Sophos XGS 87 — login, gateway address and status lights
Open a browser on a device connected to your Sophos XGS 87 and go to 172.16.16.16.
The documented default login is admin with the password admin.
The Sophos XGS 87 is a firewall router from Sophos, in UK use 2021-2025 (end of sale). This page covers the four things people actually come looking for: its settings address, how its login works, what its lights mean and how to reset it safely.
What is the Sophos XGS 87 gateway address?
The Sophos XGS 87 settings page is at 172.16.16.16. Type that into the address bar of a browser — not into a search box, which will just search for the number instead of opening the page.
Your device has to be connected to the Sophos XGS 87 itself for this to work — over its Wi-Fi or by cable. On mobile data, or connected to a different network, the address goes nowhere.
Two things about this address catch people out, and both matter more than the number itself. The admin console is not on port 443 — it is on port 4444, so the URL is https://172.16.16.16:4444 and browsing to https://172.16.16.16 will get you nowhere. And the LAN is 172.16.16.0/24 rather than a 192.168 range, so a laptop expecting a familiar subnet will not find the box. Sophos enables DHCP on the LAN, but if no lease arrives its own guide tells you to set a static 172.16.16.2/24 with the gateway and DNS both pointed at 172.16.16.16.
What is the default username and password for the Sophos XGS 87?
Documented fixed default
The manufacturer publishes a single default login for the Sophos XGS 87, so we can show it:
- Username
admin- Password
admin
Sophos publishes this plainly: "The factory configuration of Sophos Firewall carries a default super administrator with the following credentials: Username: admin, Password: admin." The same pair works for the web console and the CLI. You must change it during first-time configuration, and Sophos checks the replacement against a dictionary of common passwords and rejects matches. You cannot rename or delete the admin account. One caveat worth knowing before you rely on admin/admin: while that default is still in place Sophos deliberately blocks the firewall from the WAN side, so the web console returns a forbidden error and an SSH attempt is closed silently, which is confusing to diagnose if you are working remotely.
This only works if nobody has changed it. On a unit that has been in service for a while, someone should have, and if they did then no published default will help you.
What do the lights on the Sophos XGS 87 mean?
Here is what each light on the Sophos XGS 87 is telling you, and what to do about it.
| Light | What it means | What to do |
|---|---|---|
| Statussolid green | Normal operation. | |
| Statussolid red | Storage or boot failure. | The appliance has not come up. Connect a serial console to see how far it got, and raise a support case — this is not a configuration problem. |
| Statusflashing red | General error. | Sophos asks you to contact support for this one rather than giving a specific cause. |
| Storageflashing blue | The storage drive is being accessed. | |
| Power 1solid green | The power adapter is working normally. | |
| Power 1solid red | The power adapter has failed or been disconnected. | Check the adapter and its connection. The XGS 87 has a single power supply, so there is no redundancy to fall back on. |
| WiFisolid green | Wi-Fi is active. XGS 87w only — the non-wireless XGS 87 has no Wi-Fi light. | |
| WiFioff | Wi-Fi is inactive, or this is a non-wireless XGS 87. | |
| Ethernet ACT/LNK (left)solid green | The port has a link and a good connection to the switch. | |
| Ethernet ACT/LNK (left)flashing green | Sending or receiving data. | |
| Ethernet ACT/LNK (left)off | No link. Either nothing at the far end has power, the cable is not making a connection at one or both ends, or the far end has no working network driver. | Work outwards from the cable: reseat both ends, then try a known-good patch lead, then check the device at the other end. |
| Ethernet Speed (right)solid amber | The port is running at 1000 Mbps. | |
| Ethernet Speed (right)solid green | The port is running at 100 Mbps. | If you expected gigabit, suspect the patch lead or a fixed speed setting on the switch port. |
| Ethernet Speed (right)off | The port is running at 10 Mbps. | Almost always a cabling fault on a modern link. |
| SFP ACT/LNKsolid green | The SFP port has power and a good connection. | |
| SFP ACT/LNKflashing green | Sending or receiving data. | |
| SFP ACT/LNKoff | No connection on the SFP port. | Check the module is seated and that both ends agree on the fibre type. |
On boot, Sophos says the Status light "will turn to solid green and the unit will boot. This process should take a few minutes."
How do you reset a Sophos XGS 87?
What you lose. Sophos summarises it as "all configuration, reports and patterns will be flushed", which in practice means every firewall rule and rule group, all NAT rules, IPsec and SSL VPN configuration including pre-shared keys and remote-access profiles, VLANs and interface addressing, web and application control policies, authentication and directory integration, and all stored reports and logs. Two things do survive: Sophos states that a console-driven reset "doesn't affect the firewall's registration" and that the secure storage master key is not cleared, so the licence stays attached to the serial number even though the entire security posture has gone.
- There is a physical reset button on the appliance. Sophos documents it as: "Press and hold for >10 seconds to reset the unit to factory default settings. All configuration, reports and patterns will be flushed." The QuickStart Guide lists the button alongside the USB ports but only shows its exact position in the panel photographs rather than describing it in words. There is also a serial console route, which is the more useful one — see recovery.
- Hold it for More than 10 seconds..
- Release, and give the unit a few minutes to restart before trying to connect.
Do not reach for the button first. The console menu can reset the admin password on its own and leave your configuration intact, which is almost always what you actually wanted.
A reboot is not a reset. A normal reboot from the console or the web interface keeps every setting.
What if you cannot get into the Sophos XGS 87 at all?
Yes, and this is the best reason to keep a serial cable in the comms cupboard. Connect to the RJ45 COM port or the front Micro USB port, open a session at 38,400 baud, and type RESET in capitals. Sophos offers four numbered options, and option 4 resets the default admin password without touching the configuration — you sign back in as admin/admin and are immediately prompted to set something complex. Options 1 to 3 progressively delete configuration, reports, logs and personally identifiable information, so read the menu rather than pressing 1 out of habit. On a high-availability pair the password reset is not synchronised, so you have to do the primary and the auxiliary separately.
If that does not work, a factory reset will always get you in, at the cost of every setting on the unit.
Where this comes from
- Sophos XGS 87/87w/107/107w Quick Start Guide — Model-specific source for the 172.16.16.16:4444 address, the reset button, the light table and the console settings.
- Sophos Firewall — device access — The admin/admin default, the forced change and the dictionary check.
- Sophos Firewall — console reset menu — The four RESET options, including the password-only reset that preserves the configuration.
- Sophos Firewall — registration and basic setup — The WAN-side restrictions that apply while the default password is still in place.
- Sophos Central — firewall Zero Touch provisioning — The Central-managed case, where the local password may never be set.
- Sophos retirement calendar — Lifecycle dates: end of sale 31 January 2025, last renewal 30 September 2029, end of life 30 September 2030, migration path XGS 88.