Skip to content
Avanet

Monitor AP6 clients, Usage Insight, and alerts in Sophos Central Wireless

When Wi-Fi feels slow or a client disappears, the Wireless Dashboard is the starting point, not the diagnosis. Follow one trace: record the time, AP6, SSID, and client MAC address; inspect the client details; then correlate events, alerts, and, if enabled, Usage Insight.

Fast path: Sign in at fusion.sophos.com, open My Products > Wireless, note the affected period and AP6, find the MAC address under Devices, inspect Connectivity and Signal quality, then check Diagnostics > Events for matching AP, gateway, DNS, RADIUS, or retry events. Make a change only after reproducing the symptom.

This guide applies exclusively to AP6 managed in Sophos Fusion (formerly Sophos Central). Older AP series and the SFOS wireless controller are outside its scope.

What Sophos Fusion can and cannot show

Sophos Fusion is the management and telemetry plane here: it displays reported AP status, connected clients, signal history, usage, events, and alerts. Client traffic itself travels from the endpoint through AP6, the switch/VLAN, and the gateway or firewall. The AP6 management model and this data-path boundary matter: an AP6 shown as online does not prove that DHCP, DNS, the VLAN, and firewall rules work for the client.

Likewise, Online in the client list is not an application test. It confirms the reported association, not reachability of a specific service. A recently disconnected device may already be Offline while its historical data remains in a 24-hour or 7-day view.

Trace the issue from the dashboard to an AP6 and client

  1. Open My Products > Wireless. In Access Points, distinguish Good, Issues, Critical, Offline, and Unconfigured. If several clients fail together, investigate their shared AP6 or uplink before one endpoint.
  2. In Devices, switch between 24 hours and 7d. Toggle AP6 lines in the legend; a dashed AP6 line represents clients with poor signal quality.
  3. Filter Alerts with All, Errors, Warnings, and Info. Record alert type, AP6, and time rather than restarting immediately.
  4. If Usage Insight is enabled, record its top category and period. Heavy usage is correlation evidence, not proof that a client caused an incident.
  5. Click Devices and continue with the specific client.

Investigate a client globally or by SSID

At My Products > Wireless > Devices, choose 24h or 7d. The All bands, 2.4 GHz, 5 GHz, and 6 GHz filter affects both chart and list. Filter Online, Offline, or All, search by name, MAC, IP, or vendor, and use Export to CSV to preserve the filtered baseline.

Useful AP6 columns include MAC, IPv4/IPv6, Access point, SSID, Band, five-minute average upload/download speed, transferred data, and First seen. Do not overinterpret the name: for AP6, Device name may show only the MAC address. Security Heartbeat isn’t available for AP6 in this view and is not an AP6 health test.

Clicking a client opens Static details (current AP6, site, network, signal, band, status, hostname, addresses, username, and vendor), Usage details (external and total traffic), Connectivity (APs, SSIDs, and bands over time), and Signal quality. Colors in Connectivity only mark a status change; Sophos assigns no further meaning to a specific color.

For one network, use My Products > Wireless > SSIDs > SSID > Devices with the same time and band filters. A username appears only after supported authentication, such as WPA2/WPA3 Enterprise or supported captive-portal authentication. For enterprise failures, check the RADIUS and WPA3 Enterprise workflow.

Operational rule: Record MAC address, AP6 serial number, SSID, and time together. When a client rotates its private or randomized MAC address, one physical endpoint can appear as multiple records in Sophos Fusion.

Use Usage Insight for AP6

Usage Insight summarizes one day or one week of traffic. Its AP6 view shows the top five access points, SSIDs, and clients plus traffic categories; expanded categories show leading domains or IP addresses and total, uploaded, and downloaded data. It is a usage summary, not a packet capture or proof of connection contents.

Usage Insight is off by default:

  1. Confirm AP6 firmware 1.7.2563 or later.
  2. Open My Products > Wireless > Diagnostics > AP6 usage insight.
  3. Turn on Usage insight and click Save to categorize AP6 traffic.
  4. To categorize traffic from connected clients too, turn on Client usage insight separately and click Save again.
  5. From an approved test client, visit a known harmless HTTPS site. In Usage Insight, correlate AP6, SSID, client, category, and period. Sophos gives no guaranteed refresh time, so missing immediate data does not prove a fault.

