We're pleased to announce the addition of bulk firmware updating to Sophos Central firewall management! This feature is available today, for all grouped firewalls, and allows you to trigger immediate firmware updates in one action, for any number of grouped firewalls that have firmware updates available. We're also pleased to announce the arrival of Scheduled firmware updates! for firewalls running XG v18 MR3 or newer, the time when firmware updates may be installed, may be scheduled from Central.

What's New and How to Use it:

  • Bulk Firmware Upgrades - On the Group menu, Firmware Upgrades may now be selected. This option will bring up a list of firewalls with pending updates. You may select any or all of the firewalls, then with "immediately" selected for the schedule, click Schedule Upgrade. All selected firewalls will begin upgrading shortly, and you will se a spinning gear icon once the upgrade has started. 
  • Scheduled Firmware Upgrades - Requires firewalls to be running at least v18 MR3 or newer. When upgrading the firmware for a single firewall by clicking the upgrade icon, or when bulk updating firmware, you may now choose to install immediately, or schedule the update to occur at a future time and date. The schedule will be run based on the firewalls local time zone. 

  • Hi Ben, perhaps I misunderstood your question. I was commenting on the way firmware updates are staged today, based on your comment that clients not being offered updates. If firmware updates are released, but a firewall doesn't see it available yet, that's likely because staged firmware releases don't get announced to every firewall initially. firewalls receive the announcement in waves, over time. I sometimes receive the request to make that process more consistent, so a customer doesn't have some firewalls see the new firmware automatically, while others don't. 

    If you were meaning that firewalls running current versions of 17.5 haven't always had a firmware that they could apply to get to v18, then that issue should be solved now. MR3 is available, and moving forward, any 17.5 MRs should be released in tandem with v18 firmware updates. 

    If you were referring to something else, please let me know, or PM me to discuss directly, and sorry for any confusion. 

  • Hi Alan,

    Are you serious? Sophos pushed V18 as the next big thing and much better, faster etc, we upgrade major contract clients then have issues and you are saying that fixing problems in PRODUCTION firmware is not a priority? 


  • Hi Claudio, there are no plans to add any capabilities to CFM. It is scheduled for end-of-life at the end of this year. 

  • Hi Ben,

    Your request is heard, and it is on the backlog, but there are no immediate plans to tackle this yet.

  • Hi Allan, about Sophos Central Firewall Manager, is there a prevision to do SCFM full compatibility with XG 18 version. Some configurations like NAT and SSL inspection are not supported yet. I have a customer with 370 XG firewall and it would be very help.I need use v18 because I also need CFR.

    Regards,