Skip to content
Avanet

Set up and test Sophos Firewall Wireless Mesh

A Wireless Mesh on Sophos Firewall connects one or more APX Access Points wirelessly to a wired root AP. It can bridge a coverage gap where no Ethernet cabling is available at the remote location. The mesh backhaul isn’t the visible wireless SSID: SFOS creates a hidden WPA2-Personal network for it with a random passphrase. Clients continue to use a separately configured Wireless Network.

⚠️ Important: This guide applies to existing APX installations managed directly by SFOS. APX can only form a mesh with APX. AP6, integrated LocalWiFi, SD-RED Wi-Fi modules, and mixed Sophos AP series aren’t part of this workflow. A mesh also isn’t a substitute for wired redundancy: At least one AP remains connected by LAN, and SFOS doesn’t perform an automatic root change if the root AP fails.

Quick workflow:

  1. First connect both APX devices by LAN, accept them under Wireless > Access points, and check firmware, Country, and the radio plan.
  2. Set the same fixed channel on all participating APs for the mesh band and turn off Dyn chan.
  3. Configure the mesh ID, Frequency band, and APX devices under Wireless > Mesh networks > Add.
  4. Assign the visible client SSID separately to both APX devices.
  5. Save the configuration, restart the APX devices, leave only the root AP wired, and wait up to five minutes.
  6. Check AP status, client connectivity, DHCP, Rule ID, internet access, and the failure of the root path in a controlled test.

When an APX mesh is suitable

A mesh is suitable for an existing APX installation when one remote access point has no Ethernet connection and the radio link to the root AP is stable enough. Typical examples include a small warehouse area, a meeting room, or a temporary area where cabling is planned later.

An Ethernet uplink remains the better technical foundation for sustained high capacity, stable latency, and predictable failover. The mesh backhaul shares radio airtime with other transmissions. Real performance should therefore be measured with the intended clients and applications rather than inferred from link status.

The product boundary also matters for new installations: APX is End-of-Sale and reaches End-of-Life on December 31, 2027. The APX lifecycle and AP6 as its successor should therefore be included in medium-term planning. AP6 isn’t managed through SFOS.

Understand the mesh backhaul, client SSID, and roles

These components serve different purposes:

  • Mesh network: Hidden radio backhaul between the APX devices. The mesh ID identifies the group; SFOS manages the random WPA2 passphrase.
  • Root AP: APX with an existing Ethernet connection to the firewall. For APX, this role follows automatically from the cabling.
  • Mesh AP: APX without an Ethernet uplink that reaches the root AP by radio.
  • Wireless Network: Visible client SSID with Security mode, Client traffic, DHCP, and rules. The complete foundation is covered in Set up wireless directly on Sophos Firewall.

With older Sophos AP series, root and mesh roles must be assigned explicitly. This article uses APX only and therefore doesn’t transfer that legacy role screen to the example steps.

Repeater or wireless bridge

In repeater operation, the mesh AP broadcasts the assigned client SSID at the remote location. Endpoints connect over Wi-Fi; the AP transports their traffic over the mesh backhaul to the root AP.

With a wireless bridge, an Ethernet segment is additionally connected to the network port of the mesh AP. This design extends Layer 2 and can create loops if a second cable path exists at the same time. It therefore belongs in a maintenance window with a documented recovery path. STP must match the overall switch and bridge design; it isn’t disabled merely because a path is blocked.

Repeater operation is clearer for most small extensions. A bridge should only be used when the remote Ethernet segment is genuinely required and its broadcast, VLAN, and loop behavior is understood.

Check the limits before configuration

An APX mesh has clear product limits:

  • All participating access points must belong to the APX series.
  • Only one mesh network can be used per AP.
  • At least one APX must remain connected to the firewall by LAN.
  • All mesh APs use the same channel on the mesh band.
  • Dynamic Channel Selection, or Dyn chan, must not be active on this band because APs may otherwise use different channels after a restart.
  • On APX, both radios must not be configured for 5 GHz at the same time when mesh is used.
  • APs with an assigned VLAN can only form a mesh if the VLANs don’t use the Bridge to VLAN Client traffic mode.
  • A second mesh network on the same AP doesn’t work.
  • Failure of the root AP isn’t taken over automatically and without interruption by another mesh AP.

The current Sophos help describes 2.4 GHz for the mesh backhaul and 5 GHz for client SSIDs as a possible starting point. This isn’t a universal best practice. Distance, walls, interference, available channels, the regulatory Country, and required capacity determine the actual design.

