Skip to content
Avanet

Sophos portals: SophosID, Central, Support and firewall access

Sophos provides several portals that are easily confused in day-to-day work: SophosID, Sophos Central, Support Portal, the local firewall WebAdmin, User Portal, VPN Portal, Captive Portal and documentation. Admins need to know what each portal is for, which login it uses and which access points are security-critical.

This overview explains the main Sophos portals. It is intended primarily for admins who operate Sophos Firewall, Sophos Central or Remote Access and need to know quickly where to complete a task, especially during a support case.

Quick overview

The main portals are:

  • SophosID: personal Sophos account for signing in to Sophos services and accessing support and licensing functions.
  • Sophos Central: cloud management for products, users, devices, licences, firewall management and reports.
  • Sophos Support Portal: support cases, RMAs, Sophos KB and support communications.
  • Sophos Firewall WebAdmin: local firewall management for rules, VPN, NAT, certificates, logs, firmware and Device Access.
  • User Portal: user functions such as OTP, quarantine, downloads or legacy Remote Access functions.
  • VPN Portal: Remote Access with Sophos Connect downloads, VPN configurations and user access.
  • Captive Portal: browser-based user login for network access, guests or internal users.
  • Sophos Docs and Release Notes: current manuals, release notes and known limitations.

Not every portal is relevant in every environment. A standalone Sophos Firewall installation without Central Endpoint requires different access from an organisation using Sophos Central, MDR, ZTNA and multiple firewalls.

Sophos account and cloud portals

These portals sit outside the local firewall and cover accounts, licensing, cloud management or support. They become particularly important when several admins, Sophos Central or a support case are involved.

SophosID

SophosID is the personal Sophos account. It is used for several Sophos services, including support, account and licensing functions and access to specific Sophos portals.

Open SophosID:

Open the SophosID account page

Important operational points:

  • SophosID accounts should be assigned to individuals rather than used as a shared team login.
  • MFA should be enabled whenever Sophos offers it for the relevant access.
  • When someone leaves, their personal access must be removed from Sophos Central and from support and licensing contexts.
  • Service providers and teams with several admins should document roles and responsibilities.

If a Sophos Firewall must be transferred to another account, see Transfer a Sophos Firewall to another Sophos Central account.

Sophos Central

Sophos Central is the cloud management platform for many current Sophos products. Depending on the licence, it manages Endpoint, Server, Email, Wireless, ZTNA, Firewall Management, Reporting, MDR/XDR and other functions.

Open Sophos Central:

Open Sophos Central

Other starting points:

Sophos Central is particularly relevant for Sophos Firewall when firewalls need to be registered, managed centrally, inventoried or included in Central Firewall Reporting. The connection process is described in Connect Sophos Firewall to Sophos Central. For reporting, see Enable Central Firewall Reporting.

Important admin points:

  • Central admins should have individual accounts and appropriate roles.
  • MFA and admin roles should be reviewed regularly.
  • Licence status and expiry dates belong in the operational process.
  • Changes made through Sophos Central can be traced more clearly in audit logs in current SFOS versions.
  • Where several Central accounts exist, it should be clear which tenant contains each firewall and licence.

For licence checks, see Check Sophos Central licences. For permissions in Central, see Sophos Central administrative roles. For larger structures, What is Sophos Central Enterprise? is the better starting point.

Sophos Support Portal

The Sophos Support Portal is used to open and manage support cases and RMAs. It is also the starting point for many public Sophos KB articles.

Open the Support Portal:

Open the Sophos Support Portal

Before opening a support case, establish:

  • Is there valid support entitlement or an appropriate licence?
  • Which serial number or Central tenant ID is affected?
  • Which firmware version, appliance, logs and error messages are relevant?
  • Are screenshots, time windows and reproducible steps available?
  • Who is available internally to answer follow-up questions?

