Skip to content
Avanet

Sophos AP6: Plan RF channels, band steering, and roaming

A good AP6 wireless network isn’t created by maximum transmit power or the widest channel option. Neighboring cells need enough overlap for roaming, but shouldn’t overlap unnecessarily or use the same or adjacent channels. Band steering and roaming aids can support a sound RF design, but can’t replace one.

Quick plan: Measure the current environment with a site survey, define channel plan, channel width, and transmit power per band, ensure identical SSID and security settings on participating AP6 units, and change only a small AP pilot. Walk the same route with several client types. Continue with the next wave only when measurements and applications are stable.

Separate the management plane from the RF and data path

An AP6 can be managed locally or with Sophos Fusion (formerly Sophos Central). The management plane carries settings and status. The RF and data path instead runs from the client through the AP6, switch or VLAN, and gateway. A green Central status proves neither good RF coverage nor working DHCP, DNS, or routing.

Roaming is client-led: The endpoint decides when to leave its current AP and which candidate to select. Sophos identifies approximately -70 dBm as a common starting point, but explicitly says thresholds vary by client. Central therefore isn’t a universal roaming requirement. Equally configured, locally managed AP6 units can also form a roaming design; Central merely makes consistent settings, assignments, and visibility easier.

SSID, encryption, authentication, and client network must match across participating AP6 units. The AP6 SSID and VLAN design guide explains the data path. Changing RF AP must not unexpectedly change VLAN, gateway, or security profile at the same time.

Capture a defensible baseline before changing anything

  1. Map areas and applications: Mark desks, meeting rooms, voice, scanners, IoT, outdoor areas, and expected movement.
  2. Inventory clients: Check supported bands, channel widths, and 802.11k/802.11r support for at least business-critical device types. 6 GHz requires a suitable AP6 model, permitted region, and capable clients.
  3. Record current state: For each AP and band, record channel, width, TX Power, Autochannel settings, SSID assignments, band steering, fast roaming, 802.11k, and Smart Handover threshold.
  4. Measure: Capture channel use, interference sources, RSSI, and SNR at representative points and planned walking routes. Sophos recommends SNR at least 25 dB above the noise floor; this is a planning value, not a performance guarantee.
  5. Set acceptance criteria: Define acceptable latency, packet loss, interruption of the real voice or video application, DHCP/DNS behavior, and intended destination access.

A pre-deployment survey estimates placement and channels. Only a post-deployment survey measures actual signal strength and SNR. Repeat it later because new neighboring networks and interference sources change the result.

Plan channels, width, and power together

Keep 2.4 GHz deliberately narrow

For 2.4 GHz, Sophos recommends 20 MHz and identifies 1, 6, and 11 as the three non-overlapping channels. Although 40 MHz is supported, Sophos doesn’t recommend it because the entire band is only 72 MHz wide and overlap is very likely. In a capacity design, turning off 2.4 GHz radios on selected AP6 units may be better than transmitting every band in every cell. Do this only after measuring coverage and testing 2.4-GHz-only clients.

Choose 5 GHz width and DFS for the environment

5 GHz provides more channels and a useful balance between range and throughput. Sophos suggests 40 or 80 MHz, but 20 MHz in highly congested environments or where AP6 units are close together. Wider channels increase a single client’s potential data rate but reduce the number of non-overlapping channels. In dense deployments, additional channel reuse is often more useful than a large nominal width.

DFS channels 52 through 144 share spectrum with radar systems. Radar detection can trigger a channel change and client disconnections. Disabling DFS, however, shrinks the available channel pool. Make this a pilot decision: measure regional availability, local radar events, client compatibility, and required reuse rather than always enabling or disabling DFS.

Don’t treat 6 GHz as a range replacement

6 GHz provides many non-overlapping channels and doesn’t require DFS, but has shorter range. Sophos suggests 80 or 160 MHz for high-performance applications. This isn’t a universal starting point for dense networks: AP model, region, client population, cell spacing, and measured occupancy decide. Clients without 6-GHz support still need suitable 5- or 2.4-GHz coverage.

TX Power shapes the cell

100% is the documented Central default, but isn’t automatically the right production setting. Lower TX Power reduces operating distance and can reduce interference. Set transmit power per band and location so that a client at the cell edge can still see a usable next AP. Increasing AP power alone also can’t fix the weak return path of a lower-power client.

Sophos provides -67 dBm for voice, -72 dBm for data, approximately 15–20% cell overlap, and a 10–15 dB advantage for the next AP as design guidance. Treat these as measurement points, not guarantees: antennas, walls, client drivers, and applications change the outcome.

Choose Autochannel or a fixed channel plan

Autochannel evaluates factors including total received signal strength, noise floor, channel load, power limitations, and visible BSS count. In Central, AP6 scans at startup and every 30 minutes by default. While clients are connected, it doesn’t move to a better channel unless Shift to a better channel even if clients are connected is turned on.

For a controlled, surveyed site, we prefer a documented fixed channel plan. Sophos’s channel guide also recommends avoiding automatic selection to reduce possible conflicts. Autochannel can still suit small or changing sites when its allowed range is deliberately constrained and its behavior is monitored.

⚠️ Plan an interruption: A forced channel change while clients are connected may disconnect them. Pilot the shift option only in a maintenance window. Save on the Central AP details page also updates the AP immediately and can cause brief downtime.

Use the local AP6 UI and Central without mixing fields

The interfaces group settings differently. Don’t transpose field names from one path to the other.

