Sophos Switch: Operating fleets, synchronization, sites and stacks
Under My Products > Switches > Switches, Sophos Fusion manages individual switches, sites and stacks. The overview page shows fleet status, whereas the Task queue shows the status of individual configuration tasks. Sites group switches at one location that share some settings. A stack treats physically connected switches, or switches requiring identical configurations, as a logical unit.
This runbook guides you through secure day-to-day operations. Firmware updates, device replacements, resets and removals from Sophos Fusion fall into their own maintenance processes. Such measures are only mentioned here as a transfer point if a status blocks further synchronization.
Understand operating model and inheritance
The Default site and custom sites are alternate site mappings; the default site is not a parent level for other sites, but rather a site itself and the fallback target. Two assignments are possible within each site:
- Default site or custom Site
- directly assigned Switch
- Stack
- Switch assigned to the stack
A stack therefore lies within its parent site. A switch can either belong directly to a site or to a stack within a site.
The Parent value on the switch indicates the site or stack from which the device received its configuration template. A stack in turn shows the associated site under Parent.
For every change, first document the effective source and target template, then move a pilot switch, fully synchronize its tasks, and only then process the next group.
Sophos Fusion only shows settings made locally on the switch if they have been synchronized or replicated to Fusion. CLI changes made via Run commands also do not appear as a configuration in Sophos Fusion. Therefore, an unremarkable Fusion view does not prove that no local deviation exists.
Assess the fleet first
- Open My Products > Switches > Switches.
- For the hierarchy use Tree view, for a serial number-based overall comparison use Flat view.
- If there are more than ten entries, include all pages; the page size can be set to 10, 25 or 50.
- Collect at least Name, Serial number, Status, Alerts, Version, Location, Model, VLANs, Tags and parent mapping for each affected switch.
- If there is an alert, click the number under Alerts. To check the last contact, open the switch and hover over the time of the last event under System details; the latest communication events appear there.
- Before a mass action, check the selection by serial number against the change list. A marked site or stack extends the scope to all switches selected below it.
Read status correctly in the overview
| Status | Meaning | Next safe step |
|---|---|---|
| Synchronized | Switch is connected and all settings are synchronized. | Perform a spot check on the device and data path; the status alone does not prove functional correctness. |
| Waiting for sync | Changes in Sophos Fusion are waiting to be synced. | Open the affected switch and Task queue, then synchronize in a controlled manner. |
| Pending | Changes have been sent to the switch; Fusion awaits confirmation. | Watch the connection and queue, do not immediately recreate the same change. |
| Syncing | Settings are being synchronized. | Let synchronization finish and use Auto refresh or refresh the view. |
| Out of sync | Fusion detected out-of-sync settings on the switch. | Investigate configuration source, local changes, and affected queue entity. Don’t overwrite blindly. |
| Manual synchronization needed | Automatic synchronization failed. | Open Task queue and check the details; use Reapply all settings only after investigating the cause. |
| Firmware too old | The released firmware has been available for more than 180 days; policy pushes are blocked. | Hand off to the separate firmware maintenance process. This runbook does not update firmware. |
The overview can also display states of the support subscription:
- Suspended: Fleet management is suspended until a valid support subscription is assigned.
- No subscription: The switch does not have a support subscription assigned.
- Oversubscribed: There are more switches registered than support subscriptions.
- Expired subscription: The subscription has expired.
Changes to the switch are not possible without a valid Sophos Switch support license. Therefore, do not circumvent license and firmware blockages by repeatedly synchronizing.
Use Task queue as the job log
Open the switch, site or stack and select Task queue. Enable Auto refresh if new tasks are expected during the change. The table shows Status, Switch, Configuration source, Entity, Action, Created by and Created at. If you have more than ten tasks, consider all pages or 10, 25 or 50 lines.
- Switch is the serial number of the target device.
- Configuration source shows the origin of the task.
- Entity indicates the affected switch module. Click on the entry to open the order details.