The practical process is described in How to open a support ticket with Sophos. If Sophos needs access to a firewall, this access should be configured in a controlled manner and removed afterwards. See Configure Avanet support access on Sophos Firewall.

Local Sophos Firewall portals

The following portals run on or in the immediate environment of Sophos Firewall. Because they are closer to the production network, they should be enabled, named and secured deliberately.

Local Sophos Firewall WebAdmin

The WebAdmin Console is the local management interface for Sophos Firewall. Access is normally through the firewall IP address and the configured HTTPS port.

The default address is:

https://<Firewall-IP-or-FQDN>:4444

By default, access is permitted from the LAN zone. Additional zones are enabled under Administration > Device access. WebAdmin should not be reachable from the WAN zone. For external administration, VPN or ZTNA, a separate management network and tightly scoped Local Service ACL Exception Rules are cleaner approaches.

Typical tasks include:

  • Configuring firewall rules, NAT and routing
  • Managing VPN, certificates and authentication
  • Reviewing logs, Packet Capture and diagnostics
  • Performing firmware updates and backups
  • Securing Device Access, MFA and admin access

The WebAdmin Console is not a normal web portal; it provides direct management access to the firewall. It should only be reachable from trusted networks. The most important follow-up article is Secure Sophos Firewall access: configure Device Access correctly.

For a new firewall, start with Sophos Firewall Getting Started. For admin MFA, see Enable MFA for Sophos Firewall WebAdmin, VPN Portal and Remote Access. If Entra ID should handle the WebAdmin login, Entra ID SSO for Sophos Firewall WebAdmin also explains role mapping, the permission test, and the local emergency login.

Anyone who opens WebAdmin and portals using an FQDN rather than an IP address should also understand the shared certificate selection. Import and assign certificates on Sophos Firewall explains SANs, the CA chain, the private key and how to switch certificates safely.

User Portal, VPN Portal and Captive Portal

The User Portal and VPN Portal are often confused. Both are local Sophos Firewall services, but they serve different purposes and should only be enabled when they are genuinely required.

Since SFOS 20, the User Portal and VPN Portal have been separated more clearly. The VPN Portal uses HTTPS port 443 by default. The User Portal uses 4443 by default. Following an upgrade or restore from a version earlier than SFOS 20, the VPN Portal adopts the previous User Portal port; the User Portal changes to 4443 or, if that port is occupied, automatically to 65040.

The User Portal displays personal data and, depending on the configuration, information such as internet usage, email quarantine, exceptions, Policy Overrides, OTP registration and other client downloads. These include the Client Authentication Agent and its Server CA. A normal local user can also change their password there. Since SFOS 20, Remote Access clients and VPN configurations are provided through the VPN Portal.

A useful rule of thumb:

  • User Portal (4443): for internal users or users who are already connected securely, for example for OTP, personal data, quarantine and Policy Overrides. Sophos warns against enabling the User Portal for the WAN zone.
  • VPN Portal (443): for Remote Access users, Sophos Connect, SSL VPN profiles and Remote Access configurations. It only appears to a user when that user or their group is assigned to a Remote Access policy.
  • Captive Portal (8090): for users on the network, browser login, user-based rules or guest access. A typical mistake is confusing it with the VPN Portal or deploying it without a clear logout and session concept.

Important points:

  • All three portals are login surfaces and therefore security-critical.
  • Reachability is controlled through Administration > Device access.
  • The User Portal should not be reachable from the WAN zone. The VPN Portal may be reachable from WAN for Remote Access, but it must then be protected with MFA, a suitable certificate, restrictive policies and login monitoring.
  • Old portals often remain open even though users no longer need them after the rollout.
  • Manually distributed .ovpn profiles must be downloaded and imported again if the SSL VPN port, protocol, interface or SSL server certificate changes. Updating Sophos Connect alone does not invalidate existing profiles.

For unusually many failed logins, distributed source IP addresses, or account lockouts, Detect and contain VPN Portal brute force guides through log review, ACL restriction, identity protection, and follow-up verification.

