Sophos Wireless requirements for Sophos Fusion
Many registration failures occur before the Wireless profile even comes into play: the access point receives too little power, is connected to the wrong management network, or cannot reach Sophos Fusion (formerly Sophos Central). This checklist therefore separates the hardware, switch-port, and bootstrap-connectivity checks from the outset. SSIDs and client VLANs come later.
Fast preflight before connection
- Check the exact AP6 model against the overview of current AP6 models. The old AP series is lifecycle context, not a basis for a new installation.
- Size the PoE standard, per-port power, and total PoE budget from the model table below. Passive PoE injectors aren’t supported.
- Make the management VLAN untagged on the switch port; permit later client VLANs as tagged VLANs on the trunk.
- Provide IPv4 DHCP, DNS, and a working default gateway in the untagged management network.
- Allow the current Sophos Fusion destinations, ensure NTP can be resolved and reached, and remove any HTTPS proxy from the path.
- For an AP6, power on the device, wait for any initial update to finish, and register it only once its status remains solid green. For AP6, the registration window is 24 hours after power-on.
Passing these checks does not prove that the subsequent SSID or VLAN design is correct. It only establishes the reliable management path that Sophos Fusion needs to reach the device initially.
Before allowing a security integration to isolate devices automatically, validate the AP6 Active Threat Response runbook with a controlled pilot device.
Current AP6 models
Sophos Wireless managed through Sophos Fusion supports these dedicated models for a current AP6 deployment:
The AP6 420, AP6 840, and AP6 420X are dual-band, dual-radio models; the AP6 420E and AP6 840E are tri-band, tri-radio models.
| Model | Standard and bands | Max. clients per radio | FCC channels | ETSI channels |
|---|---|---|---|---|
| AP6 420 | 802.11ax, 2.4/5 GHz | 128 | 2.4 GHz: 1–11; 5 GHz: 36–64, 100–144, 149–165 | 2.4 GHz: 1–13; 5 GHz: 36–64, 100–140 |
| AP6 420E | 802.11ax, 2.4/5/6 GHz | 128 | as AP6 420; 6 GHz: 1–233 | as AP6 420; 6 GHz: 1–93 |
| AP6 840 | 802.11ax, 2.4/5 GHz | 512 | 2.4 GHz: 1–11; 5 GHz: 36–64, 100–144, 149–165 | 2.4 GHz: 1–13; 5 GHz: 36–64, 100–140 |
| AP6 840E | 802.11ax, 2.4/5/6 GHz | 512 | as AP6 840; 6 GHz: 1–233 | as AP6 840; 6 GHz: 1–93 |
| AP6 420X (outdoor) | 802.11ax, 2.4/5 GHz | 128 | 2.4 GHz: 1–11; 5 GHz: 36–64, 100–144, 149–165 | 2.4 GHz: 1–13; 5 GHz: 36–64, 100–140 |
The mesh-network band is still listed as TBD for all five AP6 models, so don’t plan on it as a committed capability. The client count is a documented maximum per radio, not a design target. Country, regulatory domain, indoor or outdoor use, channel width, and Sophos Fusion configuration determine which channels are actually selectable. For outdoor deployments in particular, do not treat the table as authorization to use every listed channel.
The former Sophos AP series—AP15/AP15c, AP55/AP55c, and AP100/AP100c/AP100x—is absent from the current support matrix. For existing devices, check both the current matrix and the internal lifecycle status.
AP6 can be managed locally or through Sophos Fusion. Manage AP6 locally or with Sophos Fusion explains this choice and the other management boundaries. For Sophos Fusion management, the UI path is My Products > Wireless. This article deliberately focuses on the network and hardware preflight.
Keep the licensing boundary precise
Each AP6 managed through Sophos Fusion needs the matching quantity of Sophos AP6 Support and Services. Sophos Fusion shows a Wireless warning for missing or insufficient quantities, and APs can’t be changed through Sophos Fusion without a valid license. Sophos doesn’t require it for AP6 units not managed through Sophos Fusion.
It is not guaranteed that an AP6 managed through Sophos Fusion automatically switches to standalone mode when the license expires, is guaranteed to continue passing traffic, or transfers its Sophos Fusion configuration to the local interface. Do not plan on any of these outcomes. Decide on the management method before commissioning the AP.
Plan PoE per AP6 model
| Model | Documented AP load | Minimum AP standard |
|---|---|---|
| AP6 420 | 17 W | 802.3at |
| AP6 420E | 21 W | 802.3at |
| AP6 420X | 21 W | 802.3at |
| AP6 840 | 25.5 W | 802.3at |
| AP6 840E | 40 W | 802.3bt |
For the AP6 840E, the 40 W AP load may initially appear to conflict with the required 60 W PoE++ source. The figures describe different things: 40 W is the documented AP load, whereas 60 W is the power class of the 802.3bt source. Plan for a 60-W-capable PoE++ port or injector rather than a source limited to 40 W.
AP6 negotiates power with the Power Sourcing Equipment (PSE) over LLDP-MED. Passive PoE is not supported. If the available power is insufficient, the AP disables all radios and displays a warning in the user interface. A working link or management access alone therefore does not prove that the wireless service is operational. If you change the PSE configuration after the AP has started, restart the AP for the new power setting to take effect.
