Skip to content
Avanet

Perform a Sophos Firewall Firmware Update

This article shows how to perform a Sophos Firewall firmware update: obtain the image, install it in WebAdmin, schedule an update through Sophos Central, and roll back to the previous firmware if necessary.

The upgrade path, backup, HA status, test plan, and rollback criteria should already be clear. See Sophos Firewall Firmware Update: Preparation and Best Practices. Before moving to SFOS 22 or later, also complete the SFOS 22 upgrade check.

⚠️ Check the platform: SFOS 21.0 GA and later versions no longer support XG and SG hardware appliances. For these devices, determine before the update whether a migration to XGS is required.

Firmware update in seven steps

  1. Check the active version, target version, and supported upgrade path.
  2. Create a fresh backup and have the Secure Storage Master Key available.
  3. Under Backup & Firmware > Firmware, check the active and inactive firmware slots.
  4. Download the target version directly or upload a suitable image.
  5. Start the version change with Install or Upload & Boot.
  6. After the restart, check the active version and, for HA, both appliances.
  7. Verify WAN, VPN, DNS, NAT, published services, and logging with real tests.

The firewall terminates existing sessions and restarts when changing versions. A maintenance window is also required for HA because individual sessions, VPN tunnels, or pings may be briefly interrupted during failover.

Check before starting

Before uploading, confirm at least the following:

  • The current version, target version, and supported upgrade path are documented.
  • A current firewall backup, backup password, and Secure Storage Master Key are available.
  • HA status and synchronization are healthy if a cluster is used.
  • Remote sites have an alternative access method, such as a local contact, out-of-band access, or management VPN.
  • The release notes and Known Issues for the target version have been checked for relevant platform, VPN, interface, and migration notes.

Starting with SFOS 19.0 MR1, three free moves to GA, MR, or EAP versions are available without Enhanced Support or Enhanced Plus Support. After that, firmware can still be downloaded but not installed; Install is disabled. Pattern Updates, hotfixes, reimage, Mandatory Firmware Upgrades, and Assistant Firmware Upgrades are exempt.

Sophos Firewall shows no more than two firmware versions: one active and one inactive. The inactive version is either the previous version or a compatible image uploaded manually. Each partition has its own configuration. A later rollback therefore also activates the configuration of the previous partition.

Obtain SFOS firmware

For registered firewalls, the image can be obtained from Sophos Central through the profile menu under Licensing > Firewall licenses. Expand the firewall, select the appropriate firmware under Downloads, and, if necessary, use Other downloads to open the platform type.

Official download pages:

Before uploading, the platform, appliance series, active version, and target path must match the image. Incompatible images are rejected. An incompatible version change requires a reimage; automatic rollback isn’t available for an unsupported upgrade path.

Manual upload is also suitable for air-gapped environments. License synchronization and Pattern Updates remain separate operational processes, as described in Sophos Firewall air-gap licensing and Pattern Updates.

Install firmware manually

  1. Sign in to Sophos Firewall WebAdmin.
  2. Open Backup & Firmware > Firmware.
  3. Select the upload icon for the inactive firmware slot.
  4. In the Firmware Upgrade/Downgrade dialog, select the appropriate image.
  5. Select Upload Firmware to stage the image without starting it.
  6. Select Upload & Boot when the maintenance window is active and the restart should begin immediately.
Sophos Firewall upload dialog for a local firmware image
The upload dialog determines whether the image is only staged or installed and started immediately.
Selected SFOS firmware image before upload
Before uploading, the platform, target version, and supported upgrade path must match the image.

The three actions differ significantly:

  • Upload Firmware: Loads the image into the inactive slot without starting it. A later restart for another reason also won’t switch automatically to this version.
  • Upload & Boot: Uploads the image, terminates existing sessions, and immediately starts the firewall with the new version.
  • Boot firmware image: Starts a compatible version already present in the inactive slot. It boots that exact version, not automatically the latest available version.
Start an inactive firmware image on Sophos Firewall
The boot action starts the compatible version already uploaded to the inactive firmware slot.

Firmware update in an HA cluster

HA doesn’t need to be disabled before the update. On a connected cluster, start the process on the Primary: The Auxiliary appliance is updated and restarted first, followed by failover and then the update of the former Primary. If a Preferred Primary is defined, a failback may occur at the end.

Don’t update the Auxiliary appliance separately. An HA device in standalone mode can’t be updated through the normal cluster process. Roles, HA link, and synchronization must therefore be clear before starting. Pattern Updates are updated on the Primary and then synchronized to the Auxiliary. Sophos Firewall HA clusters: variants and maintenance explains additional special cases.

