Air Gap enables updates for XG Firewalls deployed in environments that are physically isolated from the internet (an “airgap”). Protection pattern updates can be downloaded from a public URL. Licenses, and firmware updates can be downloaded from MySophos. All updates can be applied to XG Firewall from the GUI.
This article describes how Air Gap and manual pattern updates features works. It also lists the XG Firewall's features that does not work, due to non-internet connectivity in air-gapped / physically isolated deployments. The following sections are covered:
Applies to the following Sophos products and versions Sophos XG Firewall v17.5 MR3
Log into MySophos and click on the Network Protection > Air Gap Licenses > Download Licenses button.
A single file containing the current licenses for all eligible devices will be downloaded to the browser's default download location.
Below is an example of a license file for an XG 105:
Login to the Console and type the following command to enable Air Gap:
system airgap enable
From the graphical use interface (GUI), go to Administration > Licensing to upload the license file.
Even when Air Gap is enabled, if the XG gets internet connectivity, it will start performing license sync as a usual appliance.
Only one license file for all Air Gap enabled devices under one customer account.
Manual pattern updates is available independent of AirGap feature; starting 17.5 MR3, users will be able to upload patterns manually from the GUI.
Download the pattern file from https://airgap.u2d.sophos.com/sfos_patterns_update.tar and from the XG's graphical user interface (GUI), go to Backup & Firmware > Pattern updates and upload the file.
The following features requires internet connectivity and thus they can not work with Air Gap deployment:
If you've spotted an error or would like to provide feedback on this article, please use the section below to rate and comment on the article. This is invaluable to us to ensure that we continually strive to give our customers the best information possible.
Every comment submitted here is read (by a human) but we do not reply to specific technical questions. For technical support post a question to the community. Or click here for new feature/product improvements. Alternatively for paid/licensed products open a support ticket.