Enable only the required level. To stop collection, turn the previously enabled controls off in the same view and click Save. Verify that no new test data is added; do not assume this deletes already aggregated history.

Correlate events and alerts correctly

At My Products > Wireless > Diagnostics > Events, select a range within the last 90 days and click Update. The list contains severity, date/time, and event type. Export saves the filtered current view or the past 90 days as CSV or PDF.

Sophos classifies events as High, Medium, or Low. Useful combinations include:

  • High: bad AP health, high client load, low Ethernet speed, unreachable DNS gateway, or unreachable AP gateway.
  • Medium: AP offline or not broadcasting, failed configuration or firmware update, DNS timeout, high packet retries, high DNS latency, unreachable RADIUS, or a channel change.
  • Low: scheduled or successful firmware updates, completed AP command, and restored Ethernet or RADIUS state.

Alerts are the actionable view of these conditions. After an action or Ignore, an alert leaves the active alert list but remains in Events. If an alert seems to have vanished, search event history by AP6 and time.

An event is not automatically the cause. Retries plus falling Signal quality for the same client and time support an RF hypothesis. A DNS timeout with stable signal points first to uplink, gateway, and DNS. Use the AP6 RF and roaming guide before changing RF settings.

Use the local AP6 as a cross-check

If local access is approved and available, Information > Wireless clients shows devices currently connected to that AP6 on 2.4, 5, and 6 GHz. The table includes SSID, IP/MAC, authenticated user, Tx/Rx, signal percentage, RSSI in dBm, connected and idle time, and vendor. Auto refresh or Refresh provides a local snapshot to compare with Sophos Fusion by MAC and time.

Kick only disconnects a client. Sophos explicitly says it does not block reconnection. Before using it, record MAC and time, use only an approved test device, and observe whether it reconnects. Do not use Kick as a block control.

Information > Wireless monitor > Site survey instead scans nearby SSIDs and shows channel, BSSID/MAC, security, signal, standard, and vendor. It helps assess the RF neighborhood but replaces neither the client table nor an application test.

Validate the finding in practice

  1. Identify the affected or approved test client by its currently used MAC.
  2. Save a baseline: time, AP6, SSID, band, IP, signal, Sophos Fusion status, and a harmless test target.
  3. Repeat one test, such as DNS resolution and HTTPS access to an approved target, without changing configuration at the same time.
  4. Refresh client details, AP6 status, and events/alerts for the same period. Add Usage Insight only if it is enabled.
  5. Form a hypothesis only when time, MAC, AP6, and test result agree. Make one low-risk change in the responsible system and repeat the identical test.

This distinguishes a changed Sophos Fusion indicator from a real improvement in the WLAN/client data path.

Common symptoms

The client is missing or appears twice

Reset the period, Online/Offline/All, and band filters. Compare global and SSID views using the current MAC. Check the endpoint for a changed private MAC. If the client is also absent from the expected AP6 locally, verify SSID assignment and the endpoint connection; do not infer identity from an old IP address.

Signal is poor or the client moves frequently

Compare Signal quality and Connectivity over the same period, then look for retries, channel changes, and AP load in Events. One affected client suggests position, client radio, or driver; many on one AP6 suggest coverage, channel/uplink, or load. Separate these cases before changing RF settings.

Usage Insight remains empty

Check firmware 1.7.2563, the saved Usage insight state and, for client categories, Client usage insight. Verify period and AP6 view, then generate a known test. Do not expect instant display. If AP6, SSID, and client remain empty, preserve time and firmware details and escalate through the separate diagnostics workflow.

Alert and client impact do not match

Confirm the alert historically in Events, limited to the same AP6 and time, then repeat the client test. For gateway, DNS, or RADIUS events, inspect that upstream service; for offline or failed configuration, prioritize power, Ethernet, and Sophos Fusion reachability. Continue with the AP6 offline, provisioning, and performance runbook.

Packet capture, System Logs, Syslog, and temporary support access are separate Diagnostics tasks. Start them only after narrowing the case with a documented MAC, AP6 serial, period, and reproducible test—not preemptively in this monitoring workflow.