{"id":161940,"date":"2024-09-30T08:12:00","date_gmt":"2024-09-30T07:12:00","guid":{"rendered":"https:\/\/www.avanet.com\/?p=161940"},"modified":"2024-09-30T09:18:03","modified_gmt":"2024-09-30T08:18:03","slug":"sophos-firewall-migration-from-xg-to-xgs","status":"publish","type":"post","link":"https:\/\/www.avanet.com\/en\/blog\/sophos-firewall-migration-from-xg-to-xgs\/","title":{"rendered":"Sophos Firewall migration from XG to XGS"},"content":{"rendered":"\n<p>Migrating from Sophos XG Firewall to the new XGS series is an urgent matter for many organizations as the <a href=\"https:\/\/www.avanet.com\/en\/blog\/the-time-to-switch-to-the-xgs-firewall-hardware-is-coming-soon\/\">End-of-Life date of the XG series approaches<\/a>.\nThis blog post provides a comprehensive guide for IT administrators to successfully migrate from XG to XGS and highlights the key benefits and differences between the two firewall series.\nIf you absolutely don&#8217;t feel like taking care of it, we have already done many migrations and are happy to take care of it<a href=\"https:\/\/www.avanet.com\/en\/contact\/\">(contact us<\/a>).  <\/p>\n\n<div class=\"wp-block-rank-math-toc-block\" id=\"rank-math-toc\"><h2>Topics<\/h2><nav><ul><li class=\"\"><a href=\"#titel\">Why migrate from XG to XGS?<\/a><\/li><li class=\"\"><a href=\"#migrationsprozess-im-detail\">Migration process in detail<\/a><ul><li class=\"\"><a href=\"#vorbereitung\">Preparation<\/a><ul><li class=\"\"><a href=\"#sophos-firewall-v-20-mr-2\">Sophos Firewall v20 MR2 Upgrade<\/a><\/li><\/ul><\/li><li class=\"\"><a href=\"#backup-wiederherstellung\">Backup restore<\/a><\/li><li class=\"\"><a href=\"#nachbearbeitung-und-tests\">Post-processing and tests<\/a><\/li><\/ul><\/li><li class=\"\"><a href=\"#full-step-by-step-video-guides\">Step-by-step video instructions<\/a><ul><li class=\"\"><a href=\"#single-appliance-1\">Single Appliance<\/a><\/li><li class=\"\"><a href=\"#upgrading-an-ha-configuration\">XG to XGS Migration (High Availability)<\/a><\/li><\/ul><\/li><li class=\"\"><a href=\"#faq\">FAQ<\/a><ul><li class=\"\"><a href=\"#faq-question-1726838111758\">When will support for the XG series end?<\/a><\/li><li class=\"\"><a href=\"#faq-question-1726838131822\">Can I migrate from any XG firewall to any XGS firewall?<\/a><\/li><li class=\"\"><a href=\"#faq-question-1726838153515\">Do I need a new license for the XGS firewall?<\/a><\/li><li class=\"\"><a href=\"#faq-question-1726838206020\">Which version of SFOS is required for the migration?<\/a><\/li><li class=\"\"><a href=\"#faq-question-1726838246090\">How long does the migration take on average?<\/a><\/li><li class=\"\"><a href=\"#faq-question-1726838269818\">Is it possible to migrate from a wireless XG to a non-wireless XGS?<\/a><\/li><li class=\"\"><a href=\"#faq-question-1726838291541\">Is it possible to exchange backups between different models (1U, 2U, desktop)?<\/a><\/li><li class=\"\"><a href=\"#faq-question-1726838329330\">Can the migration be carried out without downtime?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n\n<h2 class=\"wp-block-heading\" id=\"titel\">Why migrate from XG to XGS?<\/h2>\n\n<p>The <a href=\"https:\/\/www.avanet.com\/en\/kb\/sophos-product-lifecycle-calendar-end-of-sale-end-of-life\/\">Sophos XG series will be officially discontinued on March 31, 2025<\/a>.\nThis means no more updates, no more support and no more license orders after the end of March 2025. <\/p>\n\n<p>There are several reasons why this change makes sense:<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Price increase:<\/strong> One reason is that Sophos has <a href=\"https:\/\/www.avanet.com\/en\/blog\/sophos-xg-firewall-licenses-get-30-percent-more-expensive\/\">increased the prices for the XG licenses by 30%<\/a> and it is only worth staying on the old hardware to a limited extent.\nYes, we have to mention this again and again, as this was simply an uncool action by the manufacturer and has a very bland aftertaste \ud83d\udca9. <\/li>\n\n\n\n<li><strong>Future-proof<\/strong>: Future software releases such as <a href=\"https:\/\/www.avanet.com\/en\/blog\/sophos-firewall-v21-0\/\">Sophos Firewall v21<\/a> will only be available for the XGS series.<\/li>\n\n\n\n<li><strong>Higher performance:<\/strong> The XGS series is equipped with a dual-processor architecture that is specially optimized for high loads and encrypted data traffic.