Access your firewall's web admin console
How you access your firewall's web admin console depends on your firewall version. For a list of supported firewall versions, see Retirement calendar for Sophos SG UTM, Sophos Firewall, Sophos Wireless, Sophos RED, and other network products.
Note
To access your firewalls through Sophos Central Firewall Management, your Sophos Fusion administrator email address must be 50 characters or fewer. If it's longer than 50 characters, firewall access fails. As a workaround, create another administrator account with the same role and permissions and an email address that is 50 characters or fewer.
Select the tab for your firewall version.
To open the firewall's web admin console, you must be an Admin or Super Admin in Sophos Fusion.
When you're an Admin or Super Admin in Sophos Fusion, you have the same permissions as the firewall's local "admin" account. You can change the password for the "admin" account, which is necessary when you deploy firewalls via Zero Touch.
Click a firewall name to open the firewall's web admin console. This lets you view and configure the firewall.
If you're disconnected from a firewall, you can close the tab, then click the firewall name to reopen the web admin console.
Warning
Sophos Fusion firewall management doesn't allow more than one user to sign in to the firewall at the same time. If a user is already signed in to the firewall and another user accesses it through Sophos Fusion firewall management, the first user is signed out.
To open the firewall's web admin console, you must be an Admin or Super Admin in Sophos Fusion.
When you're an Admin or Super Admin in Sophos Fusion, you have the same permissions as the firewall's local "admin" account. You can change the password for the "admin" account, which is necessary when you deploy firewalls via Zero Touch.
Click a firewall name to open the firewall's web admin console. This lets you view and configure the firewall.
Your firewalls use Fast Reverse Proxy (FRP) SSO for Sophos Fusion firewall management. When you access them through Sophos Fusion or Sophos Fusion Partner, they open faster and in new tabs. You can access multiple firewalls at the same time.
If you're disconnected from a firewall, you can close the tab, then click the firewall name to reopen the web admin console.
When you access a firewall from Sophos Fusion, your firewall access is controlled by your assigned role. This ensures that you only have the required permissions for that role, including the appropriate read and write access on the firewall.
Roles and permissions
To access the firewall's web admin console, you must have an administration role in Sophos Fusion. The roles are as follows: Super Admin, Admin, Help Desk, or Read-only. For more information, see Administration roles.
If you have a custom role, you must have one of the following permissions: Full, Help Desk, or Read-only access to the firewall. For more information about custom roles, see Add a custom role.
Your Sophos Fusion role determines the level of access you receive on the firewall. This mapping is applied automatically each time you access the firewall. The access levels are as follows:
-
Full: Provides complete administrative control, including configuration and management tasks.
Note
If you have full access to the firewall, you can change the password for the "admin" account, which is required when you deploy firewalls via Zero Touch.
-
Read-only: Allows viewing of settings, configuration, and status information. Changes aren't allowed.
- Help Desk: Allows monitoring, diagnostics, and access to logs and reports. Configuration and policy changes aren't allowed.
- None: Prevents access to the firewall from Sophos Fusion.
Accessing the firewall
Click a firewall name to open the firewall's web admin console.
The firewall link in Sophos Fusion is available based on these permissions:
-
Users with Full, Read-only, or Help Desk permissions can access the firewall.
Note
These permissions are included in the Super Admin, Admin, Help Desk, and Read-only roles.
-
Users without firewall permission can't access the firewall.
When accessing the firewall from Sophos Fusion, the system applies the user's role automatically and creates a session with the corresponding permissions. Role changes in Sophos Fusion take effect the next time you access the firewall, and existing permissions on the firewall are updated to match the assigned role.
Your firewalls use Fast Reverse Proxy (FRP) SSO for Sophos Fusion firewall management. When you access them through Sophos Fusion or Sophos Fusion Partner, they open faster and in new tabs. You can access multiple firewalls at the same time.
If you're disconnected from a firewall, you can close the tab, then click the firewall name to reopen the web admin console.
Managing access and resolving issues
Role-based access is controlled in Sophos Fusion, but existing user accounts on the firewall can affect whether access is allowed. For example, if a user with the same username already exists on the firewall as a non-administrative user, access from Sophos Fusion is denied until the firewall account is updated with the appropriate permissions.
Changing access levels and firewall behavior
Access levels are managed in Sophos Fusion. You must update the user's role to change their permissions. The new access level is applied the next time the user accesses the firewall.
When a user signs in from Sophos Fusion, the firewall creates or updates the user account automatically and applies the role from Sophos Fusion. This user is managed by Sophos Fusion, and the assigned role controls what the user can view and modify.
Central-managed users can't be edited from the firewall web console. Their access is applied during sign-in based on the role in Sophos Fusion. If you want to modify these users, you must delete the user account and create a new one manually or through another authentication method.
If a Central-managed user is disabled on the firewall, access through Sophos Fusion is denied. The user sees the following message: "Sign-in failed. The user account is disabled in the firewall."
If the same username exists in another system, such as an identity provider or a local firewall account, the most recent login determines the active permissions.
Existing firewall users with the same username
Access behavior differs when a user with the same username already exists on the firewall.
If the existing firewall user has an administrator user type, access from Sophos Fusion is allowed. However, if the existing firewall user has a non-administrative user type, access is denied. In this case, the user sees the following message: "Sign-in failed. A non-administrative or guest user with the same username already exists in the firewall." This commonly occurs when users are created through identity providers such as Microsoft Entra ID. These users are typically created as non-administrative users on the firewall.
In this case, a firewall administrator must update the existing firewall user account, so the user has correct permissions before access through Sophos Fusion is allowed. This requirement applies only to the existing firewall account. The Central-managed user itself can't be modified on the firewall.
If access from Sophos Fusion is allowed, the firewall updates the user's profile and group memberships based on the role assigned in Sophos Fusion. Other non-administrative settings remain unchanged so that access to other firewall portals and services continues to work as expected.
After changing the user type, the user must access the firewall again from Sophos Fusion. The following behavior occurs:
- Sophos Fusion validates the user's role and starts the access process
- The firewall accepts the sign-in request because the account now has the correct permissions
- The firewall applies the role mapping from Sophos Fusion
- The session is created with permissions based on the user's current role
If the user's role in Sophos Fusion has changed, the updated permissions are applied during the next sign-in.
Assign only the required level of access. Keep permissions consistent across Sophos Fusion and any connected identity providers. This helps prevent conflicts where the most recent sign-in changes the effective permissions for the same username.