Plan the example topology

The example uses these names:

  • Firewall: fw01
  • wired APX: ap-office-root
  • wireless APX: ap-warehouse-mesh
  • Mesh ID: OfficeMesh
  • visible Wireless Network: Company WiFi
  • Mesh band: 2.4 GHz
  • Mesh channel: a fixed channel tested at the site

OfficeMesh is a documentation example and is replaced with a short, unique name for the local installation. The mesh ID must not be confused with the visible SSID. In the example, Company WiFi already exists with suitable Client traffic, DHCP, firewall rules, and NAT.

Before the change, prepare a current configuration backup, wired management access, and a rollback plan. Both APX devices receive PoE and are tested within range of their final positions for initial configuration. The root AP must remain reachable there by Ethernet.

Prepare the access points and radio channel

Provision both APX devices by LAN first

  1. Connect ap-office-root and ap-warehouse-mesh by Ethernet to the intended management network.
  2. Under Wireless > Wireless settings, check that Wireless Protection is active and that the management zone is allowed under Allowed zone.
  3. Under Wireless > Access points, accept both pending APX devices with Accept.
  4. Set the correct Country for both APX devices. After a Country change, save and restart the APX devices in a controlled manner so the channel list is updated.
  5. Check that both APX devices are active and have received their current configuration.

The initial wired connection isn’t an optional convenience. An APX that hasn’t received the mesh configuration can’t later be added to the group over radio alone.

Before rollout, the APX firmware level should also be planned through the Sophos Firewall pattern updates. A firmware update and the mesh cutover shouldn’t take place at the same time without control.

Set one common fixed channel

  1. Under Wireless > Access points, open the first APX.
  2. Under Advanced settings, set a fixed, locally tested channel for the selected mesh band.
  3. Turn off Dyn chan for this band.
  4. Apply the same setting to the second APX.
  5. Where possible, place nearby APs that aren’t part of the mesh on a different low-interference channel.

A channel isn’t selected merely because it works well in the example. A local scan, Country requirements, and neighboring channel use determine the choice. After every channel change, both mesh APs must show the same value again.

Create the Wireless Mesh in SFOS

Create the mesh network

  1. Open Wireless > Mesh networks.
  2. Select Add.
  3. Enter OfficeMesh as the Mesh-ID.
  4. Under Frequency band, select the planned common band, 2.4 GHz in the example.
  5. Add ap-office-root and ap-warehouse-mesh.
  6. Save.

With APX, no role needs to be assigned manually in this workflow. While both APX devices are still wired, they first receive the configuration. After ap-warehouse-mesh is disconnected later, ap-office-root remains the root AP because of its Ethernet connection.

Assign the visible client SSID

The mesh network isn’t visible to endpoints. Under Wireless > Access points, or through a suitable access point group, assign Company WiFi to both APX devices as well.

The client SSID retains its own Security mode and Client traffic. For Separate zone, the Wireless interface, DHCP, firewall rule, NAT, and Device Access must be correct in particular. A working mesh doesn’t correct a missing wireless rule or an incorrect DHCP path.

Move the mesh AP to its destination

  1. Check that the configuration and visible client SSID have reached both APX devices.
  2. Restart both APX devices in a controlled manner.
  3. Remove the Ethernet cable only from ap-warehouse-mesh.
  4. Leave ap-office-root wired.
  5. Place the mesh AP at the intended location and turn it on.
  6. Wait up to five minutes before treating the connection as failed.

Only one APX remains connected by LAN during normal mesh operation. If the second APX is accidentally connected to the same Layer 2 network as well, check the design for loops and the effect of STP.

Validate the Wireless Mesh in a controlled manner

Validation combines controller status, the radio path, and real user traffic:

  1. Under Wireless > Access points, both APX devices must be active. ap-office-root remains wired; ap-warehouse-mesh is reachable without Ethernet.
  2. Check the mesh assignment and identical channel on both APX devices.
  3. Connect a test client near ap-warehouse-mesh to Company WiFi.
  4. Under Wireless > Wireless client list, check that the client is associated with the expected mesh AP.
  5. Compare the client’s IP address, gateway, and DNS with the planned Wireless Network.
  6. Test one allowed destination and one deliberately blocked destination.
  7. In Log Viewer, filter by the client IP and check the expected Firewall Rule ID and NAT Rule ID.
  8. Run a realistic throughput and latency test and compare it with a client at the root AP.

A green AP status doesn’t yet confirm the complete data path. Success means the client uses the correct AP, address, and intended rules, and that performance is sufficient for the application. The general procedure is described in Test firewall rules reliably.

Test the failure boundary deliberately

The root AP is a known dependency. During a maintenance window, briefly disconnect the root uplink and document how long client access is interrupted. SFOS doesn’t promise an automatic root change. A mesh AP may need to be restarted and wired for a new role to be established.

This test isn’t a reason to turn off a production root AP without planning. For critical areas, use a wired AP uplink or plan another wireless architecture.

