Skip to content

Access your firewall's web admin console

How you access your firewall's web admin console depends on your firewall version. For a list of supported firewall versions, see Retirement calendar for Sophos SG UTM, Sophos Firewall, Sophos Wireless, Sophos RED, and other network products.

Select the tab for your firewall version.

To open the firewall's web admin console, you must be an Admin or Super Admin in Sophos Central.

When you're an Admin or Super Admin in Sophos Central, you have the same permissions as the firewall's local "admin" account. You can change the password for the "admin" account, which is necessary when you deploy firewalls via Zero Touch.

Click a firewall name to open the firewall's web admin console. This lets you view and configure the firewall.

If you're disconnected from a firewall, you can close the tab, then click the firewall name to reopen the web admin console.

Warning

Sophos Central firewall management doesn't allow more than one user to sign in to the firewall at the same time. If a user is already signed in to the firewall and another user accesses it through Sophos Central firewall management, the first user is signed out.

To open the firewall's web admin console, you must be an Admin or Super Admin in Sophos Central.

When you're an Admin or Super Admin in Sophos Central, you have the same permissions as the firewall's local "admin" account. You can change the password for the "admin" account, which is necessary when you deploy firewalls via Zero Touch.

Click a firewall name to open the firewall's web admin console. This lets you view and configure the firewall.

Your firewalls use Fast Reverse Proxy (FRP) SSO for Sophos Central firewall management. When you access them through Sophos Central or Sophos Central Partner, they open faster and in new tabs. You can access multiple firewalls at the same time.

If you're disconnected from a firewall, you can close the tab, then click the firewall name to reopen the web admin console.

When you access a firewall from Sophos Central, your firewall access is controlled by your assigned role. This ensures that you only have the required permissions for that role, including the appropriate read and write access on the firewall.

Roles and permissions

To access the firewall's web admin console, you must have an administration role in Sophos Central. The roles are as follows: Super Admin, Admin, Help Desk, or Read-only. For more information, see Administration roles.

If you have a custom role, you must have one of the following permissions: Full, Help Desk, or Read-only access to the firewall. For more information about custom roles, see Add a custom role.

Your Sophos Central role determines the level of access you receive on the firewall. This mapping is applied automatically each time you access the firewall. The access levels are as follows:

  • Full: Provides complete administrative control, including configuration and management tasks.

    Note

    If you have full access to the firewall, you can change the password for the "admin" account, which is required when you deploy firewalls via Zero Touch.

  • Read-only: Allows viewing of settings, configuration, and status information. Changes aren't allowed.

  • Help Desk: Allows monitoring, diagnostics, and access to logs and reports. Configuration and policy changes aren't allowed.
  • None: Prevents access to the firewall from Sophos Central.

Accessing the firewall

Click a firewall name to open the firewall's web admin console.

The firewall link in Sophos Central is available based on these permissions:

  • Users with Full, Read-only, or Help Desk permissions can access the firewall.

    Note

    These permissions are included in the Super Admin, Admin, Help Desk, and Read-only roles.

  • Users without firewall permission can't access the firewall.

When accessing the firewall from Sophos Central, the system applies the user's role automatically and creates a session with the corresponding permissions. Role changes in Sophos Central take effect the next time you access the firewall, and existing permissions on the firewall are updated to match the assigned role.

Your firewalls use Fast Reverse Proxy (FRP) SSO for Sophos Central firewall management. When you access them through Sophos Central or Sophos Central Partner, they open faster and in new tabs. You can access multiple firewalls at the same time.

If you're disconnected from a firewall, you can close the tab, then click the firewall name to reopen the web admin console.

Managing access and resolving issues

Role-based access is controlled in Sophos Central, but existing user accounts on the firewall can affect whether access is allowed. For example, if a user with the same username already exists on the firewall as a non-administrative user, access from Sophos Central is denied until the firewall account is updated with the appropriate permissions.

Changing access levels and firewall behavior

Access levels are managed in Sophos Central. You must update the user's role to change their permissions. The new access level is applied the next time the user accesses the firewall.

When a user signs in from Sophos Central, the firewall creates or updates the user account automatically and applies the role from Sophos Central. This user is managed by Sophos Central, and the assigned role controls what the user can view and modify.

Central-managed users can't be edited from the firewall web console. Their access is applied during sign-in based on the role in Sophos Central. If you want to modify these users, you must delete the user account and create a new one manually or through another authentication method.

If a Central-managed user is disabled on the firewall, access through Sophos Central is denied. The user sees the following message: "Sign-in failed. The user account is disabled in the firewall."

If the same username exists in another system, such as an identity provider or a local firewall account, the most recent login determines the active permissions.

Existing firewall users with the same username

Access behavior differs when a user with the same username already exists on the firewall.

If the existing firewall user has an administrator user type, access from Sophos Central is allowed. However, if the existing firewall user has a non-administrative user type, access is denied. In this case, the user sees the following message: "Sign-in failed. A non-administrative or guest user with the same username already exists in the firewall." This commonly occurs when users are created through identity providers such as Microsoft Entra ID. These users are typically created as non-administrative users on the firewall.

In this case, a firewall administrator must update the existing firewall user account, so the user has correct permissions before access through Sophos Central is allowed. This requirement applies only to the existing firewall account. The Central-managed user itself can't be modified on the firewall.

If access from Sophos Central is allowed, the firewall updates the user's profile and group memberships based on the role assigned in Sophos Central. Other non-administrative settings remain unchanged so that access to other firewall portals and services continues to work as expected.

After changing the user type, the user must access the firewall again from Sophos Central. The following behavior occurs:

  • Sophos Central validates the user's role and starts the access process
  • The firewall accepts the sign-in request because the account now has the correct permissions
  • The firewall applies the role mapping from Sophos Central
  • The session is created with permissions based on the user's current role

If the user's role in Sophos Central has changed, the updated permissions are applied during the next sign-in.

Assign only the required level of access. Keep permissions consistent across Sophos Central and any connected identity providers. This helps prevent conflicts where the most recent sign-in changes the effective permissions for the same username.