Restart, back up, restore, or factory-reset a Sophos AP6 locally
This runbook applies only to the local web interface of a Sophos AP6. The available actions serve different purposes: a restart restarts the device now, a restart schedule does so later, a backup writes the current settings to a .bin file, and a restore replaces the current settings from such a file. Factory default, by contrast, discards configuration changes and resets the IP address and administrator password as well.
⚠️ Plan a maintenance window: Restart, restore, and Factory default restart the AP6. Its wireless data path is interrupted and connected clients are disconnected. A scheduled restart causes the same interruption at the configured time. If this AP6 is the only one serving an area, wireless access is unavailable there until it is operational again.
Before making a change
- Have the local AP6 IP address, local administrator credentials, and physical access to the device or switch port available. The browser connects directly to the AP6 IP address.
- Record the current management access, relevant wireless, VLAN, and network settings, and the expected client data path. For the distinction between local and cloud management, see Manage AP6 locally or with Sophos Fusion (formerly Sophos Central).
- Before a restore or Factory default, create a fresh backup under Advanced > Save/Restore settings and verify that the
.binfile is actually present on the administrator’s computer. - Prefer an encrypted backup. Store its password separately and securely: without the correct password, an encrypted file cannot be opened in the documented restore flow. Treat the file as a secret because Sophos does not document which individual sensitive values it contains.
- Do not begin with an untested file. Record the model, firmware version, creation date, and associated AP6 in the filename or a separate inventory. Arbitrary compatibility across models or firmware versions is not documented.
Choose the correct action
- Restart now: for a malfunctioning or unresponsive device. Its documented purpose is a restart, not a configuration reset or replacement.
- Schedule restarts: for recurring restarts on selected weekdays at a specified time. It neither creates a backup nor troubleshoots the client data path.
- Back up or restore: back up before a risky change; restore when an exact, previously saved local settings state is required. Restore replaces current settings and then restarts.
- Factory default: only when all configuration changes must deliberately be discarded or a clean rebuild is required. This is the destructive option.
Restart locally now
- Sign in to the local web interface and open Advanced > Reboot.
- Click Reboot. The interface displays a countdown indicating restart progress.
- Alternatively, press and release the physical reset button. Do not hold it, because holding the button starts the Factory-default sequence.
Validation: Wait for the countdown, reopen the local interface, and use a test client to verify SSID visibility, association, IP address, gateway, DNS, and an allowed destination. A reachable GUI alone does not validate the client data path.
Recovery boundary: A restart already in progress cannot be rolled back. The documented procedure does not replace settings. If the AP6 remains unreachable, first check power, switch port, DHCP lease, and the recorded management IP; do not immediately use Factory default.
Configure or remove a restart schedule
- Open Advanced > Reboot schedule.
- Select Enable for Reboot schedule, then click Apply.
- In the following dialog, choose Apply to save immediately or Continue to configure more settings before saving.
- Click Add, select weekdays and a time, then click Apply.
- In the following dialog, choose Apply to save or Continue for more settings.
Remove the schedule with Delete. Reload the page and verify that the intended schedule is shown or no longer shown. Before the first production event, compare the time with the device time actually displayed; time-zone behavior is not documented for this workflow. Delete is a recovery option only before the event starts. Once restart begins, use the same limits and checks as for an immediate restart.
Back up the local configuration
- Open Advanced > Save/Restore settings.
- Optionally select Encrypt the configuration file with a password and enter a strong, unique password.
- Click Save. The AP6 saves its current settings to the administrator’s local device as a
.binfile. - Verify a non-zero file size and a known storage location. Do not edit the file. Keep a second protected copy according to your backup policy, and do not store the file and password together in an unprotected location.
A successful download proves only that a file exists. No offline integrity check or restore compatibility across models or firmware versions is documented. A restore test therefore belongs on a suitable maintenance or replacement device, not as an unplanned test on the only production AP6.
Restore the configuration
⚠️ Current settings are replaced: The AP6 restarts after Restore. Open administrator sessions and wireless connections are interrupted. Ensure that you know the IP address and credentials from the saved state before continuing.
- Under Advanced > Save/Restore settings, click Choose file, select the correct
.binfile, and click Open. - For an encrypted file, select Open file with password and enter its password.
- Click Restore. This replaces the current settings; the AP6 restarts to complete the process.
- Reconnect using the management values associated with the backup. Spot-check the local settings, then verify SSID, authentication, DHCP, gateway, DNS, VLAN assignment, and allowed destinations with a test client.
Rollback: If the restored state is reachable but incorrect, the available rollback is another known, suitable .bin file or a manual configuration correction. If the local interface is unreachable because restored IP or credential values took effect, first check those values, DHCP, and the switch/VLAN. Factory default is the last local recovery level, not an automatic undo for a restore.
Factory default through the GUI or button
⚠️ Destructive and irreversible: All configuration changes are lost. The IP address and administrator password are replaced by factory defaults. Continue only with a backup, physical access, and a recommissioning plan.
From the local GUI
- Open Advanced > Factory default.
- Click Factory Default.
- Confirm the prompt with OK. The AP6 restarts with factory-default settings.
With the physical reset button
For AP6 420(E) and AP6 840(E): hold the button for five seconds until the status LED is solid red. Keep holding for another five seconds. Releasing during this second phase still cancels the reset. Release when the status LED starts blinking red.
For AP6 420X: hold the button for five seconds until the status, radio, and mesh LEDs blink red. Keep holding for another five seconds; releasing during this second phase still cancels. Release when the mesh LED turns off.
The device then restarts with factory-default settings in both flows. Use these LED sequences only for the explicitly listed models.
Recovery boundary: There is no undo after the decisive release. Reach the AP6 with its factory defaults, then either rebuild it deliberately or restore a suitable backup from the local interface. Fully validate management access and the client data path afterward.
What cannot be inferred about Sophos Fusion state
For local AP6 maintenance actions, it is not documented whether a backup or restore contains a tenant assignment, registration, or claim. Nor is it reliably described how Factory default affects an existing Sophos Fusion record or claim state. A .bin file, restore, or successful Factory default therefore supports no conclusion about tenant or claim status. If that state matters for recommissioning, sign in to Sophos Fusion, inspect it separately, and validate it after the local action.