Configure 802.1X and port security securely on Sophos Switch
802.1X controls network access at a switch port before a user or device is admitted. Sophos Switch supports Local user, RADIUS, or TACACS+ as the global authentication method. MAC Authentication Bypass (MAB) has a narrower prerequisite: MAB and Hybrid require a RADIUS server; Local user and TACACS+ are not documented backends for them. Independently, Port security limits how many MAC addresses a port may learn dynamically. The DoS switch drops certain suspicious packet patterns.
Do not enable these functions on every port in one step. An incorrect AAA secret, an unreachable server, an unsuitable port mode, or an undersized MAC limit can lock out legitimate devices. First establish AAA reachability, then test exactly one non-critical access port, and expand only after acceptance.
⚠️ Protect management: Do not use the current management uplink, the AAA server port, or infrastructure ports as the first test ports. Before the change, ensure independent local or out-of-band access and a documented rollback. Without that recovery path, do not remotely change the only management path.
Scope and starting point
In Sophos Fusion, first open the individual switch:
My Products > Switches > Switches > [Switch] > Security
The relevant areas are:
- DoS
- 802.1X with Global settings, Port settings, and Authenticated host
- Port security
- RADIUS server
- TACACS+ server
Keep the mechanisms separate. AAA determines which identity the backend accepts. 802.1X or MAB dynamically decides access at the port; Force authorized and Force unauthorized impose a fixed port state. Port security counts learned MAC addresses but does not authenticate identities. DoS examines packet patterns and replaces neither access control nor a MAC limit.
ACLs and ACEs are outside this runbook; they need their own rule, order, and port-binding design. VLANs must already exist. Configure Sophos Switch VLANs securely explains safe Tagged/Untagged membership and PVID planning. This guide creates neither the data VLAN nor the Guest VLAN.
Prerequisites and change plan
Changes through Sophos Fusion require a valid Sophos Switch Support and Services subscription. Local management remains available without it, but Fusion changes do not. Before the maintenance window, use a controlled write operation to verify that the Fusion account can configure the selected switch; do not assume a particular tenant or custom-role name. Local management requires an account with Privilege type: Admin; User is read-only. Local accounts and Fusion roles are independent. See Choose Sophos Switch models and management.
The switch must already be registered, reachable, and synchronized. Check registration, subscription status, and the management path with Register Sophos Switch in Sophos Fusion. The same security rules apply to a deliberately locally managed switch, but the following menu paths and Configuration source notes refer to Sophos Fusion.
Record before configuration:
- the switch, test port, connected test device, and its 802.1X capability;
- the current management path and an independent recovery path;
- production access, uplink, server, phone, printer, and other infrastructure ports;
- the intended 802.1X method: Local user, RADIUS, or TACACS+; MAB or Hybrid always requires RADIUS;
- IP address, authentication port, Shared Secret, timeout, and any server order;
- the path from switch to AAA server, including VLAN, routing, and filters;
- intended 802.1X, MAB, and Guest VLAN use for each port type;
- expected simultaneous hosts per port, for example a phone with a downstream PC;
- initial Configuration source, Authorized status, and Port Security values;
- maintenance window, success criteria, observation time, and rollback owner.
The AAA server must know the switch as a requesting device with an exactly matching Shared Secret. Define a test identity and verify the expected accept or reject. With RADIUS VLAN assignment, returned VLANs must already exist correctly on the switch and throughout the path. Create the Guest VLAN in advance too, and test it through to gateway, DHCP, and permitted destinations.
MAB requires RADIUS: Before configuring MAB or Hybrid, the RADIUS server must contain a separate entry for every permitted MAB device. Both username and password are the device MAC address in lowercase without punctuation or separators, for example
fd6238bb0414.FD:62:38:BB:04:14does not satisfy the format. Provision these credentials before the port rollout; Local user or TACACS+ does not replace this prerequisite.