- Action describes the operation, for example Create for a new or Update for a changed configuration.
- Created by and Created at associate the change with a Fusion account and time.
Task status and permitted interventions
| Task status | Meaning | Permitted action |
|---|---|---|
| Success | Task completed successfully. | Validate the intended functional result. |
| Waiting | Task is configured in Sophos Fusion and waiting to be sent to the switch. | Check connection and sequence; Use Synchronize for released changes. |
| Pending | Task is pending in Sophos Fusion. | Review details and previous tasks; wait or consciously choose Skip. |
| Syncing | Task has been sent; Fusion awaits confirmation. | Observe communication, do not start a parallel counter-write process. |
| Failed | Task failed. | Fix error details and dependency; then Retry or consciously Skip. |
| Skipped | Task was skipped and not applied. | Only synchronize again with Retry if you want it to continue to apply. |
| Suspended | Task is suspended due to outdated firmware. | Hand off to the firmware maintenance process. |
The Sophos documentation lists created, Pending and Failed as selection conditions for Skip. created only reproduces the wording of this source-named condition and does not add to the documented list of task statuses. In particular, created may not be equated with Waiting nor with the time Created at. Retry is available for Failed and Skipped.
Skip is not a repair. It leaves a desired change unapplied and can technically decouple subsequent tasks. Beforehand, document Entity, Action, source, creator, time and affected switch. Only trigger Retry after the cause has been eliminated; otherwise there will just be another unsuccessful attempt.
Synchronize in a controlled manner
Handle individual switches
- Open the switch in the overview via Name.
- Check against inventory and change under Basic details State, Parent, Serial no., Model and MAC Address.
- Under System details check last event time, alerts, port overview, Connection usage and for PoE models PoE.
- Open Task queue, sort by Created at and dependencies and check the detailed view via Entity.
- Select Synchronize only if the target, source and scope are correct. In the fleet overview, after selecting the target devices, click Synchronize again to send waiting Fusion settings.
- Monitor the task through its documented status values until Success. Do not assume success from Waiting, Pending or Syncing.
- For Manual synchronization needed, first save the cause and the queue. Reapply all settings reinstalls the switch settings and is therefore not a harmless update.
- Finally, check the fleet status, queue and real network function.
Decide configuration conflicts
A conflict is a directional decision, not just a synchronization error. Clarify before the procedure:
- Which level should be authoritative: site, stack, switch, or consciously local CLI configuration?
- What does Configuration source show for the affected entity?
- Was it changed locally, via Fusion-UI or via Run commands?
- Did Out of sync arise because Fusion detected a local deviation, or did a Fusion task fail?
- Which dependent settings, uplinks, VLANs, management paths, or security controls would be affected?
Only adopt local values in Fusion if they have been checked and approved as the target state. Only reapply Fusion values if it is clear that the parent or switch configuration is authoritative. If the origin is unclear, neither skip nor trigger a blanket Reapply all settings. First save screenshots or export of the visible values, serial number, parent, Configuration source, task details and timestamp.
Plan and operate sites
A site is intended for switches in the same geographical location that share some settings. A stack is more suitable for devices that are physically connected or have completely identical configuration. Sites and stacks are created under My Products > Switches > Switches with Create site/stack; To do this, first select the intended switches and then select Site or Stack.
For a site, Name, optionally a real Location via Google Maps and optionally a Description are stored. A clear name should indicate the location and operational purpose.
The Site management page shows Site, Switches, Sync pending and Sync failed. With Edit Site you can check the name, location, description and assigned switches and stacks. The tab System Details shows Name, Serial no., Model, State, MAC address, IP address and Firmware version for each switch; the display can be organized using drag-and-drop.
Configure ports through a site
In many settings there are two selection models:
- Select the same ports on all switches applies the same logical port numbers to all switches.
- Select individual ports on each switch allows different physical port selection per device.