The switch must also have enough total PoE budget for all connected devices. A port with a suitable nominal rating will not help if the switch’s overall budget is exhausted.
Prepare the switch port and bootstrap network
The AP always communicates with Sophos Fusion over an untagged VLAN. The native or management VLAN must therefore be untagged on the wired switch, while VLANs for subsequent wireless clients are permitted as tagged VLANs on the trunk. If the management path is available only as a tagged VLAN, an unconfigured AP cannot make its initial connection to Sophos Fusion.
The AP needs DHCP and DNS for IPv4 on the management network. Once DHCP succeeds, it attempts to reach Sophos Fusion through its default gateway. The default address of an AP6 is 192.168.2.2. This address is a diagnostic clue, not a substitute for a production DHCP, DNS, and gateway path.
Sophos Fusion destinations, NTP, and proxy
If your firewall or proxy supports wildcards, use the following current allowlist:
central.sophos.com*.sophos.pool.ntp.orgsophos.jfrog.iojfrog-prod-use1-shared-virginia-main.s3.amazonaws.comwifix-*.cloudstation.*.sophos.com
If wildcards are unavailable, first use the account name and Support settings in Sophos Fusion to identify the region shown under This account is located in. Its value for <MCS_URL> is:
| Sophos Fusion region | <MCS_URL> |
|---|---|
| United States (Oregon) | us-west-2.prod.hydra.sophos.com |
| United States (Ohio) | us-east-2.prod.hydra.sophos.com |
| Ireland | eu-west-1.prod.hydra.sophos.com |
| Germany | eu-central-1.prod.hydra.sophos.com |
| Canada | stn100yul.ctr.sophos.com |
| Australia | stn100syd.ctr.sophos.com |
| Asia Pacific (Tokyo) | stn100hnd.ctr.sophos.com |
| South America (Sao Paulo) | stn100gru.ctr.sophos.com |
| India | stn100bom.ctr.sophos.com |
Then allow exactly these destinations, replacing the placeholder with the table value:
central.sophos.com0.sophos.pool.ntp.orgjfrog-prod-use1-shared-virginia-main.s3.amazonaws.comsophos.jfrog.iowifix-proxy.cloudstation.<MCS_URL>wifix-push-ws.cloudstation.<MCS_URL>
Together these destinations provide Sophos Fusion communication, time synchronization, firmware or artifact delivery, and wireless-event logging. Allowing only central.sophos.com isn’t sufficient. DNS must resolve every name, and NTP must be reachable so that the AP can update its clock. Validate the rules with DNS tests and the firewall’s connection and deny logs. If the firewall can represent neither wildcards nor regional FQDN destinations safely, agree on the allowlisting method with the responsible network team before commissioning. Recheck the mapping and rules if the account’s region changes.
There must be no HTTPS proxy in the communication path. 22/TCP is not a general onboarding requirement: Sophos requires outbound SSH on this port only for Remote Support. Open it only for that specific support scenario and after approval under your own security policy.
Recognize successful startup and registration
After power-on, the AP obtains an address and establishes its network connection. On AP6, a solid green status is the success criterion for established network connectivity and management readiness. The first contact with Sophos Fusion may trigger a firmware update that takes up to 15 minutes. While the LEDs are flashing rapidly, do not disconnect power, restart, or reset the device.
Register AP6 within 24 hours of power-on. If the window has expired, Sophos requires a hard reboot or reboot from the local web interface before another registration attempt. A factory reset isn’t the first step.
Before registration, note the serial number and match it against the device or box. The Sophos access point onboarding wizard covers the subsequent registration procedure.
Troubleshoot by symptom
AP6 at the default address 192.168.2.2
First check the untagged management VLAN, DHCP scope, and physical switch port. Then verify that the lease, DNS server, and default gateway are supplied on the correct network. Client VLANs and Sophos Fusion registration are not yet the cause at this stage.
AP reachable, but radios off or a power warning appears
Compare the port and total PoE budget with the table and replace passive PoE. After changing the PSE, restart the AP and verify that the warning clears and radios return.
If underpower is suspected and the UI is unavailable, connect a console cable to AP6 and run the read-only poestat command in the local AP6 console. Sufficient power produces a suitable PoE class and available-power value, for example PoE state = IEEE802.3bt Type 3: Power Class Level 1~6 51W available. An underpowered result ends with WARNING: Insufficient power. Model, negotiated class, and wattage can differ; what matters is that no insufficient-power warning appears and the class meets the model table.
AP starts but doesn’t register in Sophos Fusion
Test DNS resolution and access to every allowlist destination, rule out an HTTPS proxy, and verify the correct Sophos Fusion region. If the AP remains solid green but contact with Sophos Fusion still fails, investigate the internet path rather than the power supply. For an AP6, if more than 24 hours have passed, perform the documented restart before registering again.
LED flashes rapidly
This indicates an AP6 firmware update. Wait up to 15 minutes without interrupting power. If it doesn’t reach solid green afterwards, record time, model, switch port, DHCP lease, and allowed destinations for escalation. Open 22/TCP only when remote support is actually arranged.