⚠️ Device Access exception: When the firewall’s web proxy is used, SFOS treats its HTTP and HTTPS requests as internal traffic. Users with proxy access may therefore be able to reach local HTTPS services such as WebAdmin, Captive Portal, VPN Portal or User Portal even when the relevant service is not enabled for their zone under Device access. This path must be tested separately during hardening.

For help choosing a Remote Access solution, see Sophos Connect or SSL VPN: which Remote Access solution fits?. For client updates and profile maintenance, see Check the Sophos Connect client version and update it safely.

If a user is signed in to the VPN Portal but the .ovpn is missing, is 0 bytes, or cannot be generated, Sophos Firewall: .ovpn missing or 0 bytes guides through checks of the policy, User ID, certificate, storage, firmware, and HA.

For new SSL VPN environments, first check the firewall-side configuration and portal dependencies. The process is described in Configure Sophos Firewall SSL VPN Remote Access.

Plan certificates, FQDNs and portal names

To users, portal problems often look like login or VPN errors, but they may begin with DNS and certificates. The pre-installed, locally signed certificates normally trigger a trust warning in browsers. Production portals should therefore use a certificate that matches the FQDN and is trusted by the clients. If WebAdmin, VPN Portal, User Portal, Captive Portal and WAF use similar hostnames or the same WAN address, their names should be deliberately separated and documented.

Typical planning:

  • WebAdmin: for example, admin.example.com. Make it reachable only from management networks, use a suitable certificate and enable MFA.
  • VPN Portal: for example, vpn.example.com. The certificate must match the download profile, and Device Access should be configured deliberately.
  • User Portal: for example, portal.example.com. Leave it enabled only if user functions are genuinely required.
  • Captive Portal: for example, login.example.com. Test the certificate, zone, session timeout and logout behaviour.
  • WAF application: for example, app.example.com. Review the WAF rule, SNI, domains and backend host together.

If the firewall itself should obtain public certificates, see Configure Let’s Encrypt certificates on Sophos Firewall. For shared wildcard certificates across several systems, Create a Let’s Encrypt wildcard certificate is the better starting point.

The operational order matters: first plan the FQDN, DNS and certificate; then restrict portal access through Administration > Device access and Local Service ACL; and only then distribute Remote Access profiles or WAF rules. After a change to the SSL VPN port, protocol, interface or SSL server certificate, manually distributed .ovpn profiles must be imported again. For FQDN-only or DNS-only changes, check separately whether profiles, bookmarks and monitoring still contain the old name.

Understand the role of Captive Portal

The Captive Portal is not a Remote Access portal. It is used when users on the network must first complete a browser login before the firewall can associate traffic with a user identity. This can be useful for guests, BYOD devices or environments without transparent user identification.

For a guest wireless network managed directly by SFOS with vouchers or a password of the day, the wireless hotspot is the more appropriate process. The hotspot guide explains the access type, voucher limits, HTTPS and the automatically generated firewall rule.

For classic sign-in with local, AD, LDAP, or RADIUS users, Set up and test Sophos Firewall Captive Portal covers the authentication method and DNS rule through to the user rule, Live users, and Log Viewer.

When the firewall must generate temporary accounts for visitors, Create and securely manage guest users on Sophos Firewall explains the separate account, group, validity, and cleanup logic.

The default address is https://<Firewall-IP>:8090. In dual-stack networks, users must sign in separately for IPv4 and IPv6 destinations. If MFA is required, the user must first register the OTP in the User Portal and then use their password and OTP at the Captive Portal.

Typical use cases:

  • Guests or BYOD devices must sign in before internet access is permitted.
  • User-based firewall rules must apply even though no STAS, SATC or other transparent mechanism is available.
  • Individual networks need simple user mapping without full endpoint integration.

