Skip to content
Avanet

Compare Sophos AP6 Models: 420, 420E, 420X, 840, and 840E

When selecting an AP6, start with deployment location, required radio bands, MIMO configuration, uplink, and available PoE power. The AP6 420X is designed for outdoor use. If you need 6 GHz, choose the AP6 420E or AP6 840E. The 840 models use 4×4:4 MIMO, while the 420 models use 2×2:2. However, these specifications alone do not guarantee a particular range or fixed number of clients.

Quick decision: The AP6 420 is the entry-level indoor model with a Gigabit uplink. The AP6 420E adds 6 GHz and 2.5 GbE. The AP6 840 combines 4×4:4 with 2.5 GbE but does not support 6 GHz. The AP6 840E provides 4×4:4, 6 GHz, and two 2.5 GbE ports, but requires PoE++. The AP6 420X is the weather-resistant outdoor model with external antennas.

The Five AP6 Models at a Glance

Before fixing a model in the bill of materials, check the live supported-model matrix and confirm that the exact AP6 model is still listed for the intended management mode. Then use the comparison below to make the deployment decision; if the live matrix and this guide differ, stop procurement and have the model status clarified.

ModelDeploymentWireless
AP6 420Indoor2.4/5 GHz, Wi-Fi 6, 2×2:2
AP6 420EIndoor2.4/5/6 GHz, Wi-Fi 6E, 2×2:2
AP6 420XOutdoor, IP672.4/5 GHz, Wi-Fi 6, 2×2:2
AP6 840Indoor2.4/5 GHz, Wi-Fi 6, 4×4:4
AP6 840EIndoor2.4/5/6 GHz, Wi-Fi 6E, 4×4:4
ModelEthernetPower source
AP6 4201 × 1 GbE802.3at PoE+ or optional DC power supply
AP6 420E1 × 2.5 GbE802.3at PoE+
AP6 420X1 × 2.5 GbE802.3at PoE+
AP6 8401 × 2.5 GbE802.3at PoE+
AP6 840E2 × 2.5 GbE, one of which is a PoE port802.3bt PoE++

All five models can be managed with Sophos Wireless in Sophos Fusion (formerly Sophos Central) or locally. Choose the management mode before procurement: Sophos Fusion or local. For management in Sophos Fusion, the Fusion account must hold a valid AP6 Support and Services subscription quantity equal to the number of APs managed in Sophos Fusion. Local AP6 management does not require that subscription. AP6 cannot be managed through a Sophos Firewall wireless controller. Choose local or cloud-based AP6 management with Sophos Wireless explains the operational differences.

Determine the Deployment Location and Mounting Method First

AP6 420, 420E, 840, and 840E are indoor models. Their mounting options include desktop, wall, and T-bar ceiling mounting; additional kits cover other ceiling configurations. Do not install the AP where metal, utility shafts, or other obstructions could block the planned wireless cell. A ceiling height of approximately 2.5 to 4.5 meters is a guideline, but it is not a substitute for an on-site survey. These indoor models operate from 0 to 40 °C and at 10% to 95% relative humidity, non-condensing.

AP6 420X is the only current AP6 model designed for outdoor use and is IP67 rated. Its standard mounting options are wall and pole mounting. Installation requires grounding, weatherproof cabling, and a PoE source suitable for the environment. The hardware revision is also relevant: the operating temperature range is -30 to 55 °C for revision 2 and -20 to 55 °C for revision 1; permitted relative humidity is 10% to 95%, non-condensing. Verify these limits on the specific device.

Select the Appropriate Radio Bands and MIMO Configuration

The models with E in their names—AP6 420E and AP6 840E—each have one radio for 2.4, 5, and 6 GHz. AP6 420, 420X, and 840 have radios for 2.4 and 5 GHz. The 6 GHz band is not available in every region and also requires compatible clients. A 6 GHz radio therefore adds meaningful value only when the regulatory domain, client devices, and wireless design are all compatible.

2×2:2 and 4×4:4 describe the documented MIMO configurations. The 840 models provide more spatial streams, but the benefit depends on client capabilities, channel width, interference, cell size, and concurrent load. For a high-density or performance-focused environment, 840/840E is therefore the natural starting point for a pilot, but it does not guarantee a particular throughput or number of clients.

Only the AP6 420 has a 1 GbE uplink; the other models have at least one 2.5 GbE port. The AP6 840E has two 2.5 GbE ports, but only the first port supplies the AP with PoE. A 2.5 GbE port on the AP does not by itself create a 2.5 GbE data path: the switch port, cabling, negotiated speed, and the rest of the network must support it as well.

AP6 420, 420E, 420X, and 840 require at least 802.3at PoE+; AP6 840E requires 802.3bt PoE++. Passive PoE injectors are not supported. An AP6 switches off all radios if the power supply is insufficient. Restart the AP after changing the PSE power allocation.

