Skip to content
Avanet

Sophos Fusion Wireless: Plan AP6 Sites, Floorplans, and Regions

A site assigns AP6 access points in Sophos Fusion (formerly Sophos Central) to a real geographic location. It is more than a label: Sophos Fusion limits the available frequency bands according to the site’s country, and an AP6 can only be assigned to a site within its SKU region. A floorplan adds a scaled plan and AP positions to that site. The displayed wireless coverage remains an estimate and must be measured on location.

Quick workflow: Verify the SKU region and real address, create a pilot site under My Products > Wireless > Sites, assign only a few AP6 units initially, upload and scale the plan, position the APs, and save. Then verify both the Sophos Fusion status and the real wireless data path with a test client. A professional site survey is recommended before rolling out additional APs or adding further floors.

⚠️ Do not guess the location: The address must be correct before selecting Accept & continue. An incorrect location may prevent 5 GHz and 6 GHz from working and prevent APs from being added to the site.

Separate Sophos Fusion Metadata from the Wireless Data Path

The site name, address, country, AP assignment, floorplan, scale, and AP symbols are managed in Sophos Fusion. They help with inventory, regulatory assignment, and visualization. Client traffic, however, runs from the endpoint through the AP6, switch port or VLAN, and gateway. A correct-looking floorplan therefore proves neither reception nor DHCP, DNS, routing, or internet access.

The coverage graphic is not a measurement either. Walls, ceilings, shelving, antenna orientation, interference, channel planning, and client capabilities change the real cell. Floorplan coverage is therefore only an estimate; a professional site survey is recommended. For channel width, transmit power, and roaming, continue with the separate AP6 RF and roaming guide.

Check the Region and SKU Before Site Assignment

The AP6 SKU defines a region. For example, an AP6 from the US region can’t be assigned to a site in an EU region. Before ordering, and again before site assignment, compare the exact model-variant SKU with the actual installation country in the AP6 model selection guide. It combines models, radio bands, and the six procurement regions AU, CA, EU, IN, ROW, and US into one decision path; the product name, store listing, and shipping destination aren’t enough.

Record the following first:

  • the complete real address and expected country;
  • model, serial number, and SKU of every AP6;
  • previous site assignment and currently usable radio bands;
  • affected SSIDs, switch ports, and a suitable pilot client;
  • one AP6 as the pilot rather than changing the entire location at once.

A site can manage multiple APs, but an access point can belong to only one site at a time. The AP6 model selection guide explains models, bands, and regional limits before ordering.

Create the Site and Assign AP6 Units Carefully

  1. In Sophos Fusion, open My Products > Wireless > Sites and select Create.
  2. Enter a clear name, such as ZRH-HQ. The name is freely selectable; the address and country must match the actual installation location.
  3. Enter the real address under Location. Sophos Fusion uses Google Maps and applies the country automatically from the location.
  4. Read the User Acceptance Notice, check the country and map position again, and only then select Accept & continue.
  5. Initially select only the pilot AP6. If its SKU region doesn’t match the site, don’t bypass the check with another address; verify the SKU and country assignment in the AP6 model selection guide.
  6. Select Save. For later assignment changes, edit the site, select Next in the Create or update a site window to reach AP selection, and save again.

Registration itself still takes place under My Products > Wireless > Access Points. The AP6 onboarding guide covers registration, licensing, and configuration status.

Upload and Scale a Floorplan, Then Place APs

The Sophos Fusion account needs the Admin or Super Admin role to upload a plan. Supported formats are PNG, JPEG, BMP, GIF, WBMP, and PDF. Use a current, readable plan without unnecessary confidential information.

  1. Open the site under My Products > Wireless > Sites and select Create a floor.
  2. Use Choose a file to select the plan, then select Upload.
  3. Adjust the image boundaries and select Crop image, or continue unchanged with Proceed without changes.
  4. Select Edit, place two pins at points with a known distance, enter the distance in meters, and confirm with the check mark. Without measured dimensions, Sophos Fusion can’t show AP range correctly.
  5. Drag an available AP6 from the available tab to its real position. For planning only, Simulated AP can show estimated coverage when no AP is available yet.
  6. Select Save. To change the scale later, use Edit > Change scale; AP symbols can be removed from the plan on the placed tab.

Placing a symbol documents the mounting position; it doesn’t move a physical AP or repair a coverage gap. Also document room labels, floor, plan revision, and the two reference points outside Sophos Fusion so that later plan changes remain traceable.

Discover and Classify Neighborhood Networks

The site’s Neighborhood networks tab shows wireless networks detected within range of its AP6 units, including networks that this Sophos Fusion account doesn’t manage. The list is RF monitoring and classification telemetry: it includes SSID, BSSID, channel, band, RSSI, First seen, and Last seen. It doesn’t redirect client traffic, and a classification doesn’t block or isolate another wireless network. The client data path remains separate.

