Security protection on Sophos Firewall requires a Subscribed/Evaluating subscription.
If a subscription is Expired/Unsubscribed, Sophos Firewall cannot perform corresponding security protection.
Here is table of subscription and security features.
Reference: Sophos (XG) Firewall > Administration Help > Licensing
Once Base firewall becomes Expired/Unsubscribed,
It applies to Sophos Firewall v18 only.
On Sophos Firewall v17.5 MR15 and earlier, firewall rule and NAT rule still work even if Base Firewall becomes Expired/Unsubscribed.
Once Email Protection becomes Expired/Unsubscribed, Sophos firewall delivers email without anti-spam/anti-virus scanning.
It applied to Sophos Firewall v17.5 and v18.
If both Enhanced support and Enhanced plus support are expired/unsubscribed, Sophos cannot provide RMA and Technical Support service.
2022-01-14, fixed expired URL
2021-05-31, updated with section "Email protection"
2021-05-24, first release
Bundle basically means Hardware + Software. So you need the Standard Protection + Webserver Protection as a "a la card" license. They should be able to generate you an offer for you appliance.…
What about the other licence modules?I thought, that REDs are part of the Base Licence (same as for Wireless Protection). So the connection, ACLs and NAT should work for REDs with the base licence.
If Network Protection expires (and the base license is stil valid), all rules should still apply and control the traffic. But SOFS won't apply Security Heartbeat, IPS, ATP and SSL/TLS inspection, right?My expirience with expired Web Protection was, the Web Proxy was reachable - but didn't apply any rule itself (It was on 17.5 - and long ago. I don't know, whether this is valid).
Hello TheMonzel,
The RED device is part of the Network protection license. So you won’t be able to configure a RED device using only the Base License.
If the Network Protection expires, you’ll be able to configure any module but it won't be enforced.
Regards,