Configure Sophos Switch Layer 3 interfaces and static routes
An interface network and a route entry are two necessary, but not final, building blocks of Layer 3 connectivity on a Sophos switch: Under Switch > Networks > IPv4 or Switch > Networks > IPv6 the switch receives an address on a VLAN interface. Under Switch > Routes > IPv4 or Switch > Routes > IPv6 it is determined via which gateway target networks that are not directly connected can be reached. The switch automatically adds routes for new VLANs; additional paths are recorded as static routes. In order for transit traffic to actually work, the next hop must also be accessible via the intended interface, there must be a return path and the applicable forwarding/ACL policy must allow the planned traffic.
The safe process is therefore to document the current state; check the VLAN, next-hop reachability, return path, and applicable forwarding/ACL policy; configure the interface network first; verify the automatically added route; and only then add any required static routes. Changes to the interface or policy through which administration runs require a maintenance window and an independent management path; administrative traffic must remain expressly permitted before and after the change.
Requirements and change plan
Before configuration, record the following values for each IP family:
| Area | To be documented |
|---|---|
| VLAN interface | VLAN ID, previous and new switch IP address |
| IPv4 | Subnet mask, gateway, primary and secondary DNS server |
| IPv6 | Prefix length, gateway, primary and secondary DNS server |
| Static route | Destination address, subnet mask or prefix length, gateway and intended interface/VLAN |
| Return path | Route from the destination network back to the test source network |
| Forwarding | Applicable forwarding/ACL policy and authorization of the planned transit traffic |
| Operation | Management path, maintenance window, test sources and rollback values |
In addition, it must be checked:
- The VLAN exists and is transported correctly tagged or untagged on the uplink.
- The planned switch address is free and is in the intended subnet or prefix.
- The gateway can be reached from the associated interface network. A gateway in another, unreachable network cannot forward the traffic.
- Destination network and prefix do not unintentionally overlap with existing networks.
- The remote station knows the way back. An existing outbound route alone does not prove end-to-end connectivity.
- The applicable forwarding/ACL policy allows planned transit traffic between the affected source and destination networks. If this policy is managed separately, its release must be confirmed before the route is created; a visible route and an accessible next hop alone do not prove forwarding.
- Existing and intended management traffic is not blocked by any forwarding/ACL change. An independent management path remains available until management and traffic are confirmed after the change.
- A second administration connection, local access or person on site is available in case the management IP is changed.
Documented limit: A maximum of four VLAN interfaces including the default VLAN can receive a static IP address. This limit applies across the statically addressed VLAN interfaces and must be checked before further assignment.
Record existing networks and routes
- Open the desired switch in Sophos Fusion.
- First open Switch > Networks > IPv4, then Switch > Networks > IPv6.
- For each relevant entry, document VLAN, IP address, Subnet, Network details and Configuration source.
- Under Network details in particular record the gateway, primary and secondary DNS servers and existing tags.
- Check Switch > Routes > IPv4 and Switch > Routes > IPv6 separately.
- For the affected routes, note Destination, Subnet, Gateway, Interface, Protocol and Configuration source.
The network views can display both networks discovered dynamically through DHCP and networks added manually. Configuration source shows their respective origins. Before edit or Delete it must therefore be checked whether the selected network entry was discovered by DHCP or configured manually; its mere display in the table does not constitute manual configuration.
The origin is also crucial in the route views: the route table contains both entries automatically created by the switch for new VLANs and entries added manually. A displayed entry must therefore not be treated as a manually configured static route simply because of its presence. Before each change or deletion, the details and Configuration source are checked.
The inventory also serves as the rollback template. Screenshots alone are not sufficient when prefixes are similar; addresses, masks or prefix lengths, and gateways are also recorded as text in the change ticket.
Add IPv4 interface network
- Open Switch > Networks > IPv4.
- Select Add network.
- Enter the intended VLAN and the IPv4 address of the switch.
- Enter the correct IPv4 subnet mask under Subnet.
- Enter the gateway and primary and, if provided, secondary DNS server according to the change plan. Tags are informational and should clearly identify the location or purpose.
- Before saving, check again whether this entry complies with the limit of four statically addressed VLAN interfaces including the default VLAN.
- Save the change and wait for processing.
- Open the entry again under Switch > Networks > IPv4 and compare VLAN, IP address, Subnet, Network details and Configuration source with the plan.
- Under Switch > Routes > IPv4 check whether the route automatically created by the switch for the new VLAN is displayed with the expected destination, subnet and interface.