An AP6 scans once for neighborhood SSIDs at startup, such as after a restart or firmware update. It scans regularly when dynamic background channel selection is enabled. To refresh the results on demand:

  1. In Sophos Fusion, open My Products > Wireless > Sites, select the site, and open the Neighborhood networks tab.
  2. Record timestamps and notable entries first, then choose a maintenance period.

⚠️ Plan for client interruption: Manually selecting Scan interrupts the network connection of connected devices for three to five minutes. Notify affected users and don’t start the scan during a critical session.

  1. Select Scan. Scanning and automatic classification run on the individual AP6 units; Sophos Fusion then shows the state from each unit’s most recent scan.
  2. Review SSID or BSSID, channel, band, RSSI, First seen, and Last seen. Available filters include All, Rogue, Trusted, Untrusted, Advanced Impersonate, Evil Twin, BSSID Impersonate, SSID Impersonate, and Adhoc.
  3. Verify an entry against your own inventory, cabling, and location records before deciding. Then select it, choose Select classification, and apply a custom classification if required.
  4. To reverse a manual choice, select the entry and choose Clear Custom Classification. This removes only the custom classification, not the detected network.

Treat classifications as investigation signals. You must manually set Trusted for a verified network belonging to your Sophos Fusion account. Untrusted identifies an external network that usually isn’t malicious but may cause interference. Rogue identifies an untrusted network connected to the secured wired AP network. SSID Impersonate and BSSID Impersonate indicate a copied SSID and AP hardware address respectively. Evil Twin indicates a copied network name and hardware address; Advanced Impersonate indicates a copied network name and unique protection code. Adhoc identifies a peer-to-peer network.

Automatic classification requires context: two AP6 units at the same site broadcasting the same SSID can identify each other as SSID Impersonate, although clients can still connect and roam. After matching the BSSID, AP inventory, and location, manually mark such verified internal entries as Trusted. A warning class alone is neither proof of an attack nor a containment action.

Validation and safe stop: After a manual scan, allow the three-to-five-minute window to pass, then check that Last seen and the expected AP6 results are current. Test client association, IP configuration, DNS, and permitted destinations afterward. If new values don’t appear, first check AP6 online state, the selected site, and the latest scan time; don’t create more interruptions with repeated scans. If client behavior is unexpected, make no further RF or site change: stop the rollout and check the data path separately. Reverse an incorrect manual label with Clear Custom Classification. Start a scan only when the entire interruption window has been approved.

Validate the Site, Floorplan, and Data Path

After saving, check in this order:

  1. Region: Site address, automatically applied country, and SKU region match the real installation location.
  2. Assignment: The pilot AP6 appears only in the intended site. The site’s Access points tab shows details including name, connected devices, workload, and Config status.
  3. Floorplan: The correct floor and plan revision, a plausible scale, and the real AP position are visible.
  4. Management: The AP6 remains online and Config status shows no unexpected error after a reasonable wait.
  5. Radio: A walk test records at least RSSI/SNR, band, channel, and transitions at documented points. Don’t treat the colored estimate as measured data.
  6. Data path: The test client joins the intended SSID, receives the expected IP configuration, and can reach DNS plus permitted internal and external destinations.

Assign the next AP group only when management state, measurements, and client testing agree.

Troubleshoot by Symptom

The AP6 Can’t Be Added to the Site

Check the real site address and automatically determined country first, then compare the SKU and country with the AP6 model selection guide. Also check whether the AP is already assigned to another site, because an AP can belong to only one site. Never use a fictitious address to bypass the regional check.

5 GHz or 6 GHz Is Missing After Location Selection

This can be consistent with an incorrect site location or regional requirements. Check the site country, AP6 SKU, model, and client capability separately. Don’t change radio parameters broadly before resolving the regulatory assignment.

Upload or Floorplan Editing Fails

Check for an Admin or Super Admin role, a supported file format, and a readable source file, then upload again. If the range looks wrong, correct the scale and reference distance first; adding simulated APs doesn’t fix a scale error.

Sophos Fusion Is Green, but the Client Connection Is Poor

There is no contradiction: Sophos Fusion confirms management state, not the quality of the whole data path. Check the physical AP position, survey measurements, channel utilization, switch/VLAN, DHCP, DNS, and gateway in sequence. The floorplan estimate remains guidance only.

Roll Back Conservatively

Before making changes, record the site assignment, address/country, floorplan file, scale, AP positions, and client baseline. If a problem occurs, stop the rollout and revert only the last changed layer:

  • Display only is wrong: Correct the documented scale or AP symbol position and save again. This isn’t an RF repair.
  • Wrong AP assignment: In a maintenance window, assign the pilot back to the previously documented, geographically correct site, save, and repeat management and client tests.
  • Location data is wrong: Correct it to the real address. Don’t restore a known-incorrect previous location merely to make a band available.

Don’t delete a site or floorplan as a supposed quick rollback: the effects on assignments and stored floorplan data aren’t predictable enough for that. If the previous state wasn’t recorded clearly, pause changes, capture screenshots, timestamps, SKU, site country, and Config status, and escalate to Sophos Support with this evidence.