Description
Sophos Firewall Virtual for KVM

Sophos Firewall Virtual for KVM provides a virtualized deployment option for organizations using KVM-based infrastructure. Instead of installing a physical Sophos Firewall appliance, organizations can deploy the Sophos Firewall virtual appliance on supported KVM environments using the provided QCOW2 disk image.
Sophos currently lists KVM as a supported virtual firewall platform and documents deployments through Proxmox Virtual Environment and Virtual Machine Manager.
KVM Deployment
The KVM deployment requires an x86 virtualization host with a recent Linux kernel and a processor supporting Intel VT or AMD-V virtualization extensions. The virtual firewall requires at least 1 vCPU, 4 GB of vRAM, 2 vNICs, a 32 GB primary disk, and an 80 GB report disk under the current Sophos Firewall 21.5 requirements.
Virtual Networking
Virtual network interfaces connect Sophos Firewall to the required networks within the KVM environment. Administrators should plan the virtual networking configuration before deployment to ensure that the firewall has the appropriate connectivity for its intended role.
Virtual Storage
The KVM deployment uses Sophos-provided QCOW2 disks. The primary disk stores the firewall system, while the report disk provides storage for reporting and related data. Sophos recommends increasing report disk capacity when additional virtual CPU and memory resources are assigned to support additional log entries.
Deployment Options
Sophos provides deployment procedures for both Proxmox Virtual Environment and Virtual Machine Manager. In Virtual Machine Manager, the QCOW2 disk can be imported as an existing disk image and configured with the required virtual CPU, memory, network, and storage resources.
For Proxmox, administrators can create a virtual machine and configure the required virtual hardware before importing and attaching the Sophos Firewall QCOW2 disks.
Why Choose Sophos Firewall Virtual for KVM?
Sophos Firewall Virtual for KVM is designed for organizations that want Sophos network security within an existing KVM virtualization strategy. It combines a virtual firewall deployment model with the infrastructure flexibility of KVM, making it suitable for virtualized networks, security gateways, and environments where physical firewall hardware is not the preferred deployment model.
Selection Guide
For KVM Deployment
Confirm that your virtualization host uses an x86 processor with the required Intel VT or AMD-V virtualization support and that the KVM management environment is supported.
For Proxmox
Use the Sophos Firewall KVM QCOW2 disks and follow the Sophos deployment procedure for Proxmox Virtual Environment.
For Virtual Machine Manager
Use the Sophos QCOW2 image and import the existing disk image into Virtual Machine Manager.
For Virtual Resources
Start with the documented minimum of:
- 1 vCPU
- 4 GB vRAM
- 2 vNICs
- 32 GB primary disk
- 80 GB report disk
Increase resources according to the purchased license and workload requirements.
Always Verify
Check the Sophos documentation for the specific Sophos Firewall version, supported KVM platform, licensing limits, and current system requirements before deployment.
Installation Notes
Download the Firewall OS for KVM package from the Sophos Firewall installer area and extract the QCOW2 disks. Sophos provides separate installation guidance for supported KVM management platforms.
For Virtual Machine Manager, create a new virtual machine and select the existing PRIMARY-DISK.qcow2 image. Configure at least 4 GB of RAM and 1 CPU, then configure the required virtual network interfaces and VirtIO storage/network options according to the Sophos procedure. The auxiliary QCOW2 disk should also be attached as instructed by Sophos.
For Proxmox Virtual Environment, create the VM and configure its virtual hardware before attaching the Sophos Firewall QCOW2 disks. Sophos notes that settings such as the machine type, SCSI controller, and cache may need to be adjusted according to the environment.
After deployment, power on the virtual firewall and complete the initial configuration and registration process.
Best Practices
Use a current, supported KVM platform, operating system, and management tool for production deployments.
Allocate vCPU and vRAM according to the purchased Sophos Firewall license and expected workload.
Use at least two virtual network interfaces and map them carefully to the required virtual networks.
Maintain the recommended report disk capacity and consider additional storage when increasing virtual resources.
Plan the virtual networking architecture before deployment to avoid connectivity problems during initial configuration.
Keep the Sophos Firewall virtual appliance updated and verify compatibility before upgrading the underlying virtualization environment.
Do not rely on unsupported assumptions about KVM backup and restore. Sophos states that firewall backups created using virtual platform vendor backup tools are not supported.
Benefits for IT Teams
Simplified deployment of Sophos Firewall within an existing KVM infrastructure.
Reduced dependence on dedicated physical firewall hardware for suitable virtualized environments.
Centralized management of the firewall VM alongside other virtual infrastructure.
Flexible allocation of compute, memory, networking, and storage resources.
Clear deployment procedures for supported KVM environments.
A virtual security architecture that can align with existing Proxmox or Virtual Machine Manager infrastructure.
Main Benefits
Virtualized Firewall Deployment
Deploy Sophos Firewall directly within a supported KVM environment.
