Coming soon - Sophos Central Firewall Manager (CFM) Release

Hi XG Community,

Sophos Central Firewall Manager (CFM) will be upgraded on April 24, 2017. This update contains features and bug fixes.

For a detailed list of features and changes in this release, please refer to  Sophos Central Firewall Manager_April 2017_Release Notes.pdf

Compatible SFOS versions

This CFM release supports firewalls running on the following Sophos Firewall OS (SFOS) versions:

  • SFOS 15.01.0 (Build 376)
  • SFOS 15.01.0 MR-1.1 (Build 407)
  • SFOS 15.01.0 MR-2 (Build 418)
  • SFOS 15.01.0 MR-3 (Build 447)       
  • SFOS 16.01.0 (Build 144)
  • SFOS 16.01.0 (Build 167)
  • SFOS 16.01.1 (Build 202)
  • SFOS 16.01.2 (Build 222)
  • SFOS 16.01.3 (Build 265)
  • SFOS 16.05.0 (Build 098)
  • SFOS 16.05.0 (Build 117)
  • SFOS 16.05.1 MR-1 (Build 139)
  • SFOS 16.05.2 MR-2 (Build 160)
  • SFOS 16.05.3 MR-3 (Build 183) 

Compatibility Matrix

 Partial support in above table indicates

  • Export template is supported
  • One can create a fresh template, configure and apply it on the managed SFOS devices. But a template cannot be created by importing configuration from a firewall running on the respective SFOS version


What's new in this release

  • Improved UX / UI
    • Improved layout and navigation that aligns with SFOS v16 and provides a more user friendly approach.
    • Full screen view to monitor more devices in single view on Device Monitor.
    • Better user experience on selecting custom group.
  • Support for managing SFOS v16 features
    • Comprehensive management that allows to manage new features and workflow updates in SFOS v16 for Web Protection, Email Protection and more.
  • RED S2S wizard
    • Configure a RED Site-to-Site tunnel between a Server and Client in single workflow.
  • SFOS Device Hostname Support
    • Option to configure Device hostname while adding devices in CFM via Device Discovery, and from list of managed devices.
  • Device monitor & Alerts now cover endpoints with Missing Heartbeat.


Display the same list of IPS signatures in CFM at device level as visible on the individual Firewall Web Admin UI for given model.

Bug Fixes

  • NCCC-4468 – Cannot apply configuration on a firewall after renaming a Firewall hostname from CFM at device level.
  • NCCC-4409 - Gateway status is displayed as disconnected (red) on CFM Device Monitor even if the Firewall Gateway is up.
  • NCCC-4391 - Route precedence applied from CFM template does not get updated on the Firewall CLI settings.
  • NCCC-4159 – Template in CFM cannot be deleted.
  • NCCC-2217 – Junk character displayed on CFM device level policy page instead of Japanese font.


Please provide feedback and discuss this upgrade or other aspects of the product with fellow community members and Sophos staff here on the forums.

If you have any feedback on our help, manual, or any documentation (Online Help) please send it to