The common list includes 48 copper ports and four SFP ports, 49(F1) through 52(F4), because a site can contain 8-, 24-, and 48-port models. A switch only accepts settings for ports that actually exist. Port 7 therefore applies to all models, whereas port 37 applies only to 48-port models. 49(F1) maps to 9(F1) on an 8-port switch, 25(F1) on a 24-port switch, and 49(F1) on a 48-port switch.
At site level, you can access Basic details, VLANs, Port settings, Discovery, Networks, Routes, L3 protocols, QoS, SNMP, Security, Task queue and Diagnostics. Site management shows the last change made in Sophos Fusion; the site configuration is not updated regularly, unlike a backup. It is therefore not a restore point.
Plan stacks, check topology and health
A stack belongs to a parent site. It only makes sense if the members are physically connected to each other or should have identical configurations. When creating under Create site/stack > Stack parent site, Name, optionally set real Location and Description.
To display connections, Turn on LLDP and STP to see switch connections in stack management must be activated when creating. Then open the stack name under My Products > Switches > Switches. Stack management shows Stack, Parent, Switches, Sync pending and Sync failed. Under Edit Stack you can control the parent site, name, location, description and members.
Evaluate System Details and resiliency
The System Details tab shows port configuration, connections and Overall Stack Resiliency. The total value takes into account:
- Speed of stack connections and use of LAG interfaces;
- Connection topology including loops and WAN reachability;
- the lowest resiliency value of the stack members.
The display is based on the last known status and updates approximately every 90 seconds. If a switch is powered off or cannot reach Fusion, a physical topology change remains invisible until the device communicates again. Drag-and-drop only changes the visualization, not the cabling.
For each connection, Fusion calculates a value based on link speed, Rx Rate, Tx Rate and port utilization:
- Green: below 75 percent of maximum capacity;
- Orange: between 75 and 90 percent;
- Red: above 90 percent.
Hover over the symbol on the connection line to see Link speed (Gbps), Rx Rate (Kbps) and Tx Rate (Kbps). Red is a capacity signal, not automatic evidence of a broken link. According to the analysis, possible separate network changes include LAG, an SFP port or a port with higher throughput.
Name, Serial no., Model, Resiliency and State are displayed per member. Show more complements MAC address, IP address, Firmware version, Tags, Powered on and Location. Membership value takes connection to Fusion and firmware availability status into account. Therefore, always evaluate topology, link data, member status and queue together.
Stack ports are subject to the same risks of mixed 8, 24, and 48 port models as sites. Only use Select the same ports on all switches if the cabling is proven to be uniform, otherwise Select individual ports on each switch.
Move and perform mass actions safely
Move switch or stack
- Document the target parent and its effective configuration.
- Capture switch level exceptions, local CLI deviations, open queue requests, and management uplinks on the source object.
- Mark only one pilot switch. For individual devices, after selecting sites and stacks, use Move > Select switches, select target site or target stack and click Save. Once selected, a complete stack can be assigned to a new site with Move.
- Note that Fusion clears switch level settings and applies target inheritance; check the described Not set exception separately.
- Observe Task queue until the final state and test the management and data path.
- Only then move to the next clearly defined group.
Synchronize and Run commands in bulk mode
When selecting a site, stack, or multiple switches, the action applies to all selected devices. Before the second click on Synchronize or before Execute therefore:
- Expand selection and count serial numbers;
- Remove offline devices, uplinks and critical locations from the wave;
- Record change window, pilot, termination criteria and responsible persons;
- with CLI check exactly one command per line;
- Pay attention to the order: Fusion executes the commands individually for each device in the order entered;
- take into account that CLI changes are not reflected in Fusion;
- Do not modify the same entity in parallel via UI, CLI or local web interface after startup.
Validate end-to-end
A change is only complete when the control level and the real network function match:
- Assignment: Tree view shows site, stack and switch under the intended parent; Serial number and location are correct.