Observe the configuration source: Not set uses the setting configured locally on the switch. Configuration source shows its origin. Decide before rollout whether Sophos Fusion or the local interface is authoritative; do not overwrite a visible value merely because you assume a default.
Rollout overview
Choose the port profile first. A proven Local user, RADIUS, or TACACS+ configuration may be used for pure 802.1X ports. MAB or Hybrid, however, always has the RADIUS prerequisite above. Port based protects individual endpoints; Host based is only for an explicitly approved trust zone behind the first authentication. Port Security and DoS remain later, separate changes.
- Document the initial state, management recovery path, port groups, and success criteria.
- Choose pure 802.1X, MAB, or Hybrid, and select an allowed backend.
- If using an external backend, configure it and verify reachability with A0. For MAB/Hybrid, also meet the central RADIUS prerequisite above.
- Test the Guest VLAN and possible dynamic RADIUS VLANs end to end without 802.1X.
- Select one non-critical access port and positive and negative test devices. Leave uplinks, management, and AAA server ports unchanged.
- Under Global settings, prepare the authentication method and planned Guest VLAN state.
- Configure the pilot port with Mode: Auto, the suitable Authentication mode, initially MAB mode: Disabled, and unchanged default timers.
- Enable Status: On in a controlled way and transfer it with Update. Connect the test client only now if necessary.
- Run 802.1X tests A1 and A2.
- If planned, enable MAB or Hybrid separately and run A3 through A5.
- Test a second device as in A6. Remedy unauthorized access caused by Host based by changing the mode or topology.
- Accept the Guest VLAN and RADIUS VLAN assignment separately with A7. Then enable Port Security with a topology-appropriate Max number of MAC addresses and run A8.
- Enable DoS as a separate change and run A9.
- After stable observation, migrate similar ports in small groups and check each group with A10.
Acceptance tests
| ID | Test and expected result |
|---|---|
| A0 – Backend | The intended AAA server answers the defined test request as expected. With multiple servers, test preferred-server failure in a controlled manner. Configuration source globally and on the pilot port matches the plan. |
| A1 – 802.1X positive | A valid supplicant is admitted and appears under Authenticated host. Authorized status, VLAN assignment, and actual data path match the plan. Any Reauthentication works after the planned interval. |
| A2 – 802.1X negative | Invalid credentials do not receive the same production access. Authentication logs, Authorized status, Authenticated host, and a data test confirm rejection. |
| A3 – MAB positive | An inventoried test device provisioned according to the central RADIUS prerequisite is admitted through MAB. Status, host display, VLAN, and data path are correct. |
| A4 – MAB unknown MAC | In a fresh session not already opened by Host based, connect a device with an unknown, unprovisioned MAC. The RADIUS log shows Reject for the missing entry. Authorized status and Authenticated host show no unexpected admission, and a data test confirms that production traffic is denied or dropped. |
| A5 – Hybrid unknown MAC | Repeat A4 in a new Hybrid session. Three failed 802.1X attempts must be visible before MAB; the remaining expected results are those of A4. |
| A6 – Second device | After successful authentication, connect a second unprovisioned device. Port based drops its traffic. With Host based, access without separate authentication is the documented effect and is acceptable only with explicitly approved trust. For Host based, Mode: Auto, Maximum hosts from 1 to 10, Guest VLAN: Off, and RADIUS VLAN assignment: Off must also match the plan. |
| A7 – VLAN | The Guest VLAN or dynamically assigned RADIUS VLAN is correct and provides only intended access. Test the two functions separately. |
| A8 – Port Security | The port works with the intended number of legitimate MAC addresses. Test and document one additional MAC in isolation; do not assume an undocumented Violation Action. |
| A9 – DoS | NTP, DNS, DHCP, permitted-size ping, and business-critical applications work with DoS: On. Management, uplink, and AAA paths remain available. |
| A10 – Group | After each migrated port group, management, AAA, and representative positive and negative clients still work. Configuration source globally and per port matches the plan. |
Synchronization with Sophos Fusion alone is not acceptance. Actual authentication, correct VLAN assignment, and expected traffic determine success.
