Skip to content
Avanet

Replace or reset a Sophos Switch

Replacing or resetting a switch is more than moving cables and importing any backup. It may carry management, VLANs, uplinks, LAGs, STP, routing, DHCP protection, 802.1X, PoE and Sophos Fusion connectivity. Remove from Sophos Fusion also deletes its cloud backups. Inventory dependencies, save a backup outside Fusion, prepare the target, cut over in stages, restore locally, resolve conflicts, and reset the old unit only after validation. For RMA returns, follow the case-specific Sophos instructions and deadline instead; return does not depend on a successful reset.

⚠️ Plan an outage: Factory reset, powering off and moving uplinks interrupt services; PoE devices lose power and network access. A backup restores configuration, not an uninterrupted data path. Critical connections require a maintenance window, onsite access and a documented return path.

Which workflow fits the task?

TaskFusion stepTargetContinue with
Replace a failed switchDo not remove the old unit merely for replacement; register the replacement in the same accountReplacement with its own serial numberSections 1–4, 6 and 7; also 12 for RMA
Reset a working switchAfter verified external backup, remove and register the same device againSame deviceSections 1, 2 and 5–9
Move to another Fusion accountRemove from source after verified backup; register in targetSame deviceSections 1, 2 and 5–9
End cloud management onlyRemove after verified backup; do not factory-resetDevice remains localSections 1, 2 and 5.1; validate local operation under 7
Retire or return permanentlyRemove after verified backup if case-specific RMA instructions allowNo production targetSections 1, 2 and 10; also 12 for RMA
Neither firmware partition bootsUse the separate recovery runbook; remove the Fusion entry only in its stated orderSame deviceStop here and follow section 11

1. Inventory dependencies and the initial state

Record identity and management (serial, model, MAC, name, location, tags, account, site/stack, management IP, firmware/agent); physical paths (ports, patch panel, peers, uplinks, transceivers, LAG/LACP, stack cabling); Layer 2 (VLAN IDs, tagged/untagged, PVID, management VLAN, STP/root path, loop protection, voice VLAN); Layer 3/services (interfaces, routes, DHCP Relay/Snooping trust, IGMP/MLD, ACL, QoS, Storm Control); access/monitoring (802.1X/RADIUS, Port Security, local admins, SNMP, Syslog, RMON); PoE loads, priorities and budget; and Fusion state, alerts, last event, local access, test devices and approvers.

Open My Products > Switches > Switches and capture Serial no., Model, State, Parent and last event. Documented states are Waiting for sync, Pending, Syncing, Out of sync, Suspended and Manual synchronization needed; the latter requires Reapply all settings. Do not start while the baseline is unclear. Compare Fusion with the local UI and supplement screenshots with a text port/VLAN plan.

Define acceptance criteria and abort points

For every test in section 7 define the target, owner and evidence, plus maximum outage, last abort time and decision maker. Abort if independent management, a readable backup, compatible model/port capacity or timely acceptance is unavailable.

2. Save an external backup before removal or reset

  1. Go to My Products > Switches > Backup.
  2. Open the old switch serial number.
  3. Select the required backup.
  4. Choose Actions > Download backup.
  5. Record location, filename, serial and creation time.

Irreversible boundary: Removing a switch from Fusion deletes all of that switch’s Fusion backups. Continue only when the required .cfg is stored outside Fusion and readable on the restore system.

For a local export use Firmware > Backup and restore: choose Backup, then HTTPS or TFTP with server IP, choose Apply, and confirm again with Apply. Verify that the .cfg exists and is readable before removal. A backup does not replace inventory: synchronization is only from Fusion to the switch, so restore may produce Out of sync, Manual synchronization needed and port/VLAN Conflicts.

3. Prepare the replacement and maintenance window

Verify model, revision, ports, uplinks and PoE budget; record target serial/account; prepare management, internet and local credentials; label both cable ends and mark LAG/uplinks; keep the .cfg locally; confirm testing, communications and outage limit; for RMA, inspect the received model/revision. Sites and stacks may auto-assign settings. Prefer the intended template where applicable, but never apply template and backup uncontrolled. See Operate Sophos Switch fleets, sites and stacks.

Separate roles, subscription and support

An authorized Fusion user handles backup, removal, registration and site assignment; a local administrator handles Reset and Firmware > Backup and restore; network/service owners accept cabling, VLANs, uplinks, security, PoE and applications. None of these approvals replaces another. Fusion management, support, firmware and Advanced RMA require Sophos Switch Support and Services; check profile icon > Licensing. Support validates the defect and hardware exchange, while the customer handles backup, cutover, restore and acceptance. Register an RMA replacement in the same account; the subscription belongs to the customer account, not one hardware unit.

