Skip to content
Avanet

Sophos Wireless: Configure an AP6 SSID with a VLAN

A production AP6 SSID requires more than a Wi-Fi name: the switch must carry the client VLAN to the access point; the gateway, DHCP, DNS, and rules must work within that VLAN; and Sophos Fusion (formerly Sophos Central) must assign the SSID to the correct AP. The AP6 management connection remains a separate path.

Quick procedure: Sign in at fusion.sophos.com, prepare the client VLAN on the network, allow it as a tagged VLAN on the AP uplink, create a network under My Products > Wireless > SSIDs > Create AP6 > SSID, select VLAN mode and the VLAN ID under Advanced settings > Client connection, and initially choose Add access points later. Then assign the SSID to a single pilot AP, enable it, and test the complete client path.

Separate the management network, client VLAN, and gateway

An AP6 uses its management network for its IP address, DNS, time synchronization, and connection to Sophos Fusion. The client VLAN, by contrast, carries traffic from devices connected to the SSID. A green AP status in Sophos Fusion therefore does not confirm that a Wi-Fi client can obtain an address, resolve DNS names, or access the internet.

This example uses:

  • SSID: Office-Clients
  • Client VLAN: 110
  • Client network: 10.110.0.0/24
  • Gateway: 10.110.0.1
  • DHCP range: 10.110.0.50–10.110.0.199
  • AP management network: already configured and unchanged

110 and 10.110.0.0/24 are example values that you can change. Replace them with an unused VLAN and subnet in your environment. The VLAN ID must match on the AP uplink, every switch in the path, and the gateway. The Sophos Wireless requirements explain the management path, PoE, DHCP, DNS, and Sophos Fusion destinations.

Prepare the client VLAN outside Sophos Fusion

Sophos Fusion configures the SSID and instructs the AP to tag client traffic with the selected VLAN ID. However, Sophos Fusion does not create the VLAN on a switch, nor does it create a gateway, DHCP range, or firewall rule. These components must already exist on the LAN.

  1. Create the gateway: Configure 10.110.0.1/24 for VLAN 110 on the router or firewall.
  2. Provide DHCP: Configure a range such as 10.110.0.50–10.110.0.199, gateway 10.110.0.1, and the appropriate DNS servers.
  3. Define the rules: Allow only the destinations that are actually required. A client VLAN is not a security boundary if routing and rules remain unrestricted.
  4. Prepare the switch path: Allow VLAN 110 on every trunk leading to the AP. Leave the existing treatment of the management network unchanged on the AP port and add VLAN 110 as tagged traffic.
  5. Test before using Wi-Fi: If possible, first test the VLAN, DHCP, DNS, and rules through a wired test port in VLAN 110. This makes it easier to isolate any subsequent issue to the SSID, AP assignment, or AP uplink.

If a Sophos Firewall provides the gateway, Configure and test a Sophos Firewall VLAN covers the VLAN interface, DHCP, rules, and data-path testing. The tasks are the same with another gateway; only the user interface differs.

Create the AP6 SSID in Sophos Fusion

Open My Products > Wireless > SSIDs, click Create AP6, and select SSID.

  1. Under Settings, enter an SSID, such as Office-Clients. SSIDs are case-sensitive, can contain 1 to 32 printable characters, and should use printable ASCII characters for broad client compatibility.
  2. Select personal encryption appropriate for your client fleet. Under Shared secret, enter 8 to 63 printable ASCII characters. Generate a strong secret used only for this SSID; do not copy an example value. For 6 GHz, Sophos Fusion requires WPA2/WPA3 or WPA3; AP6 supports AES only. Enterprise authentication and dynamic VLAN assignment require a separate RADIUS and WPA3 Enterprise workflow.
  3. Under Frequency band, enable only the required bands. The availability of a band does not guarantee that every client supports it.
  4. Under Assign network, initially select Add access points later. This allows you to save the configuration without immediately updating all assigned APs.
  5. Open Advanced settings and, under Client connection, select VLAN mode. Enter 110 as the VLAN ID.
  6. Save the configuration, but keep the rollout controlled. Do not turn on Enable SSID until the gateway, DHCP, rules, and switch trunk are ready.

LAN sends client traffic untagged to the same LAN. VLAN tags it for a statically selected client VLAN. RADIUS VLAN assignment can supply per-user VLAN information with enterprise authentication, but it has its own requirements and limitations. In Sophos Fusion, Bridge mode and NAT mode are operating modes for an enabled guest network; they are not terms for a standard production VLAN SSID.

Assign the SSID to a pilot AP first

Edit the saved SSID, open Assign network, and initially assign it to only one registered AP6 at the test site. Then turn on Enable SSID and save the configuration. The AP uplink must carry VLAN 110 as tagged traffic. If the path crosses multiple switches, the VLAN must be allowed across the entire path.

⚠️ Plan for a brief interruption: When you save the configuration, Sophos Fusion updates every AP assigned to the SSID. Connected Wi-Fi clients may be disconnected briefly. For a new SSID on APs already in production, Sophos therefore recommends initially selecting Add access points later.

Then check My Products > Wireless > SSIDs to confirm that the SSID is enabled and assigned to exactly one access point. Under My Products > Wireless > Access Points, verify that the pilot AP is online and has applied the new configuration. The AP onboarding wizard describes registration and site assignment; Manage AP6 locally or with Sophos Fusion explains status information and the Task Queue.

Validate the complete data path

Use a client that has not previously connected to this SSID:

  1. Connect to Office-Clients and verify that the encryption method and band are negotiated as planned.
  2. Confirm that the client receives an address in the 10.110.0.50–10.110.0.199 range, gateway 10.110.0.1, and the intended DNS servers.
  3. Verify access to the gateway and an approved internal service. An internal destination that should be blocked must remain inaccessible in accordance with the planned rule.
  4. Resolve a DNS name and open an allowed external destination. A successful connection to the SSID alone does not prove that the data path is working.
  5. On the gateway or firewall, confirm that the test client appears in VLAN 110 and matches the expected rule.
  6. Repeat the test after reconnecting and with at least one other type of client. Only then assign additional APs in a small batch.

Document the SSID type, encryption, bands, VLAN ID, pilot AP, switch port, gateway, DHCP range, and observed success criteria. These values also provide a safe rollback reference.

Troubleshoot by symptom

SSID is not visible: Check Enable SSID, the AP assignment, the pilot AP’s configuration status, and the enabled bands. Also verify that the endpoint supports the selected band and encryption method.

Client connects but does not receive an IP address: First verify that VLAN 110 is allowed as tagged traffic on the AP port and every uplink. Then check the DHCP scope, the relay or local reachability of the DHCP server, and the gateway interface. The AP’s management address is not a substitute for a client address.

Client receives an address, but DNS or internet access does not work: Check the gateway, DNS settings, route, firewall rule, and, if applicable, outbound NAT along the client path. Sophos Fusion’s status does not indicate which rule matched on the gateway.

Only some APs work: Compare the SSID assignment and configuration status for each AP, then compare the switch port profile and allowed VLANs along the affected path. Do not change the SSID, VLAN, radio settings, and firewall rules at the same time.

The change disrupts production clients: First, do not assign any additional APs. Turning off Enable SSID affects every AP assigned to this SSID. For an AP-specific rollback, instead remove only the pilot AP assignment under Assign network and restore the most recently documented settings. Then check the AP status and known production SSIDs. Reassign the new SSID only after correcting and retesting the wired VLAN; deletion is not required for rollback.