The following sections explain the fields and security boundaries required for these steps.
Configure the external AAA server first
Add a RADIUS server
Under:
Security > RADIUS server
select Add and set:
| Field | Meaning |
|---|---|
| Server ID | RADIUS server ID |
| Server IP | Server IP address |
| Authorized port | Authentication port; default 1812 |
| Shared secret | Key shared by switch and RADIUS server |
| Timeout | Wait for a response before trying the next server; default 3 |
| Retry | Requests sent before failure; default 3 |
| Configuration source | Origin of the setting |
The Shared secret must match exactly on both sides. Set Timeout and Retry so that server failure does not cause an unacceptable login delay. Use Delete only when no planned authentication path still depends on that server.
Add a TACACS+ server
Under:
Security > TACACS+ server
select Add and set:
| Field | Meaning |
|---|---|
| Server IP | Server IP address |
| Priority | Order among servers; determines which is contacted first |
| Authorized port | Authentication port; default 49 |
| Shared secret | Key that must exactly match the TACACS+ server |
| Timeout | Wait before the next server; default 5 seconds |
| Configuration source | Origin of the setting |
TACACS+ is mainly used to administer network devices, but Sophos Switch also offers it as an 802.1X Authentication method. Verify that the specific TACACS+ service processes the 802.1X test request as expected. Working device administration does not prove a working 802.1X workflow.
Prepare 802.1X globally
Under:
Security > 802.1X > Global settings
these fields are available:
- Status: On, Off, or Not set
- Guest VLAN: On, Off, or Not set
- Guest VLAN ID: choose from defined VLANs; available after Guest VLAN: On
- Authentication method: Local user, RADIUS, or TACACS+
- Configuration source: origin of the settings
For a pure 802.1X test, select the planned Authentication method; use Local user or TACACS+ only for a proven 802.1X case. MAB or Hybrid is subject to the central RADIUS warning. Enable the Guest VLAN only after deliberately restricting and testing its access. Update saves; Clear discards unsaved changes.
Global Status: On does not define every port’s behavior. Prepare port parameters before activation. If global and port changes cannot be rolled out together, physically disconnect the test port until its configuration is complete, or set Status: On immediately after the port values during the controlled window.
Configure a test port
Under:
Security > 802.1X > Port settings
select only the intended test port and choose Edit.
Separate dynamic and fixed port states with Mode
Mode offers:
- Not set: use the local switch setting
- Auto: enable 802.1X on the interface; mandatory with Authentication mode: Host based
- Force authorized
- Force unauthorized
Sophos UI documentation describes the last two labels unexpectedly: Force authorized is said to block all unauthenticated traffic, while Force unauthorized is said to allow it. Because this described effect contradicts the usual meaning of their names, do not deploy either untested. Use Auto for the 802.1X test. If a forced state is needed, verify it first on an isolated port with positive and negative access tests.
Thus Auto is this runbook’s dynamic 802.1X state. The two Force values are static controls, not substitutes for successful AAA authentication, and must not count as a positive 802.1X test.
Set MAB and authentication mode
MAB mode has four values:
- Not set: use the local setting
- MAB: use MAB only
- Hybrid: try 802.1X first; switch to MAB after three failed attempts
- Disabled: do not use MAB
Use MAB only for deliberately inventoried devices that cannot use 802.1X. MAB and Hybrid require RADIUS as stated above. Hybrid does not guarantee access for an unknown device: after three failed 802.1X attempts, RADIUS must accept the resulting MAB identity. Keep MAB Disabled for a pure 802.1X test, then test MAB-capable groups separately.
Under Authentication mode:
- Not set: use the local setting
- Port based: authenticate exactly one host per port; traffic from an additional device is dropped. Sophos recommends this for endpoint switch ports.
