Plan and configure an AP6 mesh in Sophos Wireless
An AP6 mesh connects access points through a private backhaul SSID. Wireless clients can’t see this network; they connect to a separate fronthaul SSID that the root distributes to its nodes. Mesh is useful where power is available but a wired LAN uplink isn’t available at every AP location. Where cabling is possible, a wired backhaul is generally more reliable and leaves all radio capacity available to clients.
Quick workflow: Connect every AP6 to the LAN and register it in Fusion, prepare the client SSID and radio plan, then create a backhaul under My Products > Wireless > SSIDs > Create AP6 > Mesh. Assign the root and nodes and wait for Config Status to show up to date everywhere. Only then power off wireless-backhaul nodes, remove their LAN data connection, power them at their final location, and restart them. Verify Mesh status, the local mesh view, and the complete client data path.
Understand the topology and data paths
The root requires a physical Ethernet connection to the LAN. Nodes reach it over a wireless, wired, or mixed backhaul. Multiple roots are possible, but Sophos doesn’t document automatic root failover. A mesh connection is established at startup, and AP6 units start in their predetermined roles.
Sophos Fusion (formerly Sophos Central) is the management plane: it creates the mesh, roles, and assignments and displays configuration and mesh status. Client packets travel from the client through the fronthaul, AP6, backhaul, and root into the LAN; Fusion doesn’t carry them. Therefore, up to date proves that configuration arrived, not that the mesh formed or that DHCP, DNS, VLAN, and gateway work. Sophos says Fusion can’t debug mesh problems; the local AP6 view supplies the additional topology check.
An AP6 mesh can repeat the client SSID, bridge an Ethernet segment at a node to the root LAN, or do both. A bridge requires deliberate VLAN, loop-protection, and STP design. Mesh doesn’t replace a gateway, DHCP, or firewall rules.
Plan before creating the mesh
- Prefer cable: Use wired backhaul when every location can be cabled. For wireless mesh, plan a clear path and a star topology with few hops.
- Choose a band: 6 GHz offers high bandwidth and no DFS channels but short range; Sophos recommends it for AP6 420E and 840E. 5 GHz balances range and bandwidth; 2.4 GHz reaches farther but offers less bandwidth.
- Fix the channel: Every mesh AP6 must use the same channel on the backhaul band. Sophos recommends turning off autochannel after planning and setting the channel manually. APs outside the mesh should avoid that channel.
- Size conservatively: The Sophos FAQ says a maximum of five AP6 units on wireless backhaul and eight on wired backhaul. The overview instead says five or eight nodes. We don’t infer extra capacity and use the stricter FAQ limit including the root until Sophos clarifies it.
- Account for hops: Sophos states roughly 50% less maximum bandwidth plus 1–5 ms latency and more jitter for every hop to the root. These are planning figures, not throughput guarantees.
- Record the baseline: Capture AP names, models, MAC addresses, switch ports, mesh band and channel, root, client SSID, VLANs, and current assignments. An AP can have only one mesh backhaul SSID; AP6 supports one mesh SSID per broadcast domain.
MAC filtering and band steering aren’t available on an AP6 configured in a mesh. Fusion isn’t a general requirement for roaming outside a mesh: the client decides when to roam. Mesh describes the backhaul here, not a universal roaming requirement. See the AP6 RF and roaming guide.
Create the AP6 mesh in Sophos Fusion
At least two AP6 units must be registered in Fusion, and all participating units must initially be physically connected to the same LAN. The root needs at least one assigned client SSID with at least two enabled radio bands, one matching the mesh band. Future nodes must have no SSIDs assigned because the root synchronizes them later.
- Open My Products > Wireless > SSIDs, click Create AP6, and select Mesh.
- Select the strongest compatible Encryption mode and the planned Frequency band. Optionally enter a distinct backhaul name such as
Mesh-HQ-5G; clients still need a separate fronthaul SSID. - Move the prepared AP6 units from Available access points to Assigned access points.
- Select the root. Fusion only lists eligible AP6 units with the most radios and highest bandwidth; units already assigned to a mesh don’t appear.
- Remove only the SSID assignments that Fusion reports as incompatible. Keep the intended fronthaul on the root and remove every independent SSID from nodes.
- Select Enable SSID, save, and confirm that all AP6 units are connected over Ethernet.
- Under My Products > Wireless > Access Points, wait until every participating AP6 shows Config Status: up to date. Don’t disconnect or move them before then.
- For wireless nodes, power off, remove the LAN data connection, and power on at the planned location. Keep the root wired. Leave the intended LAN connections in place for wired backhaul.
Accept the mesh and client path
Open the mesh under My Products > Wireless > SSIDs and select Mesh status. It shows each root or node’s name, MAC and IP address, Type, Hop, and Signal. An RSSI value closer to zero means a stronger signal.
Fusion status isn’t sufficient. In the local AP6 interface, use Wireless Settings > Mesh or the local mesh view to confirm that all expected devices and roles appear; Refresh updates it. Then test at the root and every node with a client:
- fronthaul visible and authentication successful;
- expected client IP, gateway, and DNS received;
- allowed destinations reachable and blocked destinations still blocked;
- hop, signal, latency, jitter, and application throughput recorded;
- for a bridge, a device on the node Ethernet segment works without creating a LAN loop.
Only add more nodes or production clients after this acceptance test.
Troubleshoot by symptom
Mesh doesn’t appear: Wait up to five minutes. Then check Config Status, assignment, a common backhaul channel, and STP. At least a root and node must be assigned, and the root must remain on the LAN.
A node is missing: Confirm it stayed on the LAN until initial configuration completed and was restarted. For intended wireless backhaul, its LAN data connection must then be removed. Check the root fronthaul, two enabled root bands, and matching mesh band.
Fusion shows roles, but mesh doesn’t work: Fusion’s role display doesn’t guarantee formation. Open the local mesh view, inspect hop and signal, move the node closer, and try a longer-range band if the design permits.
Throughput or voice is poor: Check hop count, RSSI, line of sight, co-channel interference, and non-mesh APs using the backhaul channel. Improve star topology or placement before changing several radio values at once.
The SSID can’t be edited on a node: This is expected. Assign client SSIDs to the root; it synchronizes them to nodes.
Change or roll back safely
You can assign or unassign nodes without recreating the mesh, but at least one root and one node must remain assigned. You can’t directly edit AP6 mesh details: to change them, reconnect every AP6 to the LAN, delete the mesh, and recreate it.
For a failed pilot, stop rollout. Power off wireless nodes, reconnect them to the documented LAN, and start them. Once online and current, delete or turn off the mesh for a complete rollback; don’t try to dissolve the final root-node pair by unassigning it. Then either recreate the documented previous mesh or restore the former standalone SSID assignments. Don’t begin with a factory reset. Finally retest AP status, known production SSIDs, and the client data path. Because no automatic root replacement is documented, monitor the wired root connection as an operational dependency.