Sophos Wireless: RADIUS and WPA3 Enterprise for AP6
An enterprise SSID controls Wi-Fi access by identity rather than a shared key. However, RADIUS reachability, certificate trust, the selected EAP method, and the downstream VLAN data path must all work together. This guide configures an external RADIUS server for an AP6 managed in Central and pilots the change on a single AP first.
Quick procedure: Go to My Products > Wireless > SSIDs > RADIUS and use Add > Add external RADIUS server to add the primary server and, optionally, the secondary server. Then create or edit an AP6 SSID, select WPA2 Enterprise, WPA3 Enterprise, or WPA2/WPA3 Enterprise, and assign the saved RADIUS configuration. Initially assign the SSID to a pilot AP only. Optionally, turn on RADIUS VLAN assignment under Advanced settings > Client connection, but first check its exclusions and verify the tagged VLAN path.
Decision in 30 seconds: WPA3 Enterprise is suitable only if all intended clients and the selected authentication method support it. WPA2/WPA3 Enterprise is the more cautious transition option for a mixed fleet; WPA2 Enterprise remains a deliberate compatibility choice. For 6 GHz, AP6 requires WPA2/WPA3 or WPA3. As a precaution, plan for only one primary/secondary RADIUS configuration pair per frequency band: if another enterprise SSID uses a different server on the same band, it overwrites the existing RADIUS configuration, after which the new primary server applies to both SSIDs.
Make these decisions before changing anything
This adaptable example uses:
| Purpose | Example value |
|---|---|
| RADIUS configuration name | HQ-RADIUS |
| Primary server | 10.20.30.15, port 1812 |
| Secondary server | 10.20.30.16, port 1812 |
| AP6 SSID | Company-Enterprise |
| Pilot AP | AP6-HQ-Test-01 |
| Frequency bands | 5 GHz, with 6 GHz added after client testing |
| Transitional encryption | WPA2/WPA3 Enterprise |
| Example assigned client VLAN | 210 |
The IP addresses, names, and VLAN ID are examples and must be adapted to your environment. The Password in Central is the secret agreed with the RADIUS server; generate a unique, strong value for it rather than copying example text. The default port for the external authentication server is 1812.
Resolve these five points before making the change in Central:
- Server path: The pilot AP must be able to reach both RADIUS servers through the applicable routing and rules. On the server side, the primary and secondary servers must treat the relevant APs, or their network, as permitted RADIUS clients.
- Identity and certificates: Prepare the users, policy, EAP method, and trust in the server certificate chain on the RADIUS and client sides. The EAP method, certificate distribution, and RADIUS attributes depend on your environment.
- Bands and encryption: Inventory the actual client types and verify their support rather than assuming they support WPA3. AP6 offers WPA2 Enterprise, WPA3 Enterprise, and mixed mode; 6 GHz excludes WPA2-only operation.
- One RADIUS pair per band: Before adding a second enterprise SSID, compare its RADIUS selection and frequency bands. Sophos documents one RADIUS configuration per frequency band for AP6 and warns that selecting a different RADIUS server for another enterprise SSID on the same band overwrites the existing server configuration. In this context, the primary/secondary pair saved in Central constitutes one RADIUS configuration. Enterprise SSIDs on the same band should therefore use the same pair.
- Client network: For a static VLAN design, first follow the AP6 SSID and VLAN procedure. For dynamic assignment, the switches, gateway, DHCP, DNS, and rules must already carry and serve every VLAN that will actually be used.
Add an external RADIUS server in Sophos Fusion (formerly Sophos Central)
The current path in Central is My Products > Wireless > SSIDs > RADIUS. Click Add, followed by Add external RADIUS server.
- Under Name, enter a name such as
HQ-RADIUS. - Under Server address, enter the address of the primary server,
10.20.30.15in this example. - Under Port, leave
1812unless your RADIUS service deliberately uses a different authentication port. - Under Password, enter the secret previously agreed on both sides.
- For redundancy, turn on Enable secondary RADIUS server and complete its Server address, Port, and Password fields. In this example, they are
10.20.30.16,1812, and a securely stored value. - Click Save to save the configuration.
A secondary server protects against failure of the primary service, not against a shared routing, firewall, certificate, or policy error. It should therefore be reachable over a genuinely usable network path and configured with the same intended access policy.