If the current management address is replaced, the old configuration must not be deleted prematurely. First, the new management path must work from a system in the appropriate network. If parallel entry is not possible due to the four-interface limit, the change is only made in the maintenance window with local or otherwise independent access.
Add IPv6 interface network
IPv6 is managed separately; a working IPv4 configuration therefore does not confirm IPv6 reachability.
- Open Switch > Networks > IPv6.
- Select Add network.
- Enter the VLAN and IPv6 address of the switch.
- Enter the intended IPv6 prefix length under Subnet.
- Enter the IPv6 gateway and the primary and optionally secondary DNS server according to the plan.
- Check the limit of four VLAN interfaces with static IP addresses including default VLAN.
- Save and completely check the resulting entry under Switch > Networks > IPv6.
- Check under Switch > Routes > IPv6 whether the expected automatic route with the appropriate prefix and interface exists for the new VLAN.
- Perform validation with IPv6-capable source and target systems. Hostnames are only a supplementary test because DNS and routing failures have different causes.
With dual stack, IPv4 and IPv6 are treated as two separate test cases. Gateway and DNS addresses must match the selected IP family.
Change existing interface network
- Depending on the IP family, open Switch > Networks > IPv4 or Switch > Networks > IPv6.
- Clearly identify the affected entry based on VLAN and address.
- Open via edit.
- Change only the values approved in the change request.
- Before saving, check impact on management access, gateway reachability, DNS and existing static routes.
- Save and then check the network and route table again.
If the address, subnet mask or prefix length changes, a previously accessible gateway and static routes pointing to it may become invalid. Such dependent routes are inventoried in advance and checked after the interface change has been confirmed.
Before each static IPv4 or IPv6 route, the intended interface, the accessibility of the next hop, the return path and the release of transit traffic must be confirmed by the applicable forwarding/ACL policy. The policy check also includes the protection of the current and the intended management path.
Add static IPv4 route
A static route is only created when the intended VLAN interface exists and its gateway is reachable.
- Open Switch > Routes > IPv4.
- Check whether the destination is already covered by an existing entry.
- Select Add route.
- Fill out the mandatory fields displayed in Add route according to the approved IPv4 routing plan.
- Save the route.
- Check Destination, Subnet, Gateway, Interface, Protocol and Configuration source in the route table.
- Test accessibility from at least one relevant source network and verify the return route.
Add static IPv6 route
- Open Switch > Routes > IPv6.
- Check whether the destination prefix is already covered by an existing entry.
- Select Add route.
- Fill out the mandatory fields displayed in Add route according to the approved IPv6 routing plan.
- Save.
- Check Destination, Subnet, Gateway, Interface, Protocol and Configuration source in the table.
- Carry out an IPv6 test without DNS and then optionally a test using a resolvable host name.
The gateway must be accessible via the intended IPv6 connection. A syntactically valid but unreachable next hop does not create a functioning route.
Change existing static route
- Depending on the IP family, open Switch > Routes > IPv4 or Switch > Routes > IPv6.
- Clearly identify the route using Destination, Subnet, Gateway, Interface and Configuration source and compare it with the change ticket.
- Open the intended entry via edit.
- Change only the fields shown in the form and approved in the change request.
- Save and wait for the change to be processed.
- Retrieve the route table again and compare Destination, Subnet, Gateway, Interface, Protocol and Configuration source with the released routing plan.
- Check the affected target network, its return path and at least one explicitly unaffected target.
Before changing the destination, subnet or prefix, or gateway, check for overlaps and verify that the new next hop is reachable. Keep the previous values documented for rollback.
Securely delete route or network
Delete static route
- Depending on the IP family, open Switch > Routes > IPv4 or Switch > Routes > IPv6.
- Check destination, subnet or prefix, gateway, interface and Configuration source against the change ticket.
- Select the exact entry and click Delete.
- Wait for processing, retrieve the route table again, and ensure that only the intended path was removed.
- Only test affected and expressly unaffected destinations after this confirmation.
Before deletion, alternative accessibility and return routes must be clarified. Entries automatically created and manually configured for a VLAN are not deleted based on guesswork; the displayed details and Configuration source are decisive. Whether the change has been processed is confirmed by retrieving the route table.
Delete interface network
- First capture all static routes that use the affected VLAN interface or its gateway.
- Check management access and alternative paths.
- Depending on the IP family, open Switch > Networks > IPv4 or Switch > Networks > IPv6.
- Select the intended entry and click on Delete.
- Then check in the corresponding network and route view which entries have been removed.
- Test accessibility via the remaining interfaces.
Deleting a network removes its managed interface settings. A management VLAN is therefore never deleted without a confirmed replacement path.
