Sophos Firewall Initial Setup

Sophos Firewall Initial Setup

Before you can start using a Sophos firewall, you must complete the initial setup.

In this post, I will show you step by step, how to complete the initial setup of a virtual SFOS (Sophos Firewall Operating System). The process will be similar on a physical Sophos firewall.

Prerequisites

The Process

The default admin password is admin.

SFOS will show the current IP address for PortA. The default IP address for PortA is 172.16.16.16.

SFOS will display the current IP address for PortB. The default setting for PortB is DHCP.

The first item we need to configure is a new password for the admin account. The password must be at least ten characters, one uppercase letter, one lowercase letter, one number, and one special character.

If you leave Install the latest firmware automatically selected, and there’s a new firmware, you will need to install it.

Next, we configure the secure storage master key. The secure storage master key is unique to your firewall and provides additional protection for the passwords and account details stored in the firewall configuration. You will not be able to restore a backup without knowing the master key.

The master key must be at least twelve characters, one uppercase letter, one lowercase letter, one number, and one special character.

When configuring a virtual SFOS running version 22 or newer, an internet connection is now mandatory. This was optional in SFOS versions prior to 22.

In my example, I will use the FQDN DXT-SF-FW01.dxt.local and set the time zone to America/Edmonton.

When using a virtual SFOS running version 22 or newer, registering the firewall is now mandatory. In previous versions of SFOS, you could skip the registration.

Make sure you enter the correct serial number, as it can not be changed later.

In my example, I will leave the LAN port set to PortA.

Most deployments use route mode (gateway mode).

In my example, I will be using route mode.

Because we set the firewall’s IP address using the console, we can skip it.

In my example, I will not be using DHCP on the Sophos firewall, as I already have a DHCP server.

In my example, I will enable all the network protections.

The backup encryption password must be twelve characters.

That’s all it takes to complete the initial setup on a virtual SFOS (Sophos Firewall Operating System).

If you want to remove the default GuestAP interface, my blog post Sophos Firewall Remove GuestAP Interface, goes into detail on the process.

If you need more than the 3 initial interfaces, my blog post, Sophos Firewall Interface Mapping on vSphere, goes into detail on how to add additional interfaces on a virtual SFOS and how to map them.

If you want to read more about the initial SFOS setup, here is the Sophos documentation.

Exit mobile version