\nBy using multi-core CPUs, encryption operations such as TLS inspection can be carried out much more efficiently. <\/li>\n\n\n\n<li><strong>Improved hardware quality:<\/strong> The XGS series was developed in close cooperation with leading hardware manufacturers, resulting in greater reliability and a longer service life for the devices.\nIn addition, the devices have been extensively tested to ensure the highest quality standards. <\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\" id=\"migrationsprozess-im-detail\">Migration process in detail<\/h2>\n\n<p>Migrating from XG to XGS is relatively easy thanks to the seamless backup and restore function.\nHere are the most important steps: <\/p>\n\n<h3 class=\"wp-block-heading\" id=\"vorbereitung\">Preparation<\/h3>\n\n<ul class=\"wp-block-list\">\n<li><strong>Create a backup of the XG configuration<\/strong>: Before the migration, you should create a current <a href=\"https:\/\/www.avanet.com\/en\/kb\/creating-or-restoring-a-sophos-sfos-backup\/\">backup of the XG firewall<\/a>.\nIt is important that the backup encryption password and the Secure <a href=\"https:\/\/docs.sophos.com\/nsg\/sophos-firewall\/20.0\/help\/en-us\/webhelp\/onlinehelp\/AdministratorHelp\/ControlCenter\/index.html\" target=\"_blank\" rel=\"noopener\">Storage Master Key<\/a> are available. <\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li><strong>Check SFOS versions<\/strong>: At least the same or a higher version of SFOS must be installed on the XGS target device as on the XG source.\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.avanet.com\/en\/kb\/upgrading-sfos-firmware-on-a-sophos-firewall\/\">Updating the firmware on the Sophos Firewall<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n<h4 class=\"wp-block-heading\" id=\"sophos-firewall-v-20-mr-2\">Sophos Firewall v20 MR2 Upgrade<\/h4>\n\n<p>If possible, you should update the Sophos XGS Firewall to <a href=\"https:\/\/www.avanet.com\/en\/blog\/sophos-firewall-v20-mr2\/\">Sophos Firewall v20 MR2<\/a> or higher before restoring the config, as the migration process has been improved considerably in this version.<\/p>\n\n<p>The backup and restore wizard makes it much easier to migrate firewall configurations.\nYou can create backups of versions from v19.5 MR4 and restore them to v20 MR2 or higher.\nThis simplifies the upgrade from XG to XGS as well as the migration between XGS models or to\/from virtual and cloud appliances.\nInterfaces can be flexibly assigned, which is particularly helpful for network infrastructure optimization.\nPseudo interfaces act as placeholders for unused interfaces.    <\/p>\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\"> \n<iframe loading=\"lazy\" title=\"Sophos Firewall v20: Backup-Restore Enhancements\" width=\"1290\" height=\"726\" src=\"https:\/\/www.youtube.com\/embed\/hXfI-Nj7GCw?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n <\/div><figcaption class=\"wp-element-caption\">Sophos Firewall XG to XGS &#8211; Backup and restore for an HA cluster<\/figcaption><\/figure>\n\n<h3 class=\"wp-block-heading\" id=\"backup-wiederherstellung\">Backup restore<\/h3>\n\n<p>The backup of the XG can be transferred directly to the XGS.\nThe migration assistant function offers the option of adjusting the port assignments if the hardware configurations of the two devices differ. <\/p>\n\n<div class=\"wp-block-stackable-image stk-block-image stk-block stk-48c10d1\" data-block-id=\"48c10d1\"><style>.stk-48c10d1 .stk-img-figcaption{text-align:center !important;color:#abb7c2 !important;}<\/style><figure><span class=\"stk-img-wrapper stk-image--shape-stretch stk--has-lightbox\"><img loading=\"lazy\" decoding=\"async\" class=\"stk-img wp-image-161189\" src=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-v20-mr2-backup-restore-config-ports-scaled.jpg\" width=\"2560\" height=\"1442\" alt=\"Sophos Firewall XG to XGS - Backup \/ Restore Interface mapping (SFOS v20 MR2)\" srcset=\"https:\/\/www.avanet.com\/assets\/sophos-firewall-v20-mr2-backup-restore-config-ports-scaled.jpg 2560w, https:\/\/www.avanet.com\/assets\/sophos-firewall-v20-mr2-backup-restore-config-ports-300x169.jpg 300w, https:\/\/www.avanet.com\/assets\/sophos-firewall-v20-mr2-backup-restore-config-ports-1024x577.jpg 1024w, https:\/\/www.avanet.com\/assets\/sophos-firewall-v20-mr2-backup-restore-config-ports-768x433.jpg 768w, https:\/\/www.avanet.com\/assets\/sophos-firewall-v20-mr2-backup-restore-config-ports-1536x865.jpg 1536w, https:\/\/www.avanet.com\/assets\/sophos-firewall-v20-mr2-backup-restore-config-ports-2048x1154.jpg 2048w, https:\/\/www.avanet.com\/assets\/sophos-firewall-v20-mr2-backup-restore-config-ports-600x338.jpg 600w, https:\/\/www.avanet.com\/assets\/sophos-firewall-v20-mr2-backup-restore-config-ports-64x36.jpg 64w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/span><figcaption class=\"has-text-color stk-img-figcaption\">Sophos Firewall XG zu XGS &#8211; Backup \/ Restore Interface Mapping (SFOS v20 MR2)<\/figcaption><\/figure><\/div>\n\n<ul class=\"wp-block-list\">\n<li>Sophos has removed the restrictions so that you can now easily migrate configurations between devices with different numbers of ports.