4. Controlled cutover to a replacement switch

  1. Record Fusion state and a final functional test.
  2. Gracefully stop critical PoE devices where required.
  3. Disconnect edge ports, then redundant paths per design, and the remaining uplink last; never create an uncontrolled LAG/STP loop.
  4. Power off but do not reset the old unit. Keep it as a limited fallback; meet RMA packing and return deadlines independently.
  5. Open My Products > Switches > Switches and choose Add switches.
  6. Enter replacement serial, select site and click Register.
  7. Connect management and power on.
  8. Connect only the intended management/uplink path; await registration, firmware and state changes.
  9. If needed, restore under section 6.
  10. Connect ports in groups: infrastructure/test segment, access ports, then critical PoE loads.
  11. After each group test link, VLAN, STP/LAG, addressing and application.

Network/domain requirements and the 15-minute window are in Register a Sophos Switch in Sophos Fusion. The same-account RMA rule still applies.

5. Reset or migrate accounts in the correct order

5.1 Remove the old device from Sophos Fusion

Required for resetting the existing device; for migration, do this in the source account after download.

⚠️ Stop before removal: Continue only if the required .cfg exists outside Fusion and is readable. Remove from Sophos Fusion deletes every Fusion backup for this switch.

  1. Open My Products > Switches > Switches.
  2. Click the switch serial number.
  3. Choose Remove from Sophos Fusion.
  4. Select the checkbox and confirm with Confirm.

Removal ends Fusion management but does not factory-reset local configuration.

5.2 Register and reset the same device

  1. In the future account open My Products > Switches > Switches.
  2. Choose Add switches.
  3. Enter serial, select site and click Register.
  4. Sign in to the local UI.

⚠️ Stop before reset: The outage must be approved and the section 8 fallback decision made. After factory reset, the previous local configuration no longer runs.

  1. Open the profile icon and choose Reset.
  2. Confirm with Apply; the switch reconnects to Fusion.

For account migration, perform these Reset switch steps in the target account, after ensuring the source no longer holds the only backup.

5.3 If Fusion is unavailable

If only the local password is lost, set a new one under System details > Recover password. If Fusion communication is impossible, use the physical reset button and then the factory password printed on the label or packaging. Do not guess model-specific button timings; follow that device’s operating instructions.

6. Restore the .cfg locally

  1. Sign in locally.
  2. Open Firmware > Backup and restore.
  3. Set Backup and restore to Restore.
  4. Choose HTTPS.
  5. Click Select file, select the .cfg, and confirm with OK.
  6. Choose Apply and confirm again with Apply.

Alternatively choose Restore and TFTP, enter server IP and backup filename, and confirm with Apply. Do not interrupt power during restore, restart or synchronization. Reconnect further ports only after local access and comparison with the plan.

7. Resolve conflicts and validate service

Out of sync, Manual synchronization needed, and Conflicts under Port settings or VLANs indicate an incomplete migration, not permission to overwrite blindly. Compare local values, Fusion template and inventory, then choose the authority. Use Reapply all settings only after confirming Fusion as desired state.

Technical acceptance

  1. Identity: serial, model, name, site/stack and firmware match.
  2. Management: local UI and Fusion work; last event is current.
  3. Synchronization: no unexplained Waiting for sync, Pending, Syncing, Out of sync or Manual synchronization needed remains.
  4. Ports/loop protection: uplinks, LAG, speed, STP role and errors match.
  5. VLANs: test tagged/untagged, PVID and management VLAN; decide conflicts.
  6. Layer 3/DHCP: verify IP, routes, relay, Snooping trust/bindings; a test client gets the correct VLAN address and reaches gateway, DNS and approved targets.
  7. Security: test 802.1X, RADIUS, ACLs and Port Security with allowed and, where safe, denied cases.
  8. PoE: check consumption and complete re-registration of phones, APs and cameras.
  9. Monitoring: SNMP, Syslog, RMON and alerts provide new timestamps/data.
  10. Application: owners confirm real services, not merely LEDs or ping.

8. Rollback and its limits

Before factory-resetting the old device

If cutover fails while the old unit is unchanged: isolate the replacement and prevent parallel paths; return labelled cabling in reverse order to the powered-off old unit; power it on and retest management, uplinks, LAG/STP, VLANs, DHCP and critical services; preserve logs, failed target state and Fusion states.

After reset, cloud removal or hardware return

Immediate full rollback is no longer guaranteed: Fusion backups are gone after removal; local running configuration is gone after reset; restore conflicts may require manual work; a shipped or failed unit cannot be fallback; a recovery image restores only minimal boot/network functions before update and registration. “Rollback” then means rebuilding from external .cfg, inventory and approved values. Decide before reset.

