Sophos Fusion Wireless: Guest networks and captive portals for AP6
A secure AP6 guest network has two distinct parts. Sophos Fusion (formerly Sophos Central) distributes the SSID, guest-network and portal configuration. Client traffic, however, travels from the device through the AP6, switch and gateway to the internet. Sophos Fusion creates neither the VLAN nor the firewall rules. An AP shown as online therefore does not prove that guests receive an address or cannot reach internal networks.
In brief: Prepare a dedicated guest VLAN with DHCP, DNS, a gateway and restrictive rules. Open the existing AP6 SSID under My Products > Wireless > SSIDs, select the VLAN under Advanced Settings > Client Connection, and enable Enable Guest Network. Choose Bridge Mode or NAT Mode deliberately, enable the hotspot under Captive Portal, configure authentication and the landing page, test on one pilot AP, and only then expand the rollout.
Plan the management plane and guest data path
The examples below use SSID Guest-WiFi, VLAN 120, network 10.120.0.0/24 and gateway 10.120.0.1. Replace them with an unused VLAN and subnet from your environment. The AP6 management path remains unchanged; VLAN 120 is an additional client path to the gateway. For the underlying design, see Plan AP6 SSIDs and VLANs.
Complete this preflight before configuring the portal:
- Allow VLAN
120on the AP uplink and every switch trunk in the path. - Provide a gateway, DHCP and DNS in the guest network. In Bridge Mode, your infrastructure supplies the leases.
- Permit only the required internet services and explicitly block internal networks, including management, server, voice, printer and site networks.
- Allow DNS, NTP and, where needed, access to a RADIUS server narrowly. Do not use a broad guest-to-LAN rule as a shortcut.
- Prepare tests for at least one allowed internet destination, one blocked internal destination and two different client types.
Sophos documents an important limitation: the Sophos Fusion guest network permits public IP addresses. If your organization uses publicly addressed resources internally, block those destinations at the gateway as well. Blocking private address ranges alone is not sufficient.
Choose Bridge Mode or NAT Mode
Sign in at fusion.sophos.com, open My Products > Wireless > SSIDs, edit the AP6 SSID and go to Advanced Settings > Client Connection. Select LAN or VLAN, enable Enable Guest Network, and choose the addressing mode.
Bridge Mode for controlled segmentation
In Bridge Mode, clients obtain addresses from your DHCP server in the selected LAN or VLAN. The AP6 automatically isolates guest clients from one another; Sophos Fusion also describes internet access without access to private IP addresses. Sophos cites seamless roaming between multiple AP6 access points as another benefit.
For most business networks, Bridge Mode with a dedicated VLAN is the clearest option: gateway, leases, DNS and matched rules remain visible in your infrastructure. Do not rely on the AP alone for protection. The gateway must block internal destinations and limit permitted internet services.
NAT Mode for AP-addressed guests
In NAT Mode, the AP supplies DHCP and DNS information and translates client traffic onto the LAN. Clients cannot communicate with one another but can access the internet. Primary DNS Server and Secondary DNS Server are optional; without them, the AP distributes its own DNS servers.
NAT Mode is useful when a separate client VLAN is not available, but it gives the gateway less direct visibility of individual guest addresses. Decide in advance how logging, policy enforcement and support investigations will work. In either mode, the upstream firewall remains responsible for the rest of the data path.
Configure the captive portal in Sophos Fusion
Under Advanced Settings > Captive Portal, select Enable hotspot. Give the landing page a clear Page title, brief Welcome text and, if required, Terms of service. Terms must be under 10,000 characters and cannot contain HTML or special characters.
Select the authentication type that matches the use case:
- None displays the portal without a user login. Network separation and firewall rules are still required.
- Backend authentication uses RADIUS with PAP. Enter the server IP address, port and shared secret; Sophos Fusion lists
1812as the default port. Use a strong secret dedicated to this relationship and open only the network path required for authentication. - Password schedule generates a new password daily, weekly or monthly. Verify the time zone and recipients, and share passwords only with authorized people.
- Social login requires a current Google or Facebook application configuration. Authorized Domain can restrict access to identities from the specified domain. Check the provider’s current requirements separately before rollout.
- Voucher provides time- or data-limited individual access and is covered below.
For every method, set Session timeout to a value from 1 to 24 hours. Re-login timeout additionally determines whether guests must sign in again every day, week or month. Choose both values to match the risk and intended visit duration.
For Redirect URL, choose either the originally requested page or a custom HTTPS address. A custom destination must be reachable from the guest network. Save the settings; the hotspot becomes available after Sophos Fusion updates the AP.
⚠️ Review legal and privacy requirements before activation: Sophos notes that public hotspots may be subject to country-specific requirements, content restrictions or registration obligations. Align terms of use, logging, retention and social login with your legal and privacy requirements.
Customize the portal without obscuring sign-in
The hotspot must already be enabled. Under Advanced Settings > Captive Portal > Template, select Custom. In Customization preview, upload a logo and set the background color. Sophos allows up to 1 MB and recommends 200 × 200 pixels. Use the preview on the right for a visual check, then save the portal options followed by the SSID settings.
