Diagnose Sophos AP6: logs and packet captures
With a Sophos AP6, define the question before starting a diagnostic tool. System logs are usually the best starting point for a Central or provisioning issue. Syslog helps with an event over time. A packet capture shows whether particular packets arrive at a wired or wireless interface. Ping and traceroute only test reachability from the AP6’s perspective.
Fast path: Record the AP, test client, symptom, and time including timezone. Reproduce the problem once under controlled conditions while collecting System logs, running a short Packet Capture, or deliberately starting Syslog. Stop the capture afterwards, test the client data path separately, and share only sanitized data belonging to the incident window.
⚠️ Wireless capture causes an interruption: Local WLAN packet capture disconnects all connected wireless devices. Schedule a maintenance window. Captures and logs can contain addresses, device names, user-related details, and payload data; limit access, storage, and sharing to the specific support case.
Separate the management and telemetry plane from the client data path
Sophos Fusion (formerly Sophos Central) configures diagnostic tasks and receives status or log archives over the AP6 management and telemetry plane. The client data path instead runs from the endpoint over radio, AP6, switch port, and VLAN to DHCP, DNS, gateway, and destination. It does not pass through Sophos Fusion.
A green AP state proves Central can reach the AP6, not that a client has the correct VLAN, address, DNS response, or application access. Likewise, a ping from the AP6 uses its own network view and cannot replace a client ping or a capture at the suspected point in the client path.
If the AP is offline in Central, Central packet capture, syslog, and new system-log collection cannot start. Restore power, uplink, DHCP, DNS, time, and Central connectivity with the AP6 offline runbook. See Central Wireless requirements for the underlying destinations and ports.
Prepare the capture
- Record AP name, model, serial number, site, management IP, switch port, SSID, expected client VLAN, and firmware.
- Record start, end, and timezone. The AP6, client, syslog system, and other components need a traceable time basis.
- Choose one known client and one exact reproduction, such as “join SSID, obtain address, open destination.” Keep client MAC and IP addresses only in the protected case notes.
- Choose system logs for state, syslog for a live sequence, capture for packets, or ping/traceroute for reachability from the AP.
- Preserve current settings and visible errors. Do not reset, restart, or combine configuration changes before the first capture.
Collect system logs and local AP6 logs
Complete system logs through Central
- Open My Products > Wireless > Diagnostics > System logs.
- Check AP name, serial number, model, Status, and Last generated at. Collection works only while status is green.
- Click Collect logs for the affected AP and wait for generation to finish.
- Use Download logs to download the
.GZarchive. Record its filename and generation time with the reproduced incident time.
Last generated at distinguishes an old archive from the requested collection. Sophos does not state a fixed retention period here, so do not assume it remains available; download it securely and handle it under your policy.
Local log and advanced RSSI entries
In the local AP6 interface, Information > Log shows operational information such as uptime and connection processes. Search filters while typing, and Match whole words restricts matches. Entries contain ID, date/time, category, severity, user, and event description. Save exports logmsg.log; Refresh updates the view.
Do not clear before saving: The AP overwrites older entries when the log reaches an unspecified size. Sophos gives no fixed size or retention. Clear empties the log, so use Save first and clear only with deliberate approval.
Under Information > Advanced log, Low RSSI threshold creates entries when a connected device’s RSSI falls below -70. For a focused radio test, choose Enable > Apply, record the interval, then reverse it with Disable > Apply. It is a log signal, not proof of a particular root cause.
Sophos also documents the read-only CLI command show status log. The local interface is usually more convenient for filtering and export; still include execution location, time, and only the relevant extract in a case.
Run the packet capture at the right point
Received wired packets through Central
At My Products > Wireless > Diagnostics > Packet Capture, an online AP6 can capture received packets on its wired LAN ports. This AP6 capture in Central does not capture WLAN radio traffic.
Central packet capture requires AP6 firmware 2.1.0-1 or later. If Central shows Not Supported, check and update the firmware before trying again.
- Select the AP6 and start immediately before reproduction.
- Run the defined client test exactly once and note start and end times.
- Stop or wait for completion. Status includes Started and Completed; Download retrieves the result from the AP6.
- Label the PCAP with AP, interface context, client, and interval without publishing those details openly.
If the expected packet is already absent at this receive point, move the next check earlier in the path. If present, examine the return path, VLAN, gateway, or next hop. One capture never proves the entire client path.
Capture LAN or WLAN locally
The local Management > Packet capture page provides two modes:
- Packet Capture records LAN-port traffic for the entered duration in seconds.
- WLAN packet capture records traffic on the 2.4, 5, and 6 GHz frequencies for the entered duration and disconnects all connected wireless devices when it starts.
