Skip to content
Avanet

Manage Sophos AP6 locally or with Sophos Fusion

A Sophos AP6 can be managed locally through its own web interface or centrally through Sophos Fusion (formerly Sophos Central). The local interface may be enough for one deliberately standalone AP6. For several AP6 devices, we recommend Sophos Fusion because inventory, status, firmware tasks, profiles, and SSID assignments are in one place. Sophos Firewall, however, is not an AP6 controller.

Quick decision: Use local management for one AP6 with a clearly documented configuration. Use Sophos Fusion for multiple AP6 devices, multiple sites, or operations that need a shared view of changes and status. Check the network requirements before registering with Sophos Fusion.

Keep the management plane and data path separate

The management plane carries configuration, status, and tasks. With local management, the browser connects directly to the AP6 IP address. With Sophos Fusion, the AP6 establishes its management connection through the network and internet.

The data path is the route taken by client traffic: wireless client, AP6, switch or VLAN, then gateway or firewall. Choosing Sophos Fusion does not automatically send that traffic through the platform. An AP6 can therefore be online in Sophos Fusion while a client still fails because of DHCP, VLAN, DNS, or firewall rules.

The same distinction applies behind an SD-RED. A separate AP6 remains an AP6 with local or Sophos Fusion management; it does not become the SD-RED’s Wi-Fi module. Its client traffic may use the RED data path while management follows the chosen AP6 management mode. Sophos Fusion reachability must be tested from the actual remote network; there is no blanket reachability guarantee. RED tunnel setup is a separate task; see Set up Sophos RED.

Which hardware is managed where?

Hardware/typeManagementLocal GUISophos FusionSFOSLicense required?Multiple APsRoaming/coordination
AP6local or Sophos Fusionyesyesnoonly with Sophos Fusion: yes, per AP6Sophos Fusion preferredAP6 features; client decides
XGS Appliance W modelSFOS LocalWiFiSFOS GUIvia firewall management onlyyesnolimitedlocal radio
Wi-Fi module in firewallSFOSSFOS GUInot as an APyesnolimitedSFOS features
Wi-Fi module in SD-REDSophos FirewallnonoyesnolimitedSFOS features

Built-in wireless on a W model is LocalWiFi and remains part of the firewall. A compatible Wi-Fi expansion module in a firewall or SD-RED also belongs to the SFOS wireless controller. These SFOS deployments should follow Set up wireless directly on Sophos Firewall.

Manage AP6 locally

Open the AP6 IP address to reach its local interface. Sophos specifies 192.168.2.2 as the factory-default address and admin as the username; the individual default password is printed on the device and in the box. The first login requires a new password and country code. The actual IP may differ after DHCP assignment.

This option avoids a cloud-management license, but requires disciplined per-device work: configuration, backups, firmware level, and changes must each be maintained locally. With several devices, inconsistent SSIDs, security values, or radio settings become more likely. Record the current values and a recovery path before making a local change.

Operate multiple AP6 devices in Sophos Fusion

The current overview path is My Products > Wireless > Access Points. Sophos Fusion shows details including name, IP, model, configuration status, workload, channel, profile, firmware, uptime, and last activity. Register one AP6 with Register, or several with a CSV through Register > Bulk Provisioning. The Onboarding Wizard covers initial registration.

Click an AP to open its details. Settings contains device configuration, radio settings, and assigned SSIDs. Task queue lists AP6 tasks as Created, Pending, In progress, Failed, Success, Skipped, or Invalid license. Profiles at My Products > Wireless > Access Points > Profile management apply selected management and advanced wireless settings to multiple AP6 devices rather than editing each one.

⚠️ Operational impact: Save on the AP details page updates the AP immediately. This can cause a short interruption and briefly disconnect wireless clients. Test group or profile changes on one pilot AP before applying them across sites.

