Sophos XG Series Firewalls End-of-Life
Affected Products
XG Series Models: XG 86, XG 86w, XG 106, XG 106w, XG 115, XG 115w, XG 125, XG 125w, XG 135, XG 135w, XG 210, XG 230, XG 310, XG 330, XG 430, XG 450, XG 550, XG 650, XG 750.
XG 85 and XG 105 have already reached EOL and are no longer supported.
End of Life (EOL) Date
March 31, 2025
Why So Soon?
In general, the lifecycle of firewalls is significantly shorter compared to other network devices such as routers and switches, but this happens for important reasons. To maintain the same or higher level of performance as software complexity and customer demands increase, it is sometimes necessary to upgrade hardware specifications.
For this reason, Sophos network security hardware is updated at regular intervals to leverage the latest technological innovations, and the company introduces a successor product to meet new needs and technological requirements. Typically, as in the current period, this announcement is accompanied by offers that make the cost of upgrading nearly equivalent to the cost of renewing a subscription.
According to the published policy, the EOL date for XG appliances is set 3 years after the corresponding End-of-Sales date. In this case, the minimum guaranteed lifespan for Sophos XG Firewalls was 3 years, in line with many comparable solutions from other vendors.
For XGS Series devices, the announced lifespan is 5 years. Additionally, in October, the new generation of XGS desktop devices (Gen2) was introduced, meaning that the lifespan of devices operating in the coming period is expected in excess of 7 years!
Will XG Series Devices Continue to Function After the EOL Date?
XG Series Sophos Firewalls with an active subscription will continue to operate after the EOL date, but over time, functionality and security will degrade. There will be no further updates to the Sophos Firewall OS or the software for the XG Series. If vulnerabilities are discovered, Sophos will not provide patches or fixes.
Functions such as routing, VPN, high availability, and reporting will not be immediately affected, as they do not rely on data or service updates. However:
Features dependent on pattern updates or live lookup services will be impacted:
- Threat Protection: Updates for antivirus signatures and engines, including Sophos and Avira, will cease.
- IPS (Intrusion Prevention System): IPS signature and engine updates will stop.
- Anti-Spam: SASI signature and engine updates will no longer be available.
- Sophos X-Ops Threat Feeds: Protection against new threats will end.
- Web Filtering and Email Filtering: These may fail, causing disruptions in data flow in addition to an inability to detect new threats.
- URL Classification: URL lookup services will no longer be available.
Example of Active Subscription Until June 30, 2025:
- June 25, 2025 (active subscription):
The IPS engine will provide protection based on the last installed pattern before the EOL date (March 31, 2025). No new patterns will be available after the EOL. - July 1, 2025 (subscription expiration):
The IPS engine will no longer scan network traffic, resulting in no protection being provided.
Will Branch Connectivity via SD-RED be affected?
The management of connected SD-RED devices depends on the Network Protection subscription. This functionality will be affected if the subscription expires.
What happens to the XG license during the transition?
Any license renewals for existing XG devices will have an expiration date matching the EOL. Accordingly, monthly MSP Flex subscriptions provided by the IP Partners will automatically cease.
In the case of a transition to the XGS series, a 30-day grace period is provided for XG subscriptions from the start of the new XGS license. This means the XG license will appear as expired, but its functions will continue for another 30 days.
How is a smooth transition from XG to XGS ensured?
Primarily by using the Backup/Restore process to transfer the configuration. For some time now, the Backup/Restore functionality has supported migration between any devices with port mapping options.
If you need assistance with the migration, please contact the Support Department.