Central Help does not document a general Test connection button in this workflow. For acceptance testing, use an actual pilot login, the RADIUS logs, and the wireless events rather than planning around a preliminary test that does not exist.
Configure an AP6 SSID with enterprise encryption
To create a new AP6 SSID, go to My Products > Wireless > SSIDs > Create AP6 > SSID. To edit one, go to My Products > Wireless > SSIDs and open the name of an existing AP6 SSID. Under Settings, set the name, select the required Frequency band options, and choose WPA2 Enterprise, WPA3 Enterprise, or WPA2/WPA3 Enterprise for enterprise encryption. Then select the saved HQ-RADIUS RADIUS configuration.
- WPA3 Enterprise: for a clearly scoped fleet whose devices, operating systems, and EAP configuration have been tested in practice.
- WPA2/WPA3 Enterprise: for a controlled migration when WPA3-capable and older clients must use the same SSID. It is not a substitute for client testing.
- WPA2 Enterprise: when a verified compatibility requirement still prevents mixed or WPA3-only mode; document the decision and its retirement date.
For 6 GHz, you must select WPA2/WPA3 or WPA3. A client that works only with WPA2-only encryption therefore cannot simply be included in the same 6 GHz pilot by enabling 6 GHz.
Under Assign network, select Multiple Access points and initially assign the new SSID only to AP6-HQ-Test-01. To save the SSID without assigning an AP yet, select Add Access points later. Before clicking Save, compare the bands and RADIUS selection with every enterprise SSID already active on this AP. Save immediately updates all assigned APs, which may cause brief downtime and temporary client disconnections. For registration, configuration status, and Task Queue basics, see Manage AP6 locally or with Central.
⚠️ Overwrite risk before saving: If you assign another enterprise SSID with a different RADIUS server to an AP6 on the same frequency band, the assignment overwrites the band’s existing RADIUS server configuration. The new primary server then applies to both SSIDs. Stop the rollout if the existing SSIDs do not use the same planned primary/secondary pair or if their band usage is not clearly documented.
Optionally enable RADIUS VLAN assignment
If the RADIUS server should return VLAN information after each successful login, open Advanced settings > Client connection in the AP6 SSID and select RADIUS VLAN assignment. The AP then tags user traffic according to the VLAN information supplied. If the server does not provide VLAN information, the traffic remains untagged; the connected network must be able to accept VLAN packets.
This feature is intended for Enterprise only and is not compatible with:
- IPv6,
- personal encryption,
- authentication servers other than RADIUS,
- NAT mode for a guest network.
A guest network with RADIUS VLAN assignment requires VLAN mode rather than NAT mode. Treat these restrictions as stop conditions: do not turn on the feature until you know where untagged traffic will go and have prepared every returned VLAN on the AP uplink, switches, gateway, DHCP, and rules. Align the RADIUS attributes and VLAN values in use with your own RADIUS and network configuration.
Microsoft Entra ID is an alternative, not an additional step
Under My Products > Wireless > SSIDs > RADIUS, you can alternatively use Add > Add external identity provider to add Microsoft Entra ID as the identity provider. This is a separate IdP workflow, not registration of an external RADIUS server. In this wireless workflow, Entra supports only EAP-TTLS/PAP and does not support RADIUS-assigned VLANs, accounting, or use as a captive portal backend.
Windows and Android don’t support EAP-TTLS/PAP with WPA3 Enterprise in this Central/Entra workflow, so use WPA2/WPA3 Enterprise for these clients. For the previously out-of-scope registration, Graph permissions, certificate-validation stop conditions, tenant policy matrix, and client onboarding, follow Authenticate AP6 users with Microsoft Entra ID.
Scope: Central-managed AP6
This workflow applies exclusively to an AP6 SSID in Sophos Fusion. RADIUS definition, enterprise encryption, AP assignment, and diagnostics all take place in Central; in the SSID Settings, select the previously saved central RADIUS configuration. Before saving, therefore verify that Central manages the intended AP6 and use only the Central fields and values described in this workflow.
Validate the pilot before rollout
The following checks form an operational plan; collect and record the results in your own environment.
- Record the baseline: Document the SSID name, enabled bands, enterprise mode, current RADIUS selection, AP assignments, and, where applicable, the existing client connection. Also record the configuration of the existing enterprise SSIDs on the pilot AP.