- Host based: authenticate the port once; further devices may then send traffic without their own authentication. Sophos recommends this for switch-to-switch links and documents a maximum of ten devices.
For Host based:
- Mode must be Auto.
- Maximum hosts permits
1to10. - Guest VLAN must be off.
- RADIUS VLAN assignment must be off.
With Host based, Maximum hosts does not give every counted host a separate identity decision. Do not choose it merely because several MAC addresses are visible, such as a phone with PC passthrough, a hypervisor, or a downstream device. Use it only if all devices and all traffic behind the first successful authentication are explicitly trusted. Where every endpoint needs separate enforcement, retain Port based and use a suitable physical or logical design rather than merely increasing Maximum hosts.
Set VLANs and timers
Also available per port:
- Guest VLAN: enable or disable per port
- RADIUS VLAN assignment: enable or disable VLAN assignment supplied by RADIUS
- Reauthentication: enable or disable periodic reauthentication
- Reauthentication period:
30to65535seconds, default3600 - Quiet period: wait after failed authentication,
0to65535seconds, default60 - Supplicant period: EAP request interval,
0to65535seconds, default30; the switch sends three requests at this interval before switching to MAB when configured - Authorized status: current port authentication status
- Configuration source: origin of port values
Retain default timers for the first test unless the AAA and client plan requires otherwise. Shortening several timers together impedes troubleshooting. Enable RADIUS VLAN assignment only after verifying a test response with the expected VLAN and the complete VLAN path.
Save with Update. Use Clear to discard unsaved values.
Add Port Security
Under:
Security > Port security
limit the MAC addresses learned per port:
- Port: affected physical port
- Status: Enabled or Disabled
- Max number of MAC addresses:
1to256 - Configuration source: origin of the setting
Port Security does not replace 802.1X. It limits learned MAC addresses but does not identify users in this configuration. Conversely, plan Maximum hosts for Authentication mode: Host based separately within 1 to 10. Both limits must match actual port use.
Only after 802.1X acceptance, enable Port Security on the test port with a realistic limit and select Update. Connect all intended devices in turn. The documented interface offers neither a static MAC allowlist nor a separate Violation Action here. Do not assume Shutdown, Restrict, or Sticky Learning; observe actual behavior on the pilot port. Max number of MAC addresses does not create a static MAC authorization.
Test DoS protection separately
Under:
Security > DoS
choose On, Off, or Not set, and save with Update. Not set uses the local switch setting. With On, the switch drops patterns including:
- identical source and destination MAC addresses;
- identical IPv4 or IPv6 source and destination addresses (LAND Attacks);
- identical TCP or UDP source and destination ports (TCP Blat, UDP Blat);
- fragmented packets over 64 KB (Ping of Death);
- IPv6 fragments smaller than
1240bytes; - fragmented ICMP packets;
- IPv4 and IPv6 ping packets over
512bytes; - broadcast ICMP in the Smurf Attack check, with netmask length limited to
24(x.x.x.255); - TCP headers smaller than
20bytes; - TCP-SYN with SYN set, ACK unset, and source port below
1024; - Null Scan with no TCP flags and sequence number
0; - Xmas with sequence number
0and FIN, URG, and PSH set; - TCP SYN-FIN with SYN and FIN set together;
- TCP SYN-RST with SYN and RST set together.
These checks are fixed to the global switch; the listed thresholds cannot be configured separately in this view. Sophos particularly warns that older NTP clients using the same source and destination port can be detected as TCP Blat and dropped. Test NTP explicitly before broad activation; Sophos recommends disabling DoS protection when such clients are used.
Do not enable DoS protection together with the first 802.1X and Port Security test, or a dropped packet cannot be attributed clearly to access control or the DoS filter.
