Skip to content
Avanet

Sophos hardware failure: prepare RMA and replacement

When hardware fails, a clear process matters: protect operations, isolate the fault, secure the device details and backup, open a technical support case, restore the replacement device and document the return. An RMA is no substitute for a current backup, HA or an emergency plan.

The process at a glance:

  1. Confirm the hardware fault with simple cross-checks.
  2. Clarify the warranty, support status and RMA option.
  3. Prepare the serial number, fault description, logs, backup and shipping details.
  4. Open a technical support case with the RMA form.
  5. Check the replacement device, transfer the licence, restore the configuration and test operation.
  6. Return the faulty device by the deadline and according to the RMA instructions.

Check the hardware fault and entitlement

Isolate the fault

Before requesting an RMA, rule out the power supply, cable, remote device, provider, firmware or configuration as the cause. Typical signs of a hardware fault include:

  • The device does not start or hangs during boot.
  • Power, status or drive LEDs do not show a normal state.
  • Fans, the power supply or temperature readings are repeatedly abnormal. On an XGS, check the temperature and fan status via SSH.
  • A port remains down even though the cable and remote device have been checked.
  • SSD, memory or I/O errors occur repeatedly. For firewalls, also see Check the Sophos Firewall SSD health.
  • The device is physically damaged or has been unstable since a power event.
  • An SD-RED, switch or access point remains offline despite correct power and network checks.

For a Sophos Firewall, check whether WebAdmin, SSH, Log Viewer or an HA peer is still accessible. If only WebAdmin is unresponsive, the appliance is not necessarily faulty; first follow Restart the Sophos Firewall WebAdmin GUI.

For a port fault, the Device Console via SSH shows whether SFOS detects the interface. Select menu option 4 and enter:

show network interfaces

In the Advanced Shell under 5. Device Management > 3. Advanced Shell, monitor the system messages while unplugging and reconnecting the cable:

tail -f /log/syslog.log

Link or error messages for the affected port are expected. Stop the output with Ctrl+C and save the relevant lines for the support case. Further port tests can interrupt operation and should only be performed during a planned maintenance window or as instructed by support.

Warranty and support entitlement

Whether Sophos replaces a device depends on the product, serial number, purchase date, support contract, licence status and lifecycle. For HA, both serial numbers and the role of the faulty node are required. Sophos hardware warranty, support and RMA explains the differences between the basic warranty, support and Advance Hardware Replacement; a visible Base License alone does not prove entitlement to an advance RMA.

Standard or advance replacement

  • With Standard Hardware Replacement, the faulty device is returned first. Sophos ships the replacement after receiving the hardware.
  • With Advance Hardware Replacement, Sophos may ship the replacement after approving the RMA and before receiving the faulty hardware. This requires the appropriate active support cover.

The applicable process is stated in the specific RMA approval. Do not assume an advance replacement until Sophos has confirmed it.

Prepare the RMA case

Device, fault and impact

The following details help speed up the assessment:

  • product, model, serial number and hardware revision
  • firmware version and build
  • licence and Sophos Central assignment
  • purchase or delivery date
  • site and affected country
  • exact fault description, start time and frequency
  • tested power supplies, cables, ports and remote devices
  • LED states, photos, screenshots and relevant logs
  • impact on users, the site and services
  • for HA: both serial numbers, role of the faulty node and cluster status
  • available workaround or spare hardware

Instead of writing only faulty, provide a specific fault description:

  • XGS 2100 does not boot after power event
  • Port3 no link with tested cable and switch port
  • SSD errors and reporting database failures

Depending on the device state, the Sophos Firewall serial number is available in WebAdmin, Sophos Central, on the chassis or in the licence documents.

Prepare the recovery

For a firewall, determine in parallel how operation will be restored:

  • a current backup is available
  • the backup encryption password is known
  • if configured for the backup, the Secure Storage Master Key is also available
  • firmware and model compatibility for the restore has been checked
  • WAN credentials, certificates and local administrator access are available
  • HA roles, Central registration and licence transfer are understood
  • a maintenance window, rollback plan and contacts are defined
  • relevant logs are saved while the old device is still accessible

Detailed procedures are available in Backup and restore on Sophos Firewall, Save Sophos Firewall logs for support and, if required, Reinstall Sophos Firewall OS using a USB drive.

For a cluster, also document the HA status and role of the faulty appliance.

⚠️ During a production outage, recovery and the RMA should proceed in parallel. The replacement process provides hardware, but not a working configuration.

Open a support case for the RMA

An RMA starts with a technical support case. Sophos Support checks the fault and entitlement; Customer Care then creates the RMA and the compliance review releases the shipment. The general portal process is explained in Open a Sophos support ticket.