AP6 Support and Services: license and expiry

An AP6 Support and Services license is required for each AP6 managed in Sophos Fusion; the quantity must match the number managed. It includes AP6 management features in Sophos Fusion, firmware updates, 24/7 support, and Advanced RMA. Local AP6 management and Wi-Fi managed by Sophos Firewall do not require this AP6 license. How is Sophos Fusion licensed? explains the wider tenant and licensing model.

Sophos Fusion warns in Wireless if the license is absent or the quantity is too low. Sophos explicitly documents the expiry boundary: changes to AP6 devices through Sophos Fusion are blocked without a valid license. It does not follow that the AP immediately stops forwarding client traffic or that all existing configuration disappears; Sophos does not document either outcome here. Personal help by phone, chat, or support case also requires valid support.

Budget hardware, AP6 Support and Services, and management separately. According to our September 2026 price analysis, AP6 hardware increases by 10% on 1 November 2026, while one year of AP6 Support changes from 5% to 10% of the hardware price. This is not evidence of a blanket Sophos Wireless subscription price increase; it is a hardware and AP6 Support change.

Set realistic expectations for roaming

The client ultimately initiates roaming. Matching SSID and security settings plus overlapping cells can therefore support movement between APs without claiming that Sophos Fusion is mandatory for roaming. Sophos Fusion makes configuration consistency and visibility easier, but it does not replace RF design.

Sophos gives AP6 planning values of at least -67 dBm for voice, -72 dBm for data, and roughly 15–20% cell overlap. These are starting points for a site survey and measurement, not a guarantee for every client. AP6 supports 802.11k, 802.11r, and Smart Handover, but not every client does. Smart Handover disconnects clients below the selected RSSI threshold and should only be enabled after a site survey.

Roll out with a controlled pilot AP

  1. Define inventory and target: Record model, serial number, site, switch port, PoE, management network, management choice, and the previous profile, SSID, radio, and management values.
  2. Preflight the network: Check DHCP, DNS, NTP, internet access, VLAN trunk, and gateway separately for AP management and wireless clients.
  3. Register the pilot: Register one reset AP6 at My Products > Wireless > Access Points > Register and wait for an up-to-date configuration status.
  4. Assign a small test profile: Assign a test SSID only to the pilot. Do not change production SSIDs, VLANs, or radio values everywhere at once.
  5. Run acceptance tests: With at least two different clients, test association, DHCP, DNS, permitted destinations, blocked internal destinations, and movement between two APs if roaming is in scope.
  6. Inspect tasks: Check the AP details and Task queue for Failed or Invalid license. Roll out to the next AP group only after recording success.
  7. Use the recovery path: If testing fails, reapply the known previous assignment and documented profile, SSID, radio, and management values. Then rerun the task, AP-status, and client checks. Do not use reboot, reset, or a management-VLAN change as the first diagnostic step.

Validation and troubleshooting

For a symptom-led sequence covering Offline, stuck provisioning, client connectivity, diagnostics, VoIP, performance, and roaming, use the AP6 troubleshooting workflow.

AP missing or offline: At My Products > Wireless > Access Points, inspect registration, Config status, internal IP, and Last activity. Then check PoE, switch port, DHCP lease, DNS, NTP, and the outbound Sophos Fusion path. Failed onboarding is not automatically a radio issue.

Change is not applied: Open Task queue on the AP details page. Use Retry only for Failed, Skipped, or Invalid license, and only after correcting the cause. Inspect Pending; use Skip only when appropriate. Do not blindly skip an unknown task.

SSID is visible but traffic fails: Management is at least partly working. Check the client’s IP, gateway, and DNS, then inspect switch VLANs, DHCP, and firewall rules along the data path. A green Sophos Fusion status does not prove the client network is correct.

Roaming or voice breaks up: Compare SSID, encryption, and bands on both APs; measure RSSI and overlap on site; and verify client support for 802.11k/r. Change transmit power, channel, or Smart Handover one at a time and repeat the same walking test.