\nIt is also possible to restore a backup of a wireless device to an XGS appliance without integrated WLAN functionality. <\/li>\n\n\n\n<li>The port mapping wizard (in v20 MR2) allows you to flexibly determine how the current hardware ports should be mapped to the new device.<\/li>\n<\/ul>\n\n<p>You<span style=\"font-size: revert; background-color: var(--has-boxed, var(--theme-palette-color-8)); color: var(--theme-text-color); font-family: var(--theme-font-family); font-style: var(--theme-font-style, inherit); font-weight: var(--theme-font-weight); letter-spacing: var(--theme-letter-spacing); text-transform: var(--theme-text-transform);\"> can check whether a backup is compatible between XG and XGS hardware, cloud or virtual devices<\/span> on the <a href=\"https:\/\/docs.sophos.com\/nsg\/sophos-firewall\/reference\/backup_restore\/port_mapping\/en-us\/\" data-type=\"link\" data-id=\"https:\/\/docs.sophos.com\/nsg\/sophos-firewall\/reference\/backup_restore\/port_mapping\/en-us\/\" target=\"_blank\" rel=\"noopener\">Sophos XG Backup Compatibility Tool<\/a> website<span style=\"font-size: revert; background-color: var(--has-boxed, var(--theme-palette-color-8)); color: var(--theme-text-color); font-family: var(--theme-font-family); font-style: var(--theme-font-style, inherit); font-weight: var(--theme-font-weight); letter-spacing: var(--theme-letter-spacing); text-transform: var(--theme-text-transform);\">.<\/span><\/p>\n\n<h3 class=\"wp-block-heading\" id=\"nachbearbeitung-und-tests\">Post-processing and tests<\/h3>\n\n<ul class=\"wp-block-list\">\n<li><strong>Make corrections<\/strong>: After restoration, all settings should be checked and adjusted if necessary, especially the network interfaces, VLANs and firewall rules.<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li><strong>Perform tests<\/strong>: Finally, you should comprehensively test the functionality of the firewall to ensure that all services and rules have been migrated correctly.<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\" id=\"full-step-by-step-video-guides\">Step-by-step video instructions<\/h2>\n\n<p>In this video, the process for switching from XG to XGS is explained again:<\/p>\n\n<figure class=\"wp-block-embed is-type-video is-provider-vimeo wp-block-embed-vimeo wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\"> \n<iframe loading=\"lazy\" title=\"Upgrading your Sophos Firewall from XG to XGS\" src=\"https:\/\/player.vimeo.com\/video\/990667314?dnt=1&amp;app_id=122963\" width=\"1290\" height=\"726\" frameborder=\"0\" allow=\"autoplay; fullscreen; picture-in-picture; clipboard-write\"><\/iframe>\n <\/div><figcaption class=\"wp-element-caption\">Sophos Firewall from XG to XGS<\/figcaption><\/figure>\n\n<h3 class=\"wp-block-heading\" id=\"single-appliance-1\">Single Appliance<\/h3>\n\n<p>This video explains how to migrate from Sophos XG to XGS Firewalls using the new Backup Restore Assistant.\nIt covers the prerequisites, including compatibility, the backup encryption password and the Secure Storage Master Key.\nIt shows step-by-step how to create a backup, transfer it to the target device and complete the configuration.\nImportant: The port assignment must be checked in advance, as it can no longer be changed after the restore.\nFurther details in the linked video.    <\/p>\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\"> \n<iframe loading=\"lazy\" title=\"Sophos Firewall v20: XG to XGS Migration\" width=\"1290\" height=\"726\" src=\"https:\/\/www.youtube.com\/embed\/220k8rBFzJ4?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n <\/div><figcaption class=\"wp-element-caption\">Sophos Firewall XG to XGS &#8211; Migration<\/figcaption><\/figure>\n\n<p>For an HA cluster, the process is identical, with the main addition being to configure the HA link, which must use a suitable port type on both the old and new systems.<\/p>\n\n<h3 class=\"wp-block-heading\" id=\"upgrading-an-ha-configuration\">XG to XGS Migration (High Availability)<\/h3>\n\n<p>The video shows the migration from Sophos XG to XGS Firewalls in a high-availability configuration with the new Backup Restore Assistant.