Locally managed AP6

In the local AP6 UI, radio basics for each band are under Wireless > Wireless settings > 2.4 GHz, 5 GHz, or 6 GHz > Basic settings. Each band supports up to 16 SSIDs, and SSID names can contain up to 32 letters or numbers. The pages contain Wireless, Band, SSID/VLAN fields, Auto channel, band-dependent Auto channel range, Auto channel interval, the option to change channel with clients connected, Channel, and Channel Bandwidth. Available channel and channel-width options depend on the band.

Each band’s Advanced settings page includes Tx power, Guard Interval, DTIM, RTS, Beacon Interval, Idle timeout, Beamforming/MU-MIMO, and Airtime Fairness. Only 2.4 GHz also provides Contention, Preamble, and 802.11g Protection. Sophos labels these settings for experienced users and warns that changes can hurt performance. Documented ranges and defaults depend on the band, so record each band’s baseline separately before making changes and don’t copy values blindly between bands. For RF tuning, start with channel, width, and TX power only; leave protocol timers at the recorded baseline unless a measured problem justifies changing them.

Bandsteering is a separate wireless setting in the local UI. Its modes are Off, 6G first, 5G first, Balanced, and User-defined. User-defined mode sets overload thresholds per band, with a documented default of 70, and Min RSSI; eligible 5-/6-GHz clients below the RSSI value are directed toward 2.4 GHz. Bandsteering and MAC address filtering can’t be enabled simultaneously.

Smart handover is configured locally per frequency band. Its documented default is -80 dBm. Below the configured threshold, the AP disconnects a client so it searches for another AP. Turn this on only after a survey: a threshold set too high disconnects devices before a suitable candidate is available.

Central-managed AP6

In Central, go to My Products > Wireless > Access Points, click the pilot AP, and edit every available band separately under Settings > Radio configuration. The documented fields are TX Power, Channel width, Autochannel, Range, Auto channel scan interval, and Shift to a better channel even if clients are connected. With Autochannel off, select the channel manually.

SSID roaming aids aren’t on that radio page. Go to My Products > Wireless > SSIDs, click the SSID, then Advanced Settings > Quality of service. This section contains Fast roaming, Band steering, and, for AP6, 802.11k. Central documentation says band steering operates per access point and affects all SSIDs on that AP. Consider every SSID on the pilot AP before enabling it.

Sophos says 802.11k supplies neighbor information and is on by default for all SSIDs; not every client supports it. Fast roaming uses 802.11r in suitable configurations, requires client support, and isn’t available for a guest network in NAT mode. Enable Fast Transition only when every access point serving the SSID in the deployment is AP6. Its benefit is minimal without enterprise authentication. If the SSID extends outside a controlled area, Fast Transition can create a security exposure; assess that risk before enabling it. These features assist the client’s decision but don’t force a specific destination AP.

Pilot in stages and validate with a walk test

  1. Limit the pilot: Select two neighboring AP6 units and one representative SSID. Export or clearly record baseline values and AP assignments.
  2. Change one variable class: First channel plan, then width, then power. Test band steering, fast roaming, or Smart Handover separately afterward.
  3. Wait for configuration state: In Central, check AP status and Task queue. An accepted management task isn’t yet an RF success.
  4. Check stationary points: Record RSSI, SNR, band, channel, data rate, latency, and packet loss at the same points before and after.
  5. Walk the same route: Use a continuous ping and, more importantly, the business voice or video application. Record time, source AP, target AP, transition point, interruption, and reconnection.
  6. Test client diversity: Use at least two relevant client types, including a device without or with problematic 802.11r support when fast roaming is planned.
  7. Confirm the data path: After each transition, check IP address, gateway, DNS, and allowed destinations. A DHCP renewal or network change can look like an RF roaming fault.
  8. Include load: Repeat at a representative busy time. An empty site doesn’t prove stability under channel utilization.
  9. Roll out in small waves: Change the next AP group only after acceptance criteria pass, then repeat the same short test after every wave.

Troubleshoot by symptom

Client stays on a distant AP: First verify that a next AP with the same SSID, security, and client network is visible. Measure both APs’ RSSI and separation. Excessive overlap, high TX Power, or client roaming logic may be involved. Don’t immediately make Smart Handover more aggressive.

Client disconnects but finds no replacement: Coverage at the transition is probably too small or the Smart Handover threshold too high. Restore the recorded threshold, measure the cell edge, and only then correct placement or TX Power.

Throughput is poor despite strong signal: Check band, channel width, occupancy, SNR, and co-/adjacent-channel interference. A wide channel or too many 2.4-GHz cells can provide less usable airtime despite strong RSSI.

Dropouts occur periodically: Compare timestamps with Autochannel interval, configuration tasks, and DFS events. If forced shifting with connected clients is active, disable it in the pilot and repeat the same route.

Only older clients fail: Check 802.11r, 802.11k, encryption, and band support for that exact device. Remove fast roaming from the pilot first; incompatible devices may need a separate SSID rather than global weakening.

RF transition succeeds but the application still breaks: Trace IP, VLAN, gateway, DNS, firewall state, and application session. This isn’t automatically an RF fault. Prove management, RF transition, and data path separately.

Roll back safely

Rollback isn’t a factory reset. Stop rollout and restore the recorded channel or Autochannel, channel width, TX Power, and SSID roaming options on pilot APs. Revert only the last variable class, wait for configuration status, and repeat the same stationary and walking tests.

In Central, Save can cause another brief interruption. Locally, check each AP so no divergent setting remains. Rollback is complete only when the existing SSID, DHCP, DNS, applications, and previous route reproduce baseline behavior. If neither RF measurements nor the data path explain the fault, preserve pilot values, timestamps, client model, and firmware versions and escalate with that evidence.