Do not size the power design from a single nominal wattage. For procurement, reserve the required PoE class on every AP port, calculate the switch or injector’s total budget for all APs with operating margin, and verify the result on the intended port and cable run. The Sophos Wireless Requirements provide the complete checklist for switch power budget, LLDP-MED, VLAN, DHCP, DNS, and Fusion destinations.

Choose Internal or External Antennas

The four indoor models use internal omnidirectional antennas. This is suitable for a well-planned wall or ceiling installation where orientation and placement match the intended wireless cell. AP6 420X uses external omnidirectional antennas; a 120° sector antenna and a 30° directional antenna are also available as options.

Installing an optional AP6 420X antenna is not merely a mechanical change. You must also select the correct antenna in the AP configuration. An incorrect antenna setting can cause operation outside regulatory limits. Before installation, document the antenna type, cable, orientation, and corresponding software setting together.

Check the Regulatory Domain and SKU Before Ordering

FCC and ETSI variants permit different channels. Outdoors, Australia and New Zealand, Brazil, Kenya and South Africa, as well as Albania, Andorra, Austria, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, the Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Macedonia, Malta, Moldova, Monaco, Montenegro, the Netherlands, Norway, Poland, Portugal, Romania, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Turkey, and the United Kingdom prohibit low-band 5 GHz channels that do not support DFS; those channels cannot be configured there for outdoor use. Israel has the stricter boundary: outdoor access points cannot use any 5 GHz channel and are limited to 2.4 GHz. A general model designation therefore does not constitute worldwide radio approval.

The SKU-to-country mapping distinguishes six procurement variants: Australia (AU) for Australia and New Zealand, Canada (CA) for Canada, Europe (EU) for the listed European countries, India (IN) for India, Rest of World (ROW) for the listed remaining countries, and United States (US) for the United States. Immediately before ordering, open the live AP6 SKU-country matrix, match the destination country to the SKU code on the quotation, and record both in the decision log. Because an AP6 can only be assigned to a Sophos Fusion site within its SKU region, site assignment cannot correct an unsuitable regional SKU; if the country is absent or the quotation differs, stop the order until clarified. An available declaration of conformity does not replace either this SKU check or local frequency requirements.

Validate the Selection with a Pilot Device

  1. Document the requirements: Record whether the deployment is indoors or outdoors, expected client types, required bands, need for 6 GHz, uplink, PoE standard, mounting method, country, and management mode. For management in Sophos Fusion, also record the AP count managed there and the valid AP6 Support and Services subscription quantity held by the Fusion account.
  2. Check the model and region: Verify the model, hardware revision, SKU code, and site country before ordering. In the Regulatory Compliance Library, open the exact AP6 model, download the declaration or approval required for the destination country and revision, and record the document title and retrieval date in the decision log. If the model is missing, the revision differs, or country approval is unclear, do not order until the mapping has been resolved.
  3. Pre-check the switch port: Verify negotiation at 1 or 2.5 GbE, PoE+/PoE++, cable run, LLDP-MED, and total power budget.
  4. Install one AP: Check the intended mounting location and, for the 420X, grounding, weatherproofing, antenna type, and antenna setting.
  5. Measure acceptance criteria: Document the negotiated Ethernet speed, PoE status, active radios, permitted channels, client connectivity, and throughput at several representative locations.
  6. Review the decision: Only after the pilot should you decide whether the model, quantity, placement, and switch power budget are suitable for the remaining area. If results deviate, return to the last documented configuration rather than changing multiple variables at once.

Next, register the AP under My Products > Wireless > Access Points > Register. The Onboarding Guide walks you through claiming, site assignment, and acceptance testing.

Maintain the Decision Throughout the Lifecycle

The acceptance record is the baseline for later changes. It must include at least the model, hardware revision, SKU code, site country, mounting and antenna, switch port and PoE class, plus negotiated speed, active bands, channels, and measured results. A current model or country list alone does not prove that an installed AP or a supplied replacement matches the documented deployment.

Repeat the selection check before an expansion, replacement, or move, and after changes to the country or regulatory domain, antenna, mounting, switch, PSE, cabling, or relevant firmware behavior. Repeat it as well if a model is no longer procurable or supported, or if a compliance document has been replaced. For every expansion or replacement, and during periodic operational reviews and whenever a subscription is approaching expiry or has lapsed, recheck and record the management mode, AP count managed in Sophos Fusion, and valid AP6 Support and Services subscription quantity held by the Fusion account. If that quantity is lower than the AP count managed in Sophos Fusion, stop the expansion or replacement and do not continue undersubscribed Fusion operation until the valid account quantity has been restored. Preserve the requirements and baseline, re-evaluate the proposed replacement model together with its revision and regional SKU, and stage exactly one device first.

Test the candidate with the same SSID and switch-port configuration, then compare Ethernet negotiation, PoE, active radios, permitted channels, client connectivity, and throughput with the baseline. If anything differs, return to the last documented state and change only the model, power source, port, or radio parameters one at a time. Update the bill of materials and operating record and roll out the remaining devices only after acceptance succeeds.