Roll out Sophos AP6 firmware safely in Central
For a centrally managed Sophos AP6, the shortest route is My Products > Wireless > Access Points > Firmware upgrade. Select the devices, then use Now for an immediate upgrade, Custom for a one-time date and time, or Recurring to apply new firmware automatically every day, week, or month. This article covers AP6 only.
⚠️ Plan for an outage: The AP6 cannot continuously serve wireless clients during a firmware upgrade. Do not turn off or disconnect the access point while it is upgrading because this could damage the device. Stabilize power, PoE, and uplink before starting, and do not interrupt the operation with a restart or reset.
Management plane and data path
Sophos Fusion (formerly Sophos Central) is the management plane in this workflow: Central schedules or starts the task, and the AP6 downloads and installs the firmware. Client traffic still follows the AP6, switch/VLAN, and gateway data path; it does not pass through Central. An available Central portal therefore cannot keep the wireless data path available while the AP restarts.
The AP6 must be registered, online, and reachable through its management path. A valid support subscription is also required for the latest firmware. See Central Wireless requirements and Manage AP6 locally or with Central for the underlying network and licensing requirements.
Before the rollout
- The Avanet Release Owner exports the model, current Firmware, site, configuration features, online state, and Last activity from My Products > Wireless > Access Points into the change record. A green mark in the firmware column means current, a blue arrow means an upgrade is available, and a clock means an upgrade is scheduled.
- At the start of every change, the owner opens the live AP6 release notes and records Latest version, release date, affected models, fixes, new features, and known issues. This live check is required; a version written into this article must not become the target release.
- The Avanet release ledger records the review date, candidate version, installed versions and models, support status, relevant features, and links to the change and release notes. The owner assesses known issues, fixed vulnerabilities and security advisories, dependencies on switches, VLAN, RADIUS, captive portal, and mesh, and any required configuration changes. The outcome is approve, defer, or reject, with rationale and sign-off by the responsible Service Owner.
- If approved, the owner defines the maintenance window, pilot AP, small site/model rings, broad ring, observation period, success criteria, and stop/go decision for each ring. Never begin a critical area with its only AP; hardware or feature combinations outside the approval remain outside the wave.
- Before each ring, the implementing engineer verifies the support subscription, PoE supply, switch port, DHCP, DNS, outbound Central connectivity, and a configuration backup or export. Do not start with unstable power, an AP already shown offline, or unmet approval criteria.
- The change defines identical before-and-after tests: SSID visibility, authentication, IP address, gateway, DNS, allowed destinations, and, where used, VLAN, RADIUS, captive portal, or mesh. Immediately before execution, the owner and engineer confirm the target version, device list, window, communication route, and rollback boundary below.
Upgrade now, once, or recurrently in Central
- Open My Products > Wireless > Access Points and click Firmware upgrade.
- Select only the intended pilot or rollout APs and click Choose schedule.
- Choose one option:
- Now: Click Upgrade to start upgrading the selected APs immediately.
- Custom: Select a date and time for a one-time upgrade, then click Save.
- Recurring: Select a daily, weekly, or monthly schedule. This automatically applies firmware upgrades to the selected APs. The displayed default is weekly on Tuesdays at 03:00 AM; deliberately change it to your maintenance window before saving.
- Return to the access-point list and verify the selection and the icon in the Firmware column. A clock must appear for an AP with a scheduled upgrade.
Before a scheduled upgrade starts, cancel it through Firmware upgrade, select the AP6, and click Cancel schedule. This is the safe stop boundary for a planned rollout, not a firmware downgrade.
Staged rollout under Avanet ownership
The implementing engineer records each wave’s start, end, selected APs, and Central status. The Avanet Release Owner releases the next ring only after validation passes:
- Pilot: Upgrade one representative AP6 that is not the sole critical device. Run the complete client tests and observe it for a period representative of normal operation.
- Small group: Upgrade a small wave of APs with the same model and similar configuration. Keep enough coverage at each site outside the simultaneous wave.
- Broad rollout: Schedule more groups only after the pilot result is documented. Do not assume that mesh, RADIUS, or captive-portal deployments behave identically to simple standalone APs.
- Remainder: In Central, look for a blue arrow, a clock, or a differing version. The owner reconciles the result with the ledger and records whether to bring the device forward or hold it because of an open issue.
Before a wave starts, the recovery route is not an invented downgrade: cancel its schedule and leave the unupgraded APs on their existing version until the pilot issue is understood.
Update an AP6 locally
The local web interface provides two sources under Advanced > Update firmware:
- Auto: The AP6 updates firmware automatically from Sophos. The page shows Current Firmware Version, Server Firmware Version, and Status.
- a file on your PC: In Central, first go to My Environment > Installers. Under Wireless, click Download firmware for your wireless. Extract exactly the
.tar.gz.sigfile for the relevant AP6 model from the downloaded archive. In the local interface, open Advanced > Update firmware > a file on your PC > Choose file, select that file, click Open, then click Update.
Obtaining the latest firmware also requires Central registration and a valid support subscription. The local upload does not bypass these prerequisites. Do not mix model packages or alter the signed file, and do not disconnect power or network during the update.
Validate success
After the restart, wait for the AP6 to return online. In Central, compare the displayed Firmware with the approved release; a green mark indicates a current release. For local management, check Current Firmware Version, Server Firmware Version, and Status.
Connect a real test client and repeat the predefined tests. Management being online is not enough: authentication, DHCP, gateway, DNS, and allowed destinations must work. Where applicable, test VLAN, RADIUS, captive portal, or mesh specifically. The engineer records the result, AP model, old and new versions, timestamp, and deviations in the change; the owner updates the release ledger and releases the next ring only when all success criteria pass.
Troubleshoot safely
No upgrade is offered: Check registration, valid subscription, online state, and Last activity. Then inspect the blue upgrade arrow and the release notes. An AP that is already current does not need a task.
A scheduled run does not start: Confirm that the correct AP was selected and that the clock is visible in the firmware column. Reopen the date, time, and recurring choice. Before it starts, cancel and recreate a clean schedule rather than creating parallel appointments.
The local upload is rejected: Download the Central archive again and ensure that the .tar.gz.sig file matches the exact AP6 model. Do not rename, edit, or unpack that signed file any further. Record repeated failures with model, current version, filename, time, and message.
The AP remains offline after the upgrade: Do not quickly remove power or use Factory default as the first response. Check PoE, switch port, DHCP lease, and Central connectivity. If the AP returns, validate firmware and client data path. If it remains unreachable or reports an upgrade failure, the owner stops all later rings and records time, model, serial number, installed/target version, status, and infrastructure checks; the engineer then opens a Sophos Support case with that package.
Safe rollback boundary
This AP6 workflow has no approved firmware downgrade. Do not upload an older image speculatively or promise a downgrade. Before a Central schedule starts, the engineer uses Cancel schedule; during a staged rollout, the owner blocks later waves in the change and ledger. Once an AP upgrade is running, preserve power and connectivity, wait for completion or a clear failure, and capture its state. The owner then chooses between restoring power, network, or configuration conditions, escalating to Support, and replacing the device; rollout resumes only after recovery is documented and approval is renewed. A reset does not automatically restore the previous firmware.