Troubleshoot by symptom

Mesh AP doesn’t appear or remains offline

After configuration, wait up to five minutes. If the AP remains offline, first check whether it was active during initial provisioning by LAN and received the mesh configuration. Then check the APX series, mesh assignment, band, common channel, Dyn chan, Country, and power supply.

The root AP must remain wired. If both APs are wireless or the wrong AP was disconnected from Ethernet, the path to the firewall is missing. After a correction, restart the APX devices in a controlled manner and wait again.

Client SSID isn’t visible

The mesh ID is deliberately not broadcast as a client SSID. Under Wireless > Access points, an additional visible Wireless Network must be assigned to the mesh AP. If only OfficeMesh is configured, endpoints have no visible network.

Also check the client SSID’s Frequency band, schedule, Security mode, and AP assignment. A second mesh network on the same AP isn’t a solution because only one mesh is supported per AP.

Client connects but doesn’t receive an IP address

The radio path is then already working at least partially. Next, check Client traffic, the Wireless interface, DHCP server or DHCP relay, and possible VLAN paths. With Bridge to VLAN, also consider the mesh product limit: APs with assigned VLANs can only form a mesh if the VLANs don’t use this Client traffic mode.

Restarting the wireless service isn’t a standard step. First establish which AP the client uses and whether DHCP requests reach the expected path.

Client has an IP address but no internet access

In Log Viewer, first look for the expected Firewall Rule ID and NAT Rule ID. If both are missing, the problem is more likely related to the zone, network object, rule order, or data path than to the mesh itself. If the rules match, check DNS, gateway, and the WAN path next.

A broad Any rule isn’t a mesh diagnostic. Run the same client test once at the root AP and once at the mesh AP. If it only works at the root, continue investigating the backhaul; if it fails at both APs, the fault probably belongs to the common wireless or firewall configuration.

Connection is unstable or slow

Check the same channel on all mesh APs, disabled Dyn chan, signal quality, interference, distance, and walls. APs that aren’t part of the mesh shouldn’t occupy the same channel unnecessarily. There must also be enough radio capacity left for the backhaul and clients.

Compare performance with the same application, the same client, and conditions as similar as possible at the root and mesh APs. This separates the mesh path from a general WAN, DNS, or client problem.

Controller or client status remains unclear

The Sophos Firewall service logs help with node-local diagnostics. These read-only checks are useful in the Advanced Shell:

tail -n 200 /log/awed.log
tail -n 200 /log/wc_remote.log

awed.log shows controller and APX communication; wc_remote.log helps with wireless clients. A single log entry doesn’t prove the user traffic path. Timestamps, AP status, client list, firewall logs, and a reproducible test belong together. The LED and blink codes of Sophos Access Points also help classify boot, update, and mesh states on the device.

Roll back the mesh safely

A rollback is performed in a controlled manner while wired management access works:

  1. Document which APX is the root and which one is the mesh AP.
  2. Reconnect the mesh AP by LAN to the management network and wait until it’s active.
  3. If necessary, move the visible client SSID to a remaining wired AP.
  4. Remove the mesh network from the APX devices or delete it under Wireless > Mesh networks.
  5. Restore previous channel and Dyn chan settings only deliberately.
  6. Restart both APX devices in a controlled manner.
  7. Recheck the client IP, DNS, rules, and internet access.

A factory reset only makes sense if the APX no longer accepts a managed configuration despite correct cabling, power, and controller path. It isn’t a substitute for a documented rollback.

Operations checklist

  • All participating devices are compatible APX models and were first provisioned by LAN.
  • Exactly one mesh network is assigned per AP.
  • One APX remains permanently wired as the root.
  • The mesh band and fixed channel match on all participating APX devices.
  • Dyn chan is turned off on the mesh band.
  • The visible client SSID is assigned separately.
  • DHCP, Firewall Rule ID, NAT Rule ID, and a blocked destination have been tested.
  • Performance and stability have been compared at the root and mesh APs.
  • Root failure, the lack of automatic takeover, and rollback are documented.
  • APX End-of-Life and a later wireless platform change are planned.

FAQ

Is the mesh ID the visible wireless SSID?

No. The mesh ID belongs to the hidden backhaul between the APX devices. Clients also need a normal Wireless Network with a visible SSID, security, Client traffic, and suitable rules.

Can a second APX take over the root AP automatically?

No. Sophos doesn’t document automatic root takeover for this mesh. At least one AP remains wired; after a root failure, recovery must be controlled and may require a restart or new cabling.

Why must all APX devices be connected by LAN first?

Each APX must be accepted by the firewall and receive its mesh configuration. Only then is the intended mesh AP disconnected from the LAN, started at its destination, and connected through the root AP.