\nIt explains prerequisites such as compatibility, the backup encryption password and the Secure Storage Master Key.\nThe migration process is shown step by step: Create backup, transfer to the target device, adjust ports and finalize the configuration.\nImportant: The HA-Link port assignment must match in advance.\nPseudo ports should be avoided.\nFurther details in the linked video.     <\/p>\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\"> \n<iframe loading=\"lazy\" title=\"Sophos Firewall v20: XG to XGS Migration (High Availability)\" width=\"1290\" height=\"726\" src=\"https:\/\/www.youtube.com\/embed\/3Q9DSjcSBHM?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n <\/div><figcaption class=\"wp-element-caption\">Sophos Firewall XG to XGS &#8211; backup and restore<\/figcaption><\/figure>\n\n<h2 class=\"wp-block-heading\" id=\"faq\">FAQ<\/h2>\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1726838111758\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">When will support for the XG series end?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>On March 31, 2025.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1726838131822\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Can I migrate from any XG firewall to any XGS firewall?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Almost any migration is possible, but there are restrictions on the number of ports and special models.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1726838153515\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Do I need a new license for the XGS firewall?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes, a new license is required, but there are attractive promo offers for switching.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1726838206020\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Which version of SFOS is required for the migration?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>At least SFOS 18.5 for a smooth migration.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1726838246090\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How long does the migration take on average?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Depending on the complexity of the configuration, the migration can take between 30 minutes and several hours.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1726838269818\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Is it possible to migrate from a wireless XG to a non-wireless XGS?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes, provided that the local Wi-Fi configuration is removed before the migration.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1726838291541\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Is it possible to exchange backups between different models (1U, 2U, desktop)?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>In most cases yes, but there are restrictions on the port configuration.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1726838329330\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Can the migration be carried out without downtime?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>No, a short downtime is necessary because you only have to move the cabling.<br \/>\nHowever, if everything is well planned, the downtime is less than 5 minutes. <\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Migrating from Sophos XG Firewall to the new XGS series is an urgent matter for many organizations as the End-of-Life date of the XG series approaches. This blog post provides a comprehensive guide for IT administrators to successfully migrate from XG to XGS and highlights the key benefits and differences between the two firewall series. [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":21333,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[277],"tags":[],"class_list":["post-161940","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/161940","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/comments?post=161940"}],"version-history":[{"count":0,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/posts\/161940\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media\/21333"}],"wp:attachment":[{"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/media?parent=161940"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/categories?post=161940"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.avanet.com\/en\/wp-json\/wp\/v2\/tags?post=161940"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}