Enter duration, click Start, and watch Status. Cancel can stop the capture at any time. When complete, click OK, then Save. The AP6 saves multiple PCAP files, one per Ethernet interface and wireless frequency. Keep them together with the interval and analyze the interface relevant to the question first.
Keep captures short to reduce disruption and data volume. Never start WLAN capture without an announced maintenance window; afterwards verify that clients reconnect and their data path works.
Use syslog deliberately
Temporary syslog capture in Central
At My Products > Wireless > Diagnostics > Syslog, syslog capture can be started for an online AP. Prepare a reachable syslog server first:
- The AP6 must be able to reach the server. When capture starts, the AP6 sends a ping; the server must answer that ICMP probe, or the AP sends no UDP packets.
- Syslog uses UDP port
514by default. If the listener uses another port, enter that exact port in Central and permit it along the path. - Allow UDP to the configured listener port along the network path. On the server, verify the listener, the correct interface, and sufficient storage.
- Sophos recommends configuring no more than two APs per syslog server to avoid intermingled debugging data.
Enter server IP and port, then select Start for the AP. Started confirms the task; Server not reachable points to reachability of the entered IP. Confirm new messages with the expected source and time on the server. After reproduction, click Stop in Central and verify messages cease.
Configure syslog locally
Under Management > Syslog server, select Enable Syslog server and enter the server hostname, domain, or IP and its port; the documented default is 514. It must match the real listener. If enabled only for diagnosis, disable it afterwards and verify that new AP messages stop arriving.
Keep UDP syslog and PCAP transfers on trusted administrative networks and protect the receiver. Persistent collection also needs your own storage, access, and deletion policy; the cited Sophos pages do not prescribe general retention.
Test ping and traceroute from the AP perspective
At Management > Ping test, the local interface has separate IPv4 Destination address and IPv6 Destination address fields. Enter the address and click Execute. Ping runs continuously until Stop; Result shows responses.
Test the management gateway first, then the syslog or internal destination, and finally an external destination allowed for that path. Use approved real internal targets, not copied example addresses. If the AP6 cannot reach its gateway, inspect management VLAN, switch port, and gateway. If it reaches the gateway but not syslog, inspect routing and intermediate rules.
At Management > Traceroute test, enter Destination address and click Execute. Stop ends the run and Result shows route and transit information. A missing intermediate response alone is not proof of failure because hops may filter replies; reaching the actual target service is decisive.
Both tests originate from the AP6 management view. Repeat the functional test from the affected wireless client to distinguish a fault before the AP, in the client VLAN, or farther downstream.
Interpret results by symptom
AP online, client gets no address: Correlate the client attempt with a local WLAN and, if useful, LAN capture. Look for DHCP on the relevant interface and inspect the switch port and expected VLAN. A successful AP ping to its management gateway does not disprove client-VLAN DHCP failure.
Association drops or signal is weak: Plan a short WLAN maintenance window, enable Low RSSI threshold deliberately, and correlate client, place, and time. Disable it afterwards. Missing packets or RSSI entries alone prove neither a radio nor authentication fault; combine logs with client observations.
Central task or status stalls: While the AP is green, collect fresh system logs and record the exact last-change time. Do not stack more tasks. If it goes offline, continue with switch, DHCP, DNS, and gateway evidence outside the AP.
Syslog is empty: Check listener and interface, server IP, port, ICMP response, route, and rules between AP6 and server. Retry only after the server answers the AP ping, then prove one new message in the agreed interval.
Expected traffic is absent from capture: Recheck time, AP, interface, and reproduction. Central shows only received AP6 LAN traffic; WLAN traffic requires local WLAN capture. Repeat at the next logical point instead of changing VLAN, radio, and firewall settings together.
Stop safely, sanitize, and escalate
After every test use Cancel or Stop where offered. Disable Low RSSI threshold, turn off temporary local syslog, and confirm wireless clients reconnect after radio capture. Record end time, reversals, and result. Retain PCAP and logs only as long as policy and the case require.
A useful Sophos Support package contains:
- Central customer ID, AP name, model, serial, firmware, site, and management IP;
- expected versus actual behavior and business effect;
- start, reproduction, and capture interval with timezone;
- relevant system logs,
logmsg.log, syslog extract, or PCAP mapped to its interface; - client type and only the protected address data needed for correlation;
- last change and checks already completed, without passwords or unnecessary payload.
At My Products > Wireless > Diagnostics > Support settings, enable Remote Login to Access Points for Sophos Support for 5 hours, 1 day, 7, 14, or 30 days. Only after coordinating with Support, choose the shortest suitable period and monitor Remaining time. Turning it off revokes access immediately. Use Show to view and copy the Sophos unique customer ID.
Remote Login is not required for initial collection. If needed, record case number and access window in the Sophos support ticket, then disable it immediately when work ends. Reset or re-registration belongs only after evidence preservation and a specific support instruction.