Skip to content

Update Caches and Message Relays

An Update Cache downloads updates from Sophos Fusion and distributes them to devices through a machine on your local network. If you configure a device as an Update Cache, you can also configure it as a Message Relay. A Message Relay acts as a proxy for communication between Sophos Fusion and your local devices.

Update Caches and Message Relays help save bandwidth by limiting Sophos Fusion communication to specific devices. This configuration also increases security by removing the need for direct access to Sophos Fusion for any device that isn't configured as an Update Cache or Message Relay. By configuring Update Caches and Message Relays prior to a Sophos deployment, you can install Sophos on devices that can't connect directly to Sophos Fusion.

We recommend that each remote site has a server configured as an Update Cache and Message Relay to reduce bandwidth usage and cross-site traffic. You can configure up to 500 Update Caches per Sophos Fusion account.

Video

This video shows the system requirements for Update Caches and Message Relays, how they work, and how to configure them in Sophos Fusion.

Requirements

The requirements differ for servers and endpoints.

Click the appropriate tab to see the requirements.

A server must meet the following requirements to be configured as an Update Cache and Message Relay:

  • Sophos Server Protection license.
  • One of the following Windows or Linux operating systems:

    • Windows 2008 R2, Windows 2012, Windows 2012 R2, Windows 2016, Windows 2019, Windows 2022, or Windows 2025.
    • Any Linux distribution from the "Tested platforms" list on the Sophos Protection for Linux system requirements page. See Sophos release notes.

      Linux device support isn't available for all customers.

  • At least 8 GB of free disk space.

  • TCP ports 8191 Cache and 8190 Relay open to devices that will be using the Update Cache and Message Relay.
  • DNS must be able to resolve the device's IP address.

In small site where servers may not be locally available, endpoints can be configured as Update Caches if they meet the following requirements:

  • Sophos Endpoint Protection license.
  • One of the following Windows or Linux operating systems:

    • Windows 10 x64 or Windows 11 x64
    • Any Linux distribution from the "Tested platforms" list on the Sophos Protection for Linux system requirements page. See Sophos release notes.

      Linux device support isn't available for all customers.

  • At least 8 GB of free disk space

  • TCP port 8191 open to devices that will be using the Update Cache.
  • DNS must be able to resolve the device's IP address.

In addition to the minimum system requirements listed on Sophos Fusion Windows Server System Requirements, Sophos Protection for Linux Release Notes, and Sophos Fusion Windows Endpoint System Requirements, we recommend 8 GB of RAM and the following number of CPUs, depending on how many devices will be connecting to the Update Caches and Message Relays:

  • Up to 2000 devices: 2 CPUs
  • 2000 to 5000 devices: 4 CPUs
  • More than 5000 devices: 6 CPUs

Updating and communication requirements

In order to use an Update Cache or Message Relay, devices must meet the following requirements:

  • Windows endpoints: Windows 7 and later.
  • Windows servers: Windows 2008 R2 and later.
  • Linux devices: Any Linux distribution from the "Tested platforms" list on the Sophos Protection for Linux system requirements page. See Sophos release notes.

    Linux device support isn't available for all customers.

  • Mac devices: MacOS 9.7.4 Cache or MacOS 9.8.0 Relay

Note

If you have Reject connections from other devices turned on at Global Settings > Synchronized Security, Sophos Firewall may block devices from contacting Update Caches or Message Relays because of a bad health status or a missing Security Heartbeat. To prevent this, or exclude your Update Cache and Message Relays from this behavior, see Synchronized Security.

Firewall requirements

The installer automatically configures Windows Firewall rules to allow communication on port 8191 when installing an Update Cache and port 8190 when installing a Message Relay. When the Update Cache or Message Relay is removed, the rules are also removed.

You must also configure any third-party network devices in your environment to allow communication between local devices and Update Caches on port 8191 and Message Relays on port 8190.

