for hardware appliances.
SF300stands for the XG series andSF310for the XGS series. - Software and virtual appliances: SFOS firmware for software appliances.
- Cloud appliances: SFOS firmware for cloud appliances.
Before uploading, the platform, appliance series, active version, and target path must match the image. Incompatible images are rejected. An incompatible version change requires a reimage; automatic rollback isn’t available for an unsupported upgrade path.
Manual upload is also suitable for air-gapped environments. License synchronization and Pattern Updates remain separate operational processes, as described in Sophos Firewall air-gap licensing and Pattern Updates.
Install firmware manually
- Sign in to Sophos Firewall WebAdmin.
- Open
Backup & Firmware > Firmware. - Select the upload icon for the inactive firmware slot.
- In the
Firmware Upgrade/Downgradedialog, select the appropriate image. - Select
Upload Firmwareto stage the image without starting it. - Select
Upload & Bootwhen the maintenance window is active and the restart should begin immediately.


The three actions differ significantly:
- Upload Firmware: Loads the image into the inactive slot without starting it. A later restart for another reason also won’t switch automatically to this version.
- Upload & Boot: Uploads the image, terminates existing sessions, and immediately starts the firewall with the new version.
- Boot firmware image: Starts a compatible version already present in the inactive slot. It boots that exact version, not automatically the latest available version.

Firmware update in an HA cluster
HA doesn’t need to be disabled before the update. On a connected cluster, start the process on the Primary: The Auxiliary appliance is updated and restarted first, followed by failover and then the update of the former Primary. If a Preferred Primary is defined, a failback may occur at the end.
Don’t update the Auxiliary appliance separately. An HA device in standalone mode can’t be updated through the normal cluster process. Roles, HA link, and synchronization must therefore be clear before starting. Pattern Updates are updated on the Primary and then synchronized to the Auxiliary. Sophos Firewall HA clusters: variants and maintenance explains additional special cases.
Update directly in WebAdmin or through Central
Update directly in WebAdmin
With a valid entitlement, the firewall can download available firmware directly:
- Open
Backup & Firmware > Firmware. - Under Latest Available Firmware, select
Check for new firmware. - Select
Downloadfor the required version. - After the download, start
Install. - Wait for the restart and sign in again.
- Check the active version in the Control center and under
Backup & Firmware > Firmware.


Schedule firmware through Sophos Central
Sophos Central shows a download button for eligible firewalls. Only target versions that have reached Available to all in the release process can be installed through Central.
- Open
My Products > Firewall Management > Firewalls. - Select the download button for the firewall, then select Schedule Upgrades.
- If several versions are offered, select the target version.
- Set the date and time or start the update immediately.
- Edit or cancel scheduled updates before they start if necessary.
Central uses the timezone configured on the firewall. During the upgrade, a status icon spins next to the firewall and disappears when the upgrade is complete. The active version must still be checked locally in WebAdmin afterward. If an automatic rollback occurs, Central shows a corresponding message next to the firmware version.
Missing action or failed update
Installis disabled: Check whether the three free firmware upgrades have been used and whether Enhanced Support or Enhanced Plus is active.- Central doesn’t show a download button: Check the online and management status, entitlement, platform, and available target version. For a new release,
Available to allmay not yet have been reached. - The upload is rejected: Check the platform type, appliance series, upgrade path, and file integrity. An incompatible change requires a reimage instead of another upload attempt.
- Upload or installation fails despite a suitable image: Check free disk space and, for HA, the synchronization status of both appliances. Don’t upload the same image repeatedly before identifying the cause.
- The firewall rolls back automatically: Starting with SFOS 20.0, this happens for certain configuration migration errors. An alert appears locally in the Control center along with a log entry; a Central update also shows a message next to the firmware version. The
migration.logandmigrationhash.logfiles are particularly relevant for identifying the cause. - WebAdmin remains unreachable because of corrupt firmware: SFLoader may be required for XG/SG devices. XGS doesn’t support SFLoader; for these devices, reimaging with a USB flash drive is the intended recovery path.
Don’t repeat an automatically rolled-back update without investigating the cause. Save the migration logs and involve Sophos or partner support if the findings are unclear.
Check after the update
After restarting, first check the expected active version under Backup & Firmware > Firmware. Then verify the following with real connections:
- WAN uplinks, default gateway, SD-WAN routes, and key interfaces.
- HA status, roles, and synchronization.
- Site-to-site VPN, Remote Access VPN, and RED connections.
- DNS, DHCP, NAT, WAF, and important firewall rules.
- Web access, TLS Inspection, authentication, and published applications.
- Pattern and hotfix status match the expected state.
- Sophos Central synchronization, monitoring, Syslog, and SIEM data.
If only one rule, NAT rule, or WAF publication is affected, first use Log Viewer, Policy Test, Packet Capture, and the relevant service logs. See Test a firewall rule with Log Viewer, Policy Test, and Packet Capture and Sophos Firewall troubleshooting: services and logs.
Roll back to the previous firmware
A rollback starts the previous compatible firmware in the inactive slot and activates its associated configuration. Open Backup & Firmware > Firmware and select the rollback or Boot firmware image icon for the previous firmware version. Configuration changes made since the upgrade may be lost. A rollback is therefore no substitute for a backup or restore.
- Rollback: Move to the previously installed compatible firmware and its configuration.
- Downgrade: Move to an earlier compatible version that isn’t necessarily the direct predecessor.
- Reimage: Reinstall Sophos Firewall OS and then restore the configuration.
A rollback is appropriate when WAN, HA, key VPNs, or business-critical publications can’t be stabilized within the defined analysis window. For a single rule or external service, targeted troubleshooting is usually better. A user interface that only appears slow isn’t sufficient reason for a rollback.
Before selecting the action, document the active and new firmware versions, time, symptom, affected services, HA status, and tests already performed. This makes it clear later why the rollback was performed and which cause still needs investigation.
In an HA cluster, the same inactive firmware must be present on both appliances. Alternatively, disable HA and roll back each device separately. If the previous version wasn’t configured for HA, both devices start in standalone mode after the rollback and HA must be configured again.
After the rollback, recheck the active version, WAN, VPN, HA, rules, NAT, WAF, DNS, DHCP, Central synchronization, and logging. Then document the cause and the next maintenance window.