Captive Portal should not be treated as a substitute for proper network segmentation. If a network requires particular protection, separation through zones, VLANs and clear firewall rules remains more important. The fundamentals are covered in Plan zones and interfaces on Sophos Firewall. For conventional user integration with Active Directory, see Integrate Active Directory with Sophos Firewall.

When Captive Portal is used with Microsoft Entra ID SSO, the process differs from VPN Portal or Sophos Connect. See Configure Microsoft Entra ID SSO for Sophos Firewall Captive Portal.

Important operational points:

  • Captive Portal requires reachable local firewall services. Device Access and Local Service ACL must be configured accordingly.
  • Session timeouts should suit the environment. Sessions that are too long weaken user attribution, while sessions that are too short disrupt users.
  • Logout, group mapping and Log Viewer should be tested with real test users.
  • The Captive Portal options for automatic logout do not apply to users who sign in with Microsoft Entra ID SSO. This process requires a separate session and logout test.
  • In networks containing sensitive systems, Captive Portal is generally not strong enough as the only control.

If Captive Portal cannot be reached from a network, do not start by changing ordinary firewall rules. The cause is often Administration > Device access, Local Service ACL Exception Rules, DNS, the certificate or incorrect zone mapping. For local access control, see Device Access and Local Service ACL on Sophos Firewall.

Operations, documentation and security

Choosing the right portal is only part of the task. Access, documentation and operational processes must also be reviewed regularly.

Check documentation deliberately

For current technical details, official Sophos Docs and release notes are more important than old blog posts or screenshots. Version-dependent information should be checked before making a production change, especially for SFOS versions, Sophos Connect, licensing changes, platform support and known limitations. Such sources should only be linked in the article itself when the admin genuinely needs to open them for the specific task.

For firmware topics, download availability is not the only consideration. Before an update, the platform, upgrade path, backup, HA state and known blockers all matter. The process is described in Check Sophos Firewall before an SFOS 22 upgrade and Sophos Firewall firmware update: preparation and best practices.

Security check for portal access

Portals are convenient, but every login is a potential attack surface. Review the following regularly:

  • Which SophosID and Central admins still exist?
  • Is MFA enabled for SophosID, Sophos Central and firewall admins?
  • Are WebAdmin, SSH, User Portal, VPN Portal and SSL VPN reachable only where they are needed?
  • Are there shared admin accounts that should be replaced?
  • Are failed logins reviewed regularly?
  • Have old VPN profiles, old users and former service providers been removed?
  • Is there a recent backup and are the recovery credentials known?

For local firewall services, Device Access is the central control point. For longer log retention or security monitoring, see Send Sophos Firewall syslog to a SIEM.

FAQ

Is SophosID the same as Sophos Central?

No. SophosID is the personal account or identity for Sophos services. Sophos Central is the cloud management platform in which products, devices, users, licences and security functions are managed.

Which portal do I need for a Sophos Firewall?

The firewall’s WebAdmin Console is required for local operation. SophosID, Sophos Central and the Support Portal may also be relevant for registration, licensing, support, Central Management or Reporting.

Where do I open a Sophos support ticket?

Support tickets are opened in the Sophos Support Portal. Gather the serial number, licence status, firmware version, error description, logs and relevant time windows beforehand.

Should the User Portal or VPN Portal be accessible from the internet?

According to Sophos, the User Portal should not be enabled for the WAN zone. The VPN Portal may be reachable from the internet for Remote Access when required, provided it is protected with MFA, a suitable certificate, restrictive Remote Access policies and login monitoring.

Is Captive Portal an alternative to VPN Portal?

No. Captive Portal is intended for users on the local network who sign in through a browser so that the firewall can associate traffic with a user identity. VPN Portal and Remote Access instead provide access from outside to internal resources.

Where can I find current Sophos Firewall release notes?

Current release notes are available in the official Sophos documentation. When planning an upgrade, also review the relevant Avanet KB articles on firmware, backup, HA and Remote Access.