- Limit the change: Assign the new SSID only to
AP6-HQ-Test-01. Do not change an existing SSID or a second site at the same time. - Test a valid login: Connect using an authorized pilot account. Success means that enterprise authentication works repeatedly, the client receives the intended IP configuration, resolves DNS, and can reach exactly the approved destinations.
- Test rejection: Use a purpose-built test account that is not authorized by the Wi-Fi policy and verify that it receives no Wi-Fi access. Do not lock production accounts or deliberately enter incorrect passwords repeatedly.
- Test the VLAN: With RADIUS VLAN assignment, check on the client and gateway whether the network expected for the test case is used. Test the case without VLAN information only with a dedicated test identity or a controlled test policy. If this cannot be done safely, verify fallback behavior from the policy and RADIUS log, and do not enable the feature in production until the untagged path is planned and secure.
- Test redundancy: During an approved maintenance window, take the primary path out of service in a controlled manner. The RADIUS server log must prove successful authentication through the secondary service; Central events show only reachability or recovery. Then restore the primary path and check its status again. Skip this failover test if the RADIUS service cannot be safely disrupted for testing.
- Check events: Under My Products > Wireless > Diagnostics > Events, look for RADIUS server is unreachable or RADIUS server is reachable and for wireless events with matching timestamps.
- Record acceptance: The pilot passes only if valid access, intended rejection, DHCP, DNS, rules, any VLAN assignment, reconnection, and the intended client types all work, while existing SSIDs remain unaffected. Only then add APs in small batches.
Troubleshoot by symptom
Central saves the server, but no client can log in: Under My Products > Wireless > Diagnostics > Events, look for RADIUS server is unreachable. Then check the server address, authentication port, routing and rules from the AP network to both servers, and the server-side RADIUS client definition. Verify that the Password matches on both sides without exposing it in tickets or screenshots.
RADIUS is reachable, but login is still rejected: Match the timestamp in the RADIUS log to the actual pilot attempt. Check user status, policy assignment, EAP method, and certificate trust separately. A RADIUS server is reachable event confirms reachability, not user acceptance.
Only WPA3 fails: Compare the behavior with the documented client inventory and configured EAP method. For the Entra TTLS/PAP scenario with Windows or Android, the SSID must use WPA2/WPA3 Enterprise. With external RADIUS, verify actual client and EAP support.
An existing enterprise SSID fails after the new assignment: Stop the rollout immediately and compare the frequency bands and RADIUS selections for both SSIDs. If they use different servers on the same band, the new assignment has overwritten the existing RADIUS configuration. Remove the most recently added pilot assignment. How the original configuration is reapplied depends on the affected SSID assignments; do not save further changes until you have confirmed the rollback procedure in Central.
Authentication succeeds, but the client receives no address: With RADIUS VLAN assignment, check whether the server supplies VLAN information for this case. If it does not, the traffic is untagged. If the server supplies the expected assignment, check VLAN allowance on the AP port and every uplink, as well as the gateway, DHCP, and rules; a successful RADIUS login does not prove that this data path works.
The primary server fails, but the secondary does not take over: Check Enable secondary RADIUS server and all three secondary-server fields. Then check reachability, the server-side RADIUS client definition, whether the secondary server enforces the same intended access policy, and the secondary server’s logs. Do not leave the primary server disabled while changing several other variables.
Roll back safely
If the pilot test fails, assign the new SSID to no additional APs. Under Assign network, remove only AP6-HQ-Test-01 from the new SSID. Clicking Save may briefly interrupt the assigned AP again. Then wait until the configuration status shows completion and test the existing enterprise SSIDs with a known client.
If another enterprise SSID was affected by the RADIUS configuration on the same band, removing the conflicting assignment may not be enough: Sophos does not document that this automatically restores the previous RADIUS configuration. Compare every affected SSID with the baseline documentation, and only then save the previously used RADIUS selection, original bands, and AP assignments. If this path is not unambiguous in the tenant, stop and open a Sophos Support case rather than changing more production SSIDs. Delete the RADIUS definition itself only when no SSID needs it anymore. Do not change a production server policy, certificate, or switch VLAN as the first rollback measure.
Finally, check the AP configuration status and My Products > Wireless > Diagnostics > Events, then verify that the known existing SSIDs still provide authentication, DHCP, DNS, and access governed by the expected rules. Begin a new pilot with exactly one change only after resolving the cause.