Validate reachability
After each individual change, a check is carried out before the next step follows:
- Configuration check: Are the VLAN, IP address, mask or prefix length, gateway, DNS and Configuration source correct under Switch > Networks > IPv4 or Switch > Networks > IPv6?
- Route check: Are the destination, subnet or prefix, gateway, interface, protocol and Configuration source correct under Switch > Routes > IPv4 or Switch > Routes > IPv6?
- Local test: Is the new switch address reachable from the same VLAN?
- Gateway test: Is the configured next hop accessible via the intended interface?
- Routing test: Is an IP address in the target network reachable from a relevant source network?
- Return path test: Does the response reach the source network? If the return path is asymmetrical or missing, the outward path may look correct even though the end-to-end test fails.
- Policy test: Does the applicable forwarding/ACL policy allow the planned transit traffic without blocking the current or intended management path?
- DNS test: Do the configured DNS servers resolve required names? Beforehand, the same path is tested with an IP address so that DNS and routing can be assessed separately.
- Dual-stack test: Test IPv4 and IPv6 independently; the success of one family says nothing about the other.
- Management test: Management via Sophos Fusion and intended administrative access remain available.
When there are multiple static routes, the specific affected target networks are tested individually. A successful connection to any other network does not confirm that the new route can be used.
Rollback
A rollback is triggered when management access becomes unstable, the gateway or destination network is not reachable, or the table values differ from the released plan.
After adding a route
- Identify the newly created route under Switch > Routes > IPv4 or Switch > Routes > IPv6 using all displayed fields.
- Select the entry and click Delete.
- Check that the previous table status has been restored.
- Retest original reachability.
After changing a route or network
- Open the affected entry via edit.
- Re-enter all previously documented values.
- Save and check the corresponding network and route view.
- Repeat management, gateway, target network and DNS tests.
After adding an interface network
- First remove all additionally created static routes that depend on this interface or gateway.
- Then select the newly added network under Switch > Networks > IPv4 or Switch > Networks > IPv6 and click on Delete.
- Compare network and route table against the initial state.
If the removed or changed address was the only management path, recovery occurs via the prepared independent access. Without this access, no further remote changes will be attempted.
Troubleshooting
The network cannot be added
- Count the number of statically addressed VLAN interfaces; the default VLAN counts towards the limit of four.
- Check whether VLAN and address already exist.
- For IPv4, check subnet mask, for IPv6 check prefix length.
- Check the Configuration source of an existing entry before changing or deleting it.
The automatic VLAN route is missing or unexpected
- Check under Switch > Networks > IPv4 or Switch > Networks > IPv6 whether the interface network was actually saved.
- Check that the IP family and VLAN are correct.
- Under Switch > Routes > IPv4 or Switch > Routes > IPv6, compare the destination, Subnet, Interface, Protocol, and Configuration source.
- Don’t rush to create a duplicate manual entry. First correct the interface configuration or wait for the change to be processed and check again.
The static route is visible, but the destination cannot be reached
- Check the destination address and subnet mask or prefix length for typos.
- Make sure that the displayed Interface leads to the gateway.
- First check the gateway from the directly connected network. An invalid or unreachable next hop prevents the routed connection.
- Check VLAN transport on the uplink and remote station.
- Check whether the applicable forwarding/ACL policy allows transit traffic for the affected source and destination networks.
- Check the return route, filters, and host firewall at the destination.
- Examine IPv4 and IPv6 error patterns separately.
The IP connection works, but name resolution does not
- In the entry under Switch > Networks > IPv4 or Switch > Networks > IPv6 in Network details check the primary and secondary DNS servers.
- First test the DNS server directly via IP.
- Check whether there is a suitable route and a return path for the DNS server’s network.
- Test the name resolution separately. The static route itself is based on destination addresses and is not confirmed by a successful DNS test.
Access lost after an interface change
- Do not make any further changes over the same broken path.
- Use independent management access or local support.
- Restore previous IP address, mask or prefix length, gateway and DNS values from the rollback template.
- Then check whether dependent static routes point to an accessible gateway again.
After deletion, another network is no longer accessible
- Check whether the deleted route was also required as a path for this network or whether a summary prefix was affected.
- Compare the logged initial state with Destination, Subnet, Gateway, Interface, Protocol and Configuration source.
- Re-create the entry only with the exact documented values; do not add undocumented settings.
The change is only completed when the table status, management access, forwarding/ACL policy, both IP families used, target networks, return routes and DNS have been validated according to the change plan and documented in the ticket.