9. Troubleshoot systematically

The replacement does not appear or connect

Check serial, target account/site, management IP, DHCP/static addressing, DNS, gateway and outbound access. Handle a missed registration window with a planned restart and new attempt, not an impulsive reset. Preserve switch, firewall and proxy logs with timestamps before proceeding.

The .cfg cannot be restored

Verify Restore, HTTPS, .cfg suffix, Select file, OK, source serial, target model, firmware and exact error. Do not try backups indiscriminately or power off during upload/write. Stop and escalate compatibility uncertainty to Sophos Support with evidence.

Conflicts appear or synchronization does not finish

Do not mask Out of sync, Manual synchronization needed or port/VLAN Conflicts with repeated Apply, Synchronize or Reapply all settings. Compare Parent, local, Fusion and inventory; choose authority per entity before enabling more ports.

Management works but clients or PoE devices do not

Isolate the last port group; check link/speed, tagging, PVID, LAG/LACP, STP, DHCP-Snooping trust, 802.1X and PoE budget. Green Fusion status proves neither data path nor PoE capacity. At abort time, use section 8 if the old unit remains unchanged.

Reset or erasure cannot be verified on a failed device

Record not verifiable, attach serial and defect evidence, and involve internal security. Neither cloud removal nor shipping proves local erasure. Keep firmware recovery, hardware failure and data clearing as separate decisions; do not delay RMA return beyond case instructions/deadlines.

10. Secure decommissioning

For RMA, this is not an independent instruction to reset. Reset only when technically possible and authorized by the case’s label, letter or Support instruction. Otherwise leave the device unchanged, record not verifiable, follow internal security/RMA disposition, and still meet section 12’s 15-day deadline.

  1. Confirm no production link, PoE endpoint, monitor or management path depends on it.
  2. Retain .cfg, port plans, logs and support evidence externally under policy.
  3. Remove it from the data path and confirm outage or replacement success.

⚠️ Stop before removal: The required .cfg must exist externally and be readable. Remove from Sophos Fusion deletes all Fusion backups for this switch.

  1. Run Remove from Sophos Fusion and verify disappearance from the device list.

⚠️ Stop before reset: Continue only when reset is authorized for this decommissioning/RMA case. If it cannot then be checked, explicitly record not verifiable.

  1. Reset through profile icon > Reset > Apply, or use the physical button according to model instructions if Fusion communication is unavailable.
  2. After restart verify old IP, credentials and production configuration no longer work and factory state appears.
  3. Record serial, date, operator and result; protect/delete backups under policy.

A click is not proof of clearing. Never claim erasure when it could not be verified.

11. Corrupt firmware is a separate recovery case

If neither partition boots, normal .cfg restore is impossible. This lifecycle article is not an executable firmware-recovery runbook. Model, three-character serial prefix and hardware ID determine the exact .bix; DHCP/TFTP and bootloader steps differ by family. Never infer an image or parameter by similarity.

Use only Update, roll back and recover Sophos Switch firmware. During flashing, disconnect neither power nor TFTP. The recovery image is minimal: install current family firmware on Partition 1 (Active), restart, remove the old Fusion entry and register again, then restore external configuration and inspect conflicts. Coordinate suspected hardware defects with Support.

12. Complete the RMA handover

Record defect, model, revision, firmware and serial; for no power also purchase date, LED state and tests with another cable/outlet, plus photo/video if useful. Inspect replacement model/revision; register it in the same account. Prepare return from the label, letter and specific case, resetting only if possible and authorized. Remove transceivers, connectivity/Flexi-Port modules, rack kits, PSUs and power cables: replacements ship without accessories and accessories must not be returned. Return the failed unit within 15 days after receiving the replacement, regardless of reset or verified erasure.

If reset is impossible, unauthorized or unverifiable, record not verifiable, follow internal security/RMA disposition, and immediately reconcile any conflict with Support. In the form include description, model/product, revision, firmware, serial, DOA/HA details and complete shipping/contact information. See Open a support ticket with Sophos. Late/incomplete returns may be charged or subscription transfer suspended. Closure requires receipt/validation or Sophos-confirmed disposal.

13. Closure record

Close only with: external .cfg mapped to the old unit; signed section 7 matrix with target, result, evidence, timestamp and owner; before/after inventory and approved deviations; Fusion state and conflict decisions; rollback decision and time the old unit ceased to be fallback; verified reset or not verifiable record; and, for RMA, case number, shipping proof, accessory check and deadline.