Operations and lifecycle
After rollout, document the port profile, AAA dependency, and exception reason per port type. Repeat positive and negative tests after firmware or AAA changes, VLAN redesigns, or replacement of phones, hypervisors, and downstream devices. Never carry forward the contradictory Force behavior or over-limit MAC behavior from old firmware without testing.
Do not rotate RADIUS or TACACS+ Shared secret on one side only. Use a second tested server path or a maintenance window with local recovery, coordinate both sides, and then test a new login and failover. Delete old servers only after no port or fallback path depends on them.
Regularly check:
- subscription and synchronization status under Fusion management;
- reachability, certificate or identity policy, and logs of the AAA service;
- obsolete MAB exceptions and Guest VLAN access;
- Maximum hosts and Max number of MAC addresses against current topology;
- NTP and operational diagnostic packets with DoS: On;
- management and AAA recovery after VLAN, routing, or ACL changes.
Troubleshooting by symptom
No device can authenticate
- Verify global Status: On and Mode: Auto on the test port.
- Check Configuration source; Not set may inherit a different local value.
- Compare Server IP, Authorized port, and Shared secret exactly on switch and AAA server.
- Check reachability, return path, and filters between switch and AAA server.
- Check AAA logs for a request, unknown requesting device, or rejected identity.
- Wait for Quiet period and Supplicant period rather than causing more failures by rapid retries.
- With multiple servers, check Timeout, Retry, or TACACS+ Priority.
802.1X works, but MAB does not
- Check MAB mode: Disabled never tries MAB; Hybrid waits for three failed 802.1X attempts.
- Verify global RADIUS and reachability; Local user and TACACS+ are not documented MAB backends.
- On RADIUS, verify the device entry and exclude uppercase, punctuation, or separators contrary to the central format rule.
- Account for Supplicant period; Hybrid fallback is not immediate.
- Test first without Guest VLAN and dynamic VLAN assignment, then add them separately.
The client authenticates but cannot reach the network
- Confirm success under Authenticated host and Authorized status.
- For RADIUS VLAN assignment, check the returned VLAN, switch membership, uplink, gateway, and DHCP.
- For guest access, check Guest VLAN, Guest VLAN ID, and the complete VLAN path.
- Check Port Security; a small MAC limit may disrupt multi-device ports.
- If only certain packet types fail, temporarily reverse DoS as the final, separate change.
Host based cannot operate as planned
- Set Mode: Auto.
- Turn off Guest VLAN and RADIUS VLAN assignment.
- Set Maximum hosts from
1to10to match the actual count. - Compare the additional limit under Port security with expected hosts.
NTP or individual diagnostic packets fail after the change
- Determine whether the failure began exactly with DoS: On.
- For older NTP clients, check identical source and destination ports; in this documented case set DoS: Off and save with Update.
- For ping, account for the fixed
512-byte maximum and fragmentation. - Do not permanently assume DoS is the cause: after the targeted reversal, test routing, VLAN, and endpoint separately.
Rollback
Reverse only the most recently deployed scope, in reverse order:
- If failure began with DoS, restore the documented previous Off or Not set under Security > DoS, then select Update.
- If Port Security is responsible, set Status: Disabled on the affected port or restore the previous MAC limit, then select Update.
- For MAB, Guest, or VLAN problems, reverse the last enabled port option first; do not unnecessarily remove the working 802.1X baseline.
- On an affected test port, restore the documented previous Mode, MAB mode, Authentication mode, timers, and VLAN state, then select Update.
- If several ports are affected, roll back the latest group first. Keep management, uplink, and AAA server ports unchanged.
- Only if a port-level reversal does not restore access, set global Status: Off or its documented previous value and select Update.
- Use Delete for RADIUS or TACACS+ servers only when no working port configuration depends on them.
- Recheck management, AAA reachability, client access, and Configuration source, and document the actual final state.
If management loss makes Sophos Fusion unreachable, use the prepared local or out-of-band access and restore the previously documented local state. Do not try to recover the only remote management path through further unsecured changes.