How Update Caches and Message Relays work

When you set up an Update Cache and a Message Relay, Sophos Fusion installs the Update Cache and Message Relay software on the device at the following location:

  • Windows: C:\ProgramData\Sophos\UpdateCache\www\v3\
  • Linux: /opt/sophos-spl/plugins/updatecache/var/cache

The device then downloads updates from Sophos Fusion and puts them in the cache. We don't recommend managing the files in the cache. The Update Cache removes expired files and replaces them with updated files on its own.

When you configure an Update Cache in your environment, Sophos Fusion automatically configures the computers in your network to update from it. Each time a device updates, it compares its IP address with the IP addresses of all configured Update Caches, orders the caches by calculated network distance, and updates from the closest one. If the device can't reach the closest Update Cache, it tries the next one in the list. If the device can't reach any Update Caches, it updates directly from Sophos Fusion. Manually assigning a device to an Update Cache overrides this behavior. Using caches doesn't affect how often or when computers are updated.

When you configure a Message Relay in your environment, Sophos Fusion automatically configures the computers in your network to communicate with it. Devices use Message Relays based on the following priority:

  1. A manually assigned Message Relay
  2. A Message Relay on the same host
  3. A random Message Relay in the same subnet
  4. Any other Message Relay
  5. Directly contact Sophos Fusion

To assign Update Caches and Message Relays in Sophos Fusion, click the Global Settings icon Global Settings icon. and go to Products and Services > Endpoint and Server > Update Caches & Message Relays. See Assign computers to an Update Cache or Message Relay.

If you want to prevent specific devices from using Update Caches and Message Relays, select the Don't use update caches option in the Update Management policy for those endpoints or servers. For more information on configuring Update Management policies, see Update Management Policy or Server Update Management Policy.

Configure an Update Cache and Message Relay

You can configure an Update Cache and a Message Relay at the same time, or an Update Cache only. You can also configure a Message Relay on a server that already has an Update Cache. Do as follows:

  1. Click the Global Settings icon Global Settings icon..
  2. Go to Products and Services > Endpoint and Server and click Update Caches & Message Relays.

    By default, you see a list of your cache-capable servers. You can filter the table by selecting one of the following options from the drop-down list:

    • Cache Capable Servers
    • Cache Capable Computers
    • Devices with Update Cache
    • Servers with Message Relay
  3. Select the device on which you want to configure an Update Cache or Message Relay.

  4. Click Set Up Cache/Relay.

    Note

    This button shows Set Up Cache if you select a computer instead of a server.

  5. If you selected a server, select Update Cache and, optionally, Message Relay, depending on which you want to install.

  6. Make sure your selected device meets the requirements shown in Sophos Fusion, then click Set up.

Assign computers to an Update Cache or Message Relay

You can override the default Sophos Fusion assignment for Update Caches and Message Relays by manually assigning computers to them as follows:

  1. Click the Global Settings icon Global Settings icon..
  2. Go to Products and Services > Endpoint and Server, and click Update Caches & Message Relays.
  3. Look for the device on which the cache or relay is installed, then click the link showing the number of computers in the Using Cache row or the Using Relay row.

    A window opens showing you the devices using the Update Cache or Message Relay.

  4. Click Manual assignment.

  5. Select the computers in the Available Devices list and use the picker arrow to move them to Assigned Devices.
  6. Click Save.

Remove an Update Cache or Message Relay

To remove a cache or relay, do as follows:

  1. Click the Global Settings icon Global Settings icon..
  2. Go to Products and Services > Endpoint and Server and click Update Caches & Message Relays.
  3. Select Devices with Update Cache from the drop-down list.

    You can also select Servers with Message Relay to see which servers have a Message Relay configured.

  4. Select the device you want to remove the Update Cache or Message Relay from.

  5. Reassign any devices manually assigned to it.
  6. Click Remove Cache/Relay.

    Note

    This button shows Remove Cache if you select a computer instead of a server.

  7. Click Remove.

    Sophos Fusion uninstalls the Update Cache, the cached updates, and the Message Relay, if configured. Devices are reconfigured to use another Update Cache or Message Relay. If all Update Caches and Message Relays are removed, devices will directly update from and communicate with Sophos Fusion.