This template combines the technical details with the current RMA form and can be copied into the case:

Subject: RMA request - Sophos Firewall XGS 2100 - serial C123456789

===================================================
Technical Issue
===================================================
Description/RMA Reason:
Troubleshooting performed:
Business impact:
Attachments:
Fault Code: (leave it for Sophos Support to fill)
Sub Fault Code: (leave it for Sophos Support to fill)

======================================
Defective Product Details/License Details
======================================
Model/Product:
Revision:
Firmware version:
Serial # of faulty device:
License #:
Dead on arrival: Y/N
Is this part of a HA Cluster: Y/N
HA role and peer serial number:

======================================
Shipping Info (All fields required)
======================================
Company:
TAX ID / VAT number:
Contact name:
Address:
City:
Zip/Postal code:
Country:
Phone:
Email:
Special Instructions:

For shipments to the EU, Sophos requires a VAT number; no replacement device can be shipped without the required tax details. Sophos generally ships to the country where the original hardware was purchased. Different locations or import requirements should therefore be clarified in the case.

English is not a published Sophos requirement, but it can simplify the international handover of the case. Attach only the necessary photos, screenshots and log extracts, without unnecessary confidential data.

Sophos describes each status step in its official RMA process. For a fully processed Advance RMA approved before the regional cut-off, Sophos aims to ship on the next business day. A delivery date is not guaranteed; compliance checks, queries, import procedures, weekends, public holidays and carriers can cause delays.

⚠️ Advance Hardware Replacement is not a high-availability solution either. Critical sites require HA, suitable spare hardware or a documented emergency plan.

Restore and check the replacement device

When the replacement device arrives:

  1. Check the model, revision and contents against the RMA. Replacement hardware may be new, refurbished, repaired or another suitable revision.
  2. For SG/XG/XGS running SFOS, claim the replacement device in the same Sophos Central account and check the proposed licence transfer. This deregisters the faulty device. For HA, first check the role-dependent HA transfer process.
  3. Do not assume the same SFOS version. Compare the firmware version, target model and backup compatibility before restoring; in Active-Passive HA, the build must match the healthy peer.
  4. Restore the backup with the encryption password and, where applicable, the Secure Storage Master Key.
  5. Test WAN, LAN, VLANs, routing, DNS and DHCP.
  6. Check firewall rules, NAT, VPN and Remote Access. For packet flow, see Test a firewall rule with Log Viewer, Policy Test and Packet Capture.
  7. Check HA, Sophos Central, reporting, logs and monitoring.
  8. Document the result, new serial number and return tracking in the existing case.

If problems remain, add the specific test results to the existing case. Opening a new case without referring to the RMA makes tracking more difficult.

Return the faulty device

For an advance replacement, the current Sophos RMA process specifies a return deadline of 15 days after receipt of the replacement device. Other Sophos contract documents do not phrase the start of the deadline in exactly the same way, so the specific RMA email and the date stated there take precedence. Arrange the return immediately after the licence transfer and successful recovery.

For a standard replacement, the customer pays the return shipping costs. For an advance replacement, the return is handled by the carrier specified by Sophos at Sophos’ expense; depending on the country, customs and local obligations may still rest with the customer.

DHL collection with an existing label

If the RMA instructions specify DHL and a valid return label is already available, book a DHL collection. In the German DHL form shown below, select Nein only if the label is already attached to the parcel.

DHL form for a collection with an existing return label
With an existing label, the collection is scheduled using its shipment number.

The shipment number is printed on the return label. Record it together with the collection date and confirmation in the RMA case.

DHL return label with the waybill shipment number highlighted
The highlighted waybill number is required for collection and tracking.

Device, accessories and data

  • Return the faulty hardware as a complete unit and, where possible, in the replacement device’s box.
  • Do not remove internal HDDs, SSDs or other components unless Sophos expressly permits this in writing.
  • Normally retain external accessories such as power supplies, transceivers, Flexi Port modules, rackmount kits, antennas and cables unless the RMA instructions state otherwise.
  • Back up the configuration and data or erase them according to internal policy where technically possible. If the device is no longer accessible, document the data risk in the case and wait for Sophos’ instructions.
  • Retain the return label, tracking number, shipping date and proof of delivery.
  • Dispose of hardware only when expressly instructed to do so by Sophos in writing.

If the return is late, incomplete or not made, Sophos may charge the full price of the replacement device or missing components. The case is complete only when Sophos has received and inspected the return or confirmed an authorised disposal.

FAQ

Is a Sophos RMA replacement device always new?

No. Sophos may supply new, refurbished or repaired hardware, or another suitable revision. Check the model, revision, firmware compatibility and contents before restoring.

What if data can no longer be erased from the faulty device?

Do not open the device or remove internal storage without authorisation. Document the failure and data risk in the support case, then follow Sophos’ written instructions and the organisation’s internal data protection requirements.