- Fleet status: No unexpected Out of sync, Manual synchronization needed, license or firmware blocker.
- Queue: All tasks associated with the change identified using Entity, Action, Created by and Created at; expected tasks are set to Success. Tasks that were intentionally left Skipped are documented as deviations.
- Configuration: Configuration source corresponds to the intended owner. Randomly check critical ports, VLANs, uplinks, routes and security values on the correct model.
- Communication: Last event is current; no new warning; Management access is retained.
- Stack health: members and LLDP/STP connections visible, no unexplained topology change, Overall Stack Resiliency and link colors plausible. After offline phases, wait for at least the next communication cycle.
- Data path: A test client receives the expected IP configuration on the affected access port and reaches DNS, gateway and shared internal and external destinations. Test uplinks and redundancy paths separately.
- Monitoring: Recheck queue and alerts during the agreed follow-up window before the next wave begins.
Troubleshoot specific errors
Waiting or Pending remains stuck
- Check the serial number, last event time and accessibility of the switch.
- In Task queue open the oldest unsuccessful task and its Entity.
- Include previous Failed, Skipped or Suspended tasks.
- Do not create multiple identical changes. First fix communication or dependency, then synchronize specifically or use Retry.
Out of sync
- Compare Configuration source, the parent, and the latest local or CLI change.
- Note that local and CLI changes may be missing from Fusion.
- Determine the technical target state before one side wins.
- Preserve the evidence; if the impact is unclear, do not apply Reapply all settings indiscriminately.
Manual synchronization needed or Failed
- Open failed queue line via Entity and log exact error, time, creator and serial number.
- Check license status, firmware blockage, last communication and previous tasks.
- Fix the cause and only repeat the affected task with Retry. Skip only with a documented decision that the change may be omitted.
- Do not use Reapply all settings until full reapplication is enabled and the management path is secured.
Suspended
- If Suspended is in the fleet overview, clarify the subscription status, license allocation or capacity.
- If it appears in Task queue or as the device-specific State, outdated firmware is the blocker. Hand off to the separate firmware update and recovery process; do not improvise here.
Stack topology is missing or appears outdated
- Check whether Turn on LLDP and STP to see switch connections in stack management has been activated on the stack.
- State, check the last event time and Fusion availability of each member.
- If the switch is switched off or disconnected, the last known status can be expected; After reconnection, wait for at least the update in approximately 90-second cycle.
- Examine LLDP/STP detection, physical cabling and port states separately. Drag and drop in the view does not repair the connection.
Sync pending or Sync failed on site or stack increases
- Do not sync the entire group again.
- Isolate affected members using serial number and queue.
- Separate common parent change from device-specific communication or model problem.
- For mixed models, check whether a common port selection targeted non-existent or differently numbered ports.
After Move the configuration is unexpected
- Check target parent, deleted switch level settings and Not set exception against the before documentation.
- Do not move another wave of switches.
- Back up the management and data path, then restore the authoritative target state in a controlled manner at the parent or switch level and fully validate the queue.
Handovers outside of this runbook
- Firmware too old or firmware-related Suspended: passed to the separate firmware update and recovery process with maintenance window, compatibility and fallback check.
- Switch removal from Sophos Fusion, site or stack deletion, device replacement or factory reset: submitted to the controlled offboarding/replacement process. These interventions change administration, membership and, if necessary, local settings.
- If a site or a stack has to be dissolved organizationally, record the target assignment and the status of the option Clear the Sophos Fusion configuration … before handover.
- When a site is deleted, its members are always moved to the Default site.
- When a stack is deleted, its members are always moved to its parent site.
- If Clear the Sophos Fusion configuration … is enabled, Fusion clears the local switch settings. The switches then inherit the configuration of the respective target site.
- The Clear option means clearing the local switch settings, not clearing “local Fusion settings”.
- Without the Clear option activated, it must be checked in the specific change which configuration remains effective. This should not be inferred from the move to the target site alone.