Benefit: Use existing virtualization infrastructure instead of requiring a separate physical firewall appliance.
Flexible Resource Allocation
Assign virtual CPU and memory resources according to the licensed Sophos Firewall configuration.
Benefit: Adapt the virtual firewall deployment to the available host resources and network workload.
QCOW2-Based Deployment
Sophos provides a QCOW2 disk image for KVM installation.
Benefit: Simplify the initial deployment process on supported KVM platforms.
Virtual Network Integration
Use multiple virtual network interfaces to connect the firewall to the required virtual networks.
Benefit: Build firewall connectivity around the architecture of the virtualized environment.
KVM Platform Support
Sophos documents deployment on KVM environments including Proxmox Virtual Environment and Virtual Machine Manager.
Benefit: Give organizations using Linux-based virtualization a supported Sophos Firewall deployment option.
Scalable Virtual Infrastructure
Virtual resources can be configured according to the purchased license and deployment requirements.
Benefit: Build the firewall into a broader virtual infrastructure without tying the deployment to a dedicated hardware appliance.
Typical Use Cases
1. Virtualized Network Security
Deploy Sophos Firewall as a virtual security gateway inside a KVM-based infrastructure.
2. Proxmox Firewall Deployment
Use Sophos Firewall within Proxmox Virtual Environment for organizations building network security into their virtualization platform. Sophos provides specific deployment documentation for importing the QCOW2 disks into Proxmox.
3. Virtual Machine Manager Deployments
Deploy the Sophos Firewall QCOW2 image through Virtual Machine Manager and configure the required virtual networking and storage.
4. Virtual Network Segmentation
Use the virtual firewall to control and secure traffic between different virtual networks and network zones.
5. Branch or Infrastructure Virtualization
Deploy firewall services in environments where network infrastructure is already consolidated on KVM-based virtualization hosts.
6. Data Center Virtualization
Integrate network security into a virtualized data-center architecture without requiring a dedicated physical firewall for every deployment.
Who Should Buy Sophos Firewall Virtual for KVM?
Sophos Firewall Virtual for KVM is intended for organizations that want to deploy Sophos Firewall within a supported KVM-based virtualization environment.
It can be suitable for:
- Businesses operating Proxmox Virtual Environment
- Organizations using Virtual Machine Manager
- IT teams standardizing network security on virtual infrastructure
- Data-center environments using Linux-based virtualization
- Businesses that prefer virtual firewall deployment over dedicated hardware
- MSPs and infrastructure teams managing multiple virtualized environments
The appropriate deployment should be selected based on the organization’s network architecture, workload, licensing, virtualization platform, and resource requirements.
Related Categories
Explore related Sophos solutions and deployment options:
- Sophos Firewall
- Sophos Firewall Virtual for VMware
- Sophos Firewall Virtual for Hyper-V
- Sophos Firewall Virtual for Proxmox
- Sophos Firewall Hardware Appliances
- Sophos Firewall Licenses
- Sophos Network Security Solutions
Frequently Asked Questions
What is Sophos Firewall Virtual for KVM?
Sophos Firewall Virtual for KVM is the virtual appliance deployment of Sophos Firewall on supported KVM environments. Sophos provides a QCOW2 disk image for KVM deployments.
Does Sophos Firewall support KVM?
Yes. Sophos documents KVM as a supported virtual firewall platform. Current Sophos documentation includes deployment options such as Proxmox Virtual Environment and Virtual Machine Manager.
What is the minimum RAM for Sophos Firewall on KVM?
The current Sophos Firewall KVM documentation specifies 4 GB of vRAM minimum.
How many vNICs does Sophos Firewall require on KVM?
The documented minimum is 2 virtual network interfaces.
What disk space does Sophos Firewall require on KVM?
Current Sophos documentation specifies a 32 GB minimum primary disk and an 80 GB report disk for KVM deployments.
Can I run Sophos Firewall on Proxmox?
Yes. Sophos provides specific instructions for deploying the KVM QCOW2 disk on Proxmox Virtual Environment.
Can I deploy Sophos Firewall using Virtual Machine Manager?
Yes. Sophos provides a KVM deployment procedure using Virtual Machine Manager, including importing the PRIMARY-DISK.qcow2 image and configuring the virtual networking and storage.
What processor support is required for KVM?
Sophos requires an x86 server with a recent Linux kernel and a processor supporting either Intel VT virtualization extensions or AMD SVM/AMD-V extensions.
Can I allocate more CPU and RAM to Sophos Firewall?
Yes, resources can be configured according to the purchased license. Sophos advises not exceeding the maximum vCPU and vRAM specified by the license.
Is Sophos Firewall Virtual for KVM suitable for production?
It can be deployed in production when the underlying KVM environment, operating system, management platform, resources, licensing, and Sophos Firewall version meet the supported requirements. Always verify the current Sophos documentation before deployment.



Reviews
There are no reviews yet.