Sophos Firewall Migration Checklist for Small Business Networks
Swapping out a firewall sounds like a simple hardware refresh until the cutover window arrives and something unexpected breaks, whether that is a VPN tunnel, a site-to-site link, or a piece of line-of-business software that assumed a specific IP. This checklist lays out the steps we walk through with clients moving to a Sophos firewall, in the order that keeps risk lowest.
A Sophos firewall migration goes smoothly when the old rule set is audited and documented first, the new device is configured and tested in parallel before the cutover, VPN and remote access are rebuilt and verified before staff arrive, and a rollback plan exists in case the new configuration needs to be reversed quickly.
Before you touch any hardware: audit the existing rule set
Every migration starts with understanding what the current firewall is actually doing, not what the original install document says it should be doing. Export the full rule set, VPN configuration, NAT rules, and any site-to-site tunnels, then go through them line by line.
This step matters because rule sets accumulate clutter over years. A rule added for a vendor that left three years ago should not be copied forward blindly into the new device. If your rules have not been reviewed recently, our guide on how often firewall rules should be reviewed covers what a proper audit checks.
Document what depends on the firewall
- Site-to-site VPN tunnels to other offices or partners
- Remote access VPN accounts used by staff working from home or on the road
- Port forwards for any internet-facing service, such as a hosted phone system or remote camera feed
- Static IP assignments and DHCP scopes handled by the current appliance
- Any integration with Wi-Fi access points or switches for VLAN tagging
Build the new configuration in parallel
Configure the new Sophos appliance on a bench or in a lab VLAN before it ever touches production traffic. Rebuild rules deliberately rather than importing everything wholesale, since this is the natural point to drop stale rules and tighten anything overly permissive.
This is also the right time to plan segmentation properly if it has not been done already. Separating guest Wi-Fi, staff devices, and any point-of-sale or camera systems onto distinct zones is far easier to set up correctly during a migration than to retrofit later. See our article on what a Sophos firewall actually does for a plain-language breakdown of segmentation, filtering, and VPN capability.
Planning a firewall replacement?
We scope, configure, and cut over Sophos firewalls for businesses across Northern Ontario with a documented rollback plan.
Book a Migration ConsultationPlan the VPN cutover carefully
Remote access VPN is usually the piece that causes the most disruption if handled poorly, because staff working from home or on the road will not notice a problem until they try to connect. Reissue VPN client profiles ahead of the cutover where possible, and schedule the change for a low-traffic window such as early morning or a weekend.
For site-to-site tunnels to partners or other offices, coordinate the exact cutover time with the other side in advance. A tunnel that comes up on one end and not the other will look like a network outage rather than a configuration mismatch, which wastes time troubleshooting the wrong problem.
Schedule the cutover window
- Confirm a maintenance window with the least business impact, ideally outside normal hours.
- Back up the configuration of the old firewall in full before disconnecting it.
- Physically or virtually stage the new firewall so swap time is minimized.
- Bring up core connectivity first: internet access and internal routing.
- Bring up VPN tunnels and remote access second, and test each one individually.
- Verify any port-forwarded or internet-facing service last, since these are lower priority than internal connectivity.
Test before declaring success
- Confirm internet access works from each VLAN or network segment, not just one test laptop.
- Test remote access VPN from an external network, not from inside the office.
- Verify site-to-site tunnels pass traffic in both directions, not just that the tunnel shows as up.
- Check that guest Wi-Fi still cannot reach internal resources if segmentation is in place.
- Confirm logging and alerting are active on the new device before you consider the migration finished.
Keep a rollback plan ready
No matter how carefully a migration is planned, keep the old firewall physically available and configured to be reinserted quickly if something goes wrong that cannot be resolved within the maintenance window. Losing internet connectivity for a full business day because a migration could not be reversed quickly is a preventable failure, not bad luck.
After the cutover: decommission properly
Once the new Sophos firewall has run cleanly for a week or two, retire the old device properly rather than leaving it plugged in as a spare with stale credentials still active. If the old appliance held any VPN certificates or shared secrets, confirm those have been revoked rather than just replaced on the new device.
This is also a sensible point to schedule the next rule review, since a freshly migrated firewall is the cleanest a rule set will ever be. Letting six months pass before the first review keeps that discipline in place rather than drifting back into clutter.
Frequently asked questions
How long does a Sophos firewall migration take?
For a typical small business with a handful of VLANs and a few VPN users, the cutover window itself is usually one to three hours, though the audit and preparation beforehand can take several days depending on how documented the existing environment is.
Should I copy my old firewall rules directly to the new one?
No. A migration is the best opportunity to review and rebuild rules deliberately rather than carrying forward years of accumulated clutter. See our article on the signs a business firewall needs replacing for related warning signs.
Can the migration be done without any downtime?
Some downtime during the cutover window is normal, though it can be minimized to minutes for core connectivity if the new device is fully configured and tested in parallel beforehand.
What happens to my VPN users during the migration?
Remote access VPN profiles typically need to be reissued for the new appliance. Coordinating this ahead of time avoids staff being unable to connect the next morning.
Do I need to migrate to Sophos specifically, or does this apply to any firewall replacement?
The overall process, audit, parallel build, staged cutover, and testing applies to any firewall replacement, though the specific configuration steps referenced here assume a Sophos appliance.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamGet a firewall migration done right the first time
Our team handles the audit, configuration, and cutover so your business does not carry the risk of a botched migration.
Technologies mentioned in this article
See what we support around each platform on our supported technologies hub.
Related services, locations, and resources
Related services
- Network & Wi-Fi Support
Business networks, firewalls, switches, and wireless.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
Related service areas
Related resources
- What Does a Sophos Firewall Actually Do for a Small Business?
A business-grade firewall does far more than block traffic at the edge. Here is what a device like a Sophos…
- Business Firewall vs Consumer Router: Why the ISP Box Isn't Enough
The all-in-one box your internet provider gave you was built for a home, not a business. Here is what a rea…
- How Often Should Firewall Rules Be Reviewed?
A firewall installed correctly three years ago is not necessarily a firewall configured correctly today. He…
- Designing Business Wi-Fi That Actually Works
Good business Wi-Fi is a design problem, not a shopping problem. Here is how coverage, capacity, placement,…
