Skip to content
The XG Series hardware appliances will reach end-of-life (EOL) on March 31, 2025. Click here to see the XG to XGS migration documentation.

Backup and restore FAQs

Answers to the most frequently asked questions covering backup and restore.

Backup and restore assistant

How do I move VLANs to a different physical interface?

Take a backup of your current configuration, restore it on the same device, then change the mapping of the corresponding physical interfaces. This only applies if the backup is from 19.5 MR4 and later and restored to XGS, virtual, and cloud appliances running 20.0 MR2 and later.

Why can't I see the backup-restore assistant?

The backup-restore assistant only appears if all the following conditions are met:

  • The backup is from any appliance (XG, SG running SFOS, XGS, virtual or cloud) running 19.5 MR4 and later.
  • You're restoring to 20.0 MR2 and later.
  • You're restoring to XGS, virtual, and cloud appliances.

    Note

    If you're restoring to XG or SG series firewalls, the assistant doesn't appear.

Can I restore a backup from 19.5 MR3 and earlier to 20.0 MR2 or later?

Yes, you can restore a backup from 19.5 MR3 and earlier to 20.0 MR2 or later but the firewall doesn't show the backup-restore assistant for interface mapping.

How can I delete a pseudo port?

To delete a pseudo port, see Replace and delete pseudo ports.

Note

Unbound pseudo ports with VLAN configurations aren't deleted.

Restored configurations

Are all configurations restored?

The web admin console's default admin password isn't restored when you restore a backup. The firewall retains its existing default admin password.

All other features, including the Multi-Factor Authentication (MFA) tokens for all users, VPN users, RED, site-to-site VPN, and remote access VPN configurations, are restored when you restore a backup. Remote access VPN connections using Sophos Connect client can be established.

Can I restore backups to any firewall?

The backup must meet the following conditions:

  • To make sure the backup is compatible with the firewall, see the guidelines under Upgrade information in the firewall release notes. See Release notes.
  • To retain the HA configuration, you can only restore backups from an HA cluster to another HA cluster. See Backup-restore in HA.
  • To retain Sophos Central registration, see the following FAQ on this page:

    Does restoring a backup retain the firewall's Sophos Central registration?

Does restoring a backup retain the firewall's Sophos Central registration?

Sophos Central registration is only retained when you restore a backup to the same firewall from which the backup was taken.

Restoring a backup to a different firewall or an HA cluster deregisters the firewalls from Sophos Central. You must register the firewalls to Sophos Central and reconfigure Sophos Central services such as Security Heartbeat and Sophos ZTNA again. See Backup-restore in HA.