Sophos UTM 9.6 licenses - installation and active IP addresses
Sophos
The availability of certain features on Sophos UTM is governed by licenses and subscriptions, i.e. the licenses and subscriptions you have purchased with the UTM allow you to use certain features but not others.
Purchasing a license
Sophos UTM comes with a 30-day trial license by default, which allows you to use all features and functionality without restriction. After expiry, you will need to install a valid license to continue using Sophos UTM. All licenses (including free home-use licenses) are created at MyUTM-Portal.
After purchasing a UTM licence, you will receive your activation keys by email. You need these keys to generate the actual licence or to update an existing licence. To activate a licence, log in to MyUTM-Portal and go to the licence management page. At the top of the page is a form where you can copy and paste the activation key from the email.
A new form will appear where you can enter information about your distributor as well as your own contact details. The portal will try to pre-fill as many fields as possible. Sophos will also record the hardware serial number of the UTM, if applicable. Once you have submitted the form, your licence will be generated and you will be redirected to the licence details page from where you can download the licence.
To use the licence, you must download the generated licence file and then log in to your WebAdmin installation. In WebAdmin, open the Administration > Licences > Installation tab and use the upload function to locate the licence file on your hard drive. Upload the licence file. After that, WebAdmin will read it to activate all subscriptions and other settings provided in the licence file.
Note: The activation key you received by email cannot be imported into WebAdmin. This key is only used to activate your licence. Only the licence file can be imported into the UTM.
Licence model
Sophos 's modular licensing model is extremely flexible. First, there is a basic licence that provides basic functions free of charge (see table below). There are also six additional subscriptions:
- Network Protection
- Web Protection
- Email Protection
- Endpoint Protection
- Wireless Protection
- Web Server Protection
- Sandstorm
These subscriptions can be purchased individually or in combination to suit your requirements. The FullGuard licence includes all subscriptions. Each subscription enables certain features of the product. The table below shows an overview of which functions are activated by which subscription.
| Function | Basic licence | Network | Web | Endpoint | Wireless | Web Server | Sandstorm | |
|---|---|---|---|---|---|---|---|---|
| Administration (backups, notifications, SNMP, SUM, ...) | ✔ | |||||||
| Local authentication (users, groups) | ✔ | |||||||
| Basic network functions (static routing, DHCP, DNS, Auto-QoS, NTP, ...) | ✔ | |||||||
| Firewall/NAT (DNAT, SNAT, ...) | ✔ | |||||||
| PPTP & L2TP remote access | ✔ | |||||||
| Local logging, standard reports | ✔ | |||||||
| Intrusion Prevention (IPS) (Patterns, DoS, Flood, Portscan ...) | ✔ | |||||||
| IPsec & SSL site-to-site VPN, IPsec & SSL remote access | ✔ | |||||||
| Advanced network functions (link bundling, uplink balancing, policy routing, OSPF, multicast, customised QoS, server load balancing, generic proxy ...) | ✔ | (✔) | (✔) | |||||
| User portal | ✔ | ✔ | ✔ | |||||
| High Availabilty (High Availability) | ✔ | ✔ | ✔ | |||||
| Remote authentication (AD, eDir, RADIUS, ...) | ✔ | ✔ | ✔ | |||||
| Outsourced logging, extended reports (archiving, configuration) | ✔ | ✔ | ✔ | |||||
| Basic web filter & FTP proxy | ✔ | |||||||
| Web & FTP malware filtering | ✔ | |||||||
| Application Control | ✔ | |||||||
| Basic SMTP proxy, quarantine report, mail manager | ✔ | |||||||
| SMTP & POP3 malware filtering | ✔ | |||||||
| Endpoint Protection, Antivirus | ✔ | |||||||
| Endpoint Protection, Device Control | ✔ | |||||||
| Wireless Protection | ✔ | |||||||
| Webserver Protection | ✔ | |||||||
| Sandstorm | (✔) | (✔) | ✔ |
There is also a BasicGuard subscription available for the UTM appliance model 100, which provides its own subset of the above features (For more information, visit the UTM-Website).
UTMscan also be managed and licensed by Sophos UTM Manager (SUM). In this case, SUM passes the MSP (Managed Service Provider) licence to the UTM and the Installation tab is inactive. Subscriptions can then only be activated by your SUM service provider.
For more detailed information on subscriptions and their scope of functions, please contact your certified UTM partner or the Sophos UTM Webseite.
If certain subscriptions have not been purchased, the corresponding tabs in WebAdmin are inactive. A licensing warning message is displayed above the tabs.
Up2Dates
Each subscription activates full automatic update support, which means that you are automatically notified of new firmware updates. In addition, firmware and pattern updates can be downloaded (and installed) automatically.
A basic licence without subscription supports automatic updates only to a limited extent: Only pattern updates, such as updates of the online help, will still be downloaded and installed automatically. However, you will not be informed about available firmware updates and the firmware updates must be downloaded manually. The availability of new firmware updates is announced in the Sophos UTM Up2Date Blog announced.
Support and maintenance
With the basic licence, you can use the web support. You can use the Sophos UTM Support-Forum and the Sophos Knowledgebase use the web support.
As soon as you purchase one of the subscriptions, you will automatically be upgraded to Standard Support. With this support level, you can additionally create a support case in MyUTM-Portal or contact your certified UTM partner.
In addition, you have the option of concluding a premium support contract. This offers you round-the-clock support from a UTM engineer as your contact person.
Installation
On the tabAdministration > Licences > Installation you can upload and install new licences.
Note: If you are using the MSP licence, the following changes can only be made through the Sophos UTM Manager (SUM): deactivate SUM, change SUM host, change SUM administrator rights. New licenses can be installed by your SUM service provider. For information about the managing SUM, see Central management > Sophos UTM Manager.
To install a licence, follow these steps:
- Open the Upload file dialogue box. To do this, click the folder icon next to the License file input field. The Upload File dialogue box opens.
- Select the licence file. Change to the directory in which your licence file is located. Select the licence file you want to install.
- Click on Start Upload. Your licence file is uploaded.
- Click on Apply. Your licence will now be installed. Note that the new licence automatically replaces an already installed licence. The installation of the licence takes about 60 seconds.
Active IP addresses
The free Sophos UTM Manager licence allows an unlimited number of IP addresses.
If you have purchased a licence that does not allow an unlimited number of users (IP addresses), this tab shows you information about the allowed number of IP addresses covered by your licence. IP addresses that exceed the scope of your licence are listed separately. If you have exceeded the permitted limit, you will receive a regular e-mail notification.
Note: IP addresses that have been inactive for a period of seven days are no longer included::
Marcel Zimmer is the Technical Managing Director of EnBITCon. During his time in the German Armed Forces, the trained IT developer was able to gain numerous project experiences. His interest in IT security was significantly awakened by his service in command support. Even after his service, he is an active reservist in the Bundeswehr.
His first firewall was a Sophos UTM 120, which he had to set up for a customer project. Since then, his interest in IT security has grown steadily. In the course of time, various security and infrastructure topics have come into his focus. His most interesting projects included, for example, WLAN coverage in an explosion-proof area, as well as a multi-site WLAN solution for a large