Update directly in WebAdmin or through Central

Update directly in WebAdmin

With a valid entitlement, the firewall can download available firmware directly:

  1. Open Backup & Firmware > Firmware.
  2. Under Latest Available Firmware, select Check for new firmware.
  3. Select Download for the required version.
  4. After the download, start Install.
  5. Wait for the restart and sign in again.
  6. Check the active version in the Control center and under Backup & Firmware > Firmware.
Download available SFOS firmware in WebAdmin
With a valid entitlement, available firmware can be downloaded directly in WebAdmin.
Install downloaded SFOS firmware in WebAdmin
After the download, Install starts the version change and restarts the firewall.

Schedule firmware through Sophos Central

Sophos Central shows a download button for eligible firewalls. Only target versions that have reached Available to all in the release process can be installed through Central.

  1. Open My Products > Firewall Management > Firewalls.
  2. Select the download button for the firewall, then select Schedule Upgrades.
  3. If several versions are offered, select the target version.
  4. Set the date and time or start the update immediately.
  5. Edit or cancel scheduled updates before they start if necessary.

Central uses the timezone configured on the firewall. During the upgrade, a status icon spins next to the firewall and disappears when the upgrade is complete. The active version must still be checked locally in WebAdmin afterward. If an automatic rollback occurs, Central shows a corresponding message next to the firmware version.

Missing action or failed update

  • Install is disabled: Check whether the three free firmware upgrades have been used and whether Enhanced Support or Enhanced Plus is active.
  • Central doesn’t show a download button: Check the online and management status, entitlement, platform, and available target version. For a new release, Available to all may not yet have been reached.
  • The upload is rejected: Check the platform type, appliance series, upgrade path, and file integrity. An incompatible change requires a reimage instead of another upload attempt.
  • Upload or installation fails despite a suitable image: Check free disk space and, for HA, the synchronization status of both appliances. Don’t upload the same image repeatedly before identifying the cause.
  • The firewall rolls back automatically: Starting with SFOS 20.0, this happens for certain configuration migration errors. An alert appears locally in the Control center along with a log entry; a Central update also shows a message next to the firmware version. The migration.log and migrationhash.log files are particularly relevant for identifying the cause.
  • WebAdmin remains unreachable because of corrupt firmware: SFLoader may be required for XG/SG devices. XGS doesn’t support SFLoader; for these devices, reimaging with a USB flash drive is the intended recovery path.

Don’t repeat an automatically rolled-back update without investigating the cause. Save the migration logs and involve Sophos or partner support if the findings are unclear.

Check after the update

After restarting, first check the expected active version under Backup & Firmware > Firmware. Then verify the following with real connections:

  • WAN uplinks, default gateway, SD-WAN routes, and key interfaces.
  • HA status, roles, and synchronization.
  • Site-to-site VPN, Remote Access VPN, and RED connections.
  • DNS, DHCP, NAT, WAF, and important firewall rules.
  • Web access, TLS Inspection, authentication, and published applications.
  • Pattern and hotfix status match the expected state.
  • Sophos Central synchronization, monitoring, Syslog, and SIEM data.

If only one rule, NAT rule, or WAF publication is affected, first use Log Viewer, Policy Test, Packet Capture, and the relevant service logs. See Test a firewall rule with Log Viewer, Policy Test, and Packet Capture and Sophos Firewall troubleshooting: services and logs.

Roll back to the previous firmware

A rollback starts the previous compatible firmware in the inactive slot and activates its associated configuration. Open Backup & Firmware > Firmware and select the rollback or Boot firmware image icon for the previous firmware version. Configuration changes made since the upgrade may be lost. A rollback is therefore no substitute for a backup or restore.

  • Rollback: Move to the previously installed compatible firmware and its configuration.
  • Downgrade: Move to an earlier compatible version that isn’t necessarily the direct predecessor.
  • Reimage: Reinstall Sophos Firewall OS and then restore the configuration.

A rollback is appropriate when WAN, HA, key VPNs, or business-critical publications can’t be stabilized within the defined analysis window. For a single rule or external service, targeted troubleshooting is usually better. A user interface that only appears slow isn’t sufficient reason for a rollback.

Before selecting the action, document the active and new firmware versions, time, symptom, affected services, HA status, and tests already performed. This makes it clear later why the rollback was performed and which cause still needs investigation.

In an HA cluster, the same inactive firmware must be present on both appliances. Alternatively, disable HA and roll back each device separately. If the previous version wasn’t configured for HA, both devices start in standalone mode after the rollback and HA must be configured again.

After the rollback, recheck the active version, WAN, VPN, HA, rules, NAT, WAF, DNS, DHCP, Central synchronization, and logging. Then document the cause and the next maintenance window.

Roll back Sophos Firewall to the previous firmware version
A rollback also starts the configuration associated with the previous firmware partition.