Also test on a small smartphone. The title, consent text, sign-in fields and button must be legible without zooming. Do not put credentials, internal hostnames or personal data in the logo. A preview validates appearance only—not DNS, redirection, authentication or internet access.
Create and manage vouchers throughout their lifecycle
First select Voucher as the Authentication type and save the SSID. The Create voucher button appears under Advanced Settings > Captive Portal only after you edit the SSID again.
- Enter a traceable Voucher name, such as
reception-2026-09-09, without storing guest names in Sophos Fusion. - Under Access time, choose Unlimited or Period with a start date, end date and time zone. A limited window is safer for ordinary visits.
- Under Data limit, choose Unlimited or a limit appropriate to the service rather than the largest possible allowance.
- Set Number of vouchers. Sophos Fusion creates no more than
100in one operation. - Keep Devices per voucher as low as possible. The maximum is
8; for one person,1is usually easier to attribute. - Use Valid for to set the days and hours from first use. With multiple devices, this shared period starts when the first device connects; later devices do not receive a new period.
- Select Confirm, then use Show PDF to store the vouchers securely or print them, and issue them only to the intended recipients.
Sophos requires reauthentication every 24 hours even when access lasts longer. If you need more than 100 vouchers, Clone can copy the selected values into a new creation dialog.
Keep a minimal issue record outside the code: voucher name, issue time, purpose, responsible person and planned end. Protect PDFs and printouts because they contain access credentials. After the event, reconcile the record, stop distributing vouchers, and securely destroy exports and printouts that are no longer needed. The inspected documentation does not confirm per-voucher revocation, so use bounded validity. If access must be cut off immediately, disable the hotspot in a controlled manner or contact Sophos Support.
Validate the pilot end to end
Initially test only through one pilot AP and with a device that has no saved portal session:
- Join
Guest-WiFiand record the IP address, gateway and DNS. In Bridge Mode, the address must belong to the intended VLAN; in NAT Mode, it comes from the AP. - Open an HTTP page so the operating system does not merely repeat a cached HTTPS request. Confirm that the portal appears with the expected template.
- Try an invalid voucher or invalid credentials. Internet access must remain blocked.
- Authenticate successfully, verify the redirect and open an allowed internet destination.
- Open an internal test destination. Access must fail; verify the intended block rule at the gateway.
- Test two guest clients against each other. The documented client isolation must work.
- Test expiry or the data limit with a short-lived voucher before issuing longer-lived vouchers.
- Confirm that the AP remains reachable in Sophos Fusion. This distinguishes portal or client-path faults from a problem with the management connection to Sophos Fusion.
Troubleshoot by symptom
The portal does not appear
Check Enable hotspot, SSID assignment and whether Sophos Fusion has updated the AP. Then inspect the client’s address, gateway and DNS. Saved sessions and HTTPS-only requests can mislead automatic portal detection; retry with a new client or private browser window and an HTTP page. Do not change both the VLAN and portal as your first troubleshooting step.
The portal appears, but sign-in fails
For vouchers, check the access window, time zone, Valid for, device count and exact code. For Backend authentication, verify reachability of the RADIUS IP and port 1812, the shared secret, and any rejection in the RADIUS log. For Social login, also check provider configuration and external reachability. Evidence may include time, client MAC address, AP, SSID and authentication type, but never passwords or complete voucher codes.
Sign-in succeeds, but internet access or redirection fails
Trace the client IP address, DNS, gateway, route and matched firewall rule through the data path. A custom redirect address must be reachable from the guest network. Test Redirect to original URL if needed, but recognize that this does not repair missing DNS or firewall access.
Guests can reach internal or publicly addressed internal destinations
Stop the pilot immediately and correct the gateway rules. In Bridge Mode, also verify that VLAN 120 is actually assigned. Explicitly block your organization’s public addresses because Sophos Fusion’s guest network does not treat them as private.
Roll back safely
Before changing anything, record the previous client-connection mode, VLAN, guest-network status, captive-portal status, authentication type, redirect and AP assignment. If a test fails, do not assign the SSID to additional APs.
For a quick rollback, disable Enable hotspot and save. If segmentation is at risk, also disable the guest network or remove the SSID from the pilot AP, then restore the recorded configuration. You do not need to delete the entire SSID. Recheck the Sophos Fusion update, known production SSIDs and the client data path. Start a new pilot only after the block rules and portal test pass again.
Keep the local AP6 interface separate
A standalone AP6 has a separate Captive portal configuration in its local interface, including landing page, authentication, vouchers and redirection. The Sophos Fusion paths above do not apply there. Sophos also documents a local Walled garden that limits clients to listed domains or IP addresses.
A local portal needs a portal IP address in the relevant client network. Sophos explicitly warns that a DHCP scope limited to the local LAN can prevent the portal from appearing when multiple networks or VLANs are involved. This is not a reason to run the firewall console commands shown on that help page without review; plan DHCP and reservations on the gateway actually in use. For a centrally managed AP6, change the Sophos Fusion configuration and do not mix management planes. For the underlying choice, see Manage AP6 locally or with Sophos Fusion.