All Resources
Networking

Sophos Firewall Migration Checklist for Small Business Networks

Swapping out a firewall sounds like a simple hardware refresh until the cutover window arrives and something unexpected breaks, whether that is a VPN tunnel, a site-to-site link, or a piece of line-of-business software that assumed a specific IP. This checklist lays out the steps we walk through with clients moving to a Sophos firewall, in the order that keeps risk lowest.

Published August 10, 2026 Updated August 10, 2026 9 min read By Joshua Arimoro Greater Sudbury & Ontario
The short answer

A Sophos firewall migration goes smoothly when the old rule set is audited and documented first, the new device is configured and tested in parallel before the cutover, VPN and remote access are rebuilt and verified before staff arrive, and a rollback plan exists in case the new configuration needs to be reversed quickly.

Before you touch any hardware: audit the existing rule set

Every migration starts with understanding what the current firewall is actually doing, not what the original install document says it should be doing. Export the full rule set, VPN configuration, NAT rules, and any site-to-site tunnels, then go through them line by line.

This step matters because rule sets accumulate clutter over years. A rule added for a vendor that left three years ago should not be copied forward blindly into the new device. If your rules have not been reviewed recently, our guide on how often firewall rules should be reviewed covers what a proper audit checks.

Document what depends on the firewall

  • Site-to-site VPN tunnels to other offices or partners
  • Remote access VPN accounts used by staff working from home or on the road
  • Port forwards for any internet-facing service, such as a hosted phone system or remote camera feed
  • Static IP assignments and DHCP scopes handled by the current appliance
  • Any integration with Wi-Fi access points or switches for VLAN tagging

Build the new configuration in parallel

Configure the new Sophos appliance on a bench or in a lab VLAN before it ever touches production traffic. Rebuild rules deliberately rather than importing everything wholesale, since this is the natural point to drop stale rules and tighten anything overly permissive.

This is also the right time to plan segmentation properly if it has not been done already. Separating guest Wi-Fi, staff devices, and any point-of-sale or camera systems onto distinct zones is far easier to set up correctly during a migration than to retrofit later. See our article on what a Sophos firewall actually does for a plain-language breakdown of segmentation, filtering, and VPN capability.

Planning a firewall replacement?

We scope, configure, and cut over Sophos firewalls for businesses across Northern Ontario with a documented rollback plan.

Book a Migration Consultation

Plan the VPN cutover carefully

Remote access VPN is usually the piece that causes the most disruption if handled poorly, because staff working from home or on the road will not notice a problem until they try to connect. Reissue VPN client profiles ahead of the cutover where possible, and schedule the change for a low-traffic window such as early morning or a weekend.

For site-to-site tunnels to partners or other offices, coordinate the exact cutover time with the other side in advance. A tunnel that comes up on one end and not the other will look like a network outage rather than a configuration mismatch, which wastes time troubleshooting the wrong problem.

Schedule the cutover window

  1. Confirm a maintenance window with the least business impact, ideally outside normal hours.
  2. Back up the configuration of the old firewall in full before disconnecting it.
  3. Physically or virtually stage the new firewall so swap time is minimized.
  4. Bring up core connectivity first: internet access and internal routing.
  5. Bring up VPN tunnels and remote access second, and test each one individually.
  6. Verify any port-forwarded or internet-facing service last, since these are lower priority than internal connectivity.

Test before declaring success

  • Confirm internet access works from each VLAN or network segment, not just one test laptop.
  • Test remote access VPN from an external network, not from inside the office.
  • Verify site-to-site tunnels pass traffic in both directions, not just that the tunnel shows as up.
  • Check that guest Wi-Fi still cannot reach internal resources if segmentation is in place.
  • Confirm logging and alerting are active on the new device before you consider the migration finished.

Keep a rollback plan ready

No matter how carefully a migration is planned, keep the old firewall physically available and configured to be reinserted quickly if something goes wrong that cannot be resolved within the maintenance window. Losing internet connectivity for a full business day because a migration could not be reversed quickly is a preventable failure, not bad luck.

After the cutover: decommission properly

Once the new Sophos firewall has run cleanly for a week or two, retire the old device properly rather than leaving it plugged in as a spare with stale credentials still active. If the old appliance held any VPN certificates or shared secrets, confirm those have been revoked rather than just replaced on the new device.

This is also a sensible point to schedule the next rule review, since a freshly migrated firewall is the cleanest a rule set will ever be. Letting six months pass before the first review keeps that discipline in place rather than drifting back into clutter.

Frequently asked questions

How long does a Sophos firewall migration take?

For a typical small business with a handful of VLANs and a few VPN users, the cutover window itself is usually one to three hours, though the audit and preparation beforehand can take several days depending on how documented the existing environment is.

Should I copy my old firewall rules directly to the new one?

No. A migration is the best opportunity to review and rebuild rules deliberately rather than carrying forward years of accumulated clutter. See our article on the signs a business firewall needs replacing for related warning signs.

Can the migration be done without any downtime?

Some downtime during the cutover window is normal, though it can be minimized to minutes for core connectivity if the new device is fully configured and tested in parallel beforehand.

What happens to my VPN users during the migration?

Remote access VPN profiles typically need to be reissued for the new appliance. Coordinating this ahead of time avoids staff being unable to connect the next morning.

Do I need to migrate to Sophos specifically, or does this apply to any firewall replacement?

The overall process, audit, parallel build, staged cutover, and testing applies to any firewall replacement, though the specific configuration steps referenced here assume a Sophos appliance.

About the author

Joshua Arimoro

Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.

More about our team

Get a firewall migration done right the first time

Our team handles the audit, configuration, and cutover so your business does not carry the risk of a botched migration.

Technologies mentioned in this article

See what we support around each platform on our supported technologies hub.

Keep exploring

Related services, locations, and resources

Related services

Related resources