Choose Sophos Switch models and management
A Sophos switch is not selected solely based on the number of its RJ45 ports. What matters are the speeds of the connected devices, the required uplinks, the PoE standard of each consumer, the total PoE budget, as well as space, cooling, and noise at the installation site. Equally important is the operational decision: changes are generally made in Sophos Fusion or directly on the switch. For local management, Web-GUI, CLI, and the device-specific REST API are available; SNMP is an additional local monitoring pathway.
This article distinguishes the eleven documented models from each other and leads to a verifiable selection. The model overview describes the hardware family, but it is not a promise regarding the current availability of a specific model.
Short decision
- Small, quiet 1-Gbit/s access without PoE:
CS101-8. - Small, quiet 1-Gbit/s access with PoE+:
CS101-8FP. - 24 or 48 ports with 1 Gbit/s and 10-Gbit/s uplinks: suitable
CS110variant;PandFPdiffer in the PoE budget, not in the number of PoE-capable ports. - Wi-Fi 6/6E access points or other 2.5 Gbps devices:
CS210; depending on the model, 8 or 16 copper ports support multigigabit. - Up to 10 Gbit/s on all eight copper ports and documented 802.3bt power supply up to the 60 W class:
CS1010-8FP. - Central management, multiple locations or Sophos-wide functions: Make changes in Sophos Fusion.
- Isolated standalone operation or deliberately local administration: Make changes directly on the switch via Web-GUI, CLI, or REST API; SNMP complements monitoring.
- License and service boundary: For switch management with Sophos Fusion, a suitable Switch Support and Services subscription is required for each deployed switch. This also includes firmware updates, round-the-clock support via multiple channels, and Advanced RMA. Support and RMA are services and not management channels “via” Sophos Fusion. Without management through Sophos Fusion, no such license is required for local operation.
Requirements and Planning Data
At least the following information will be collected before ordering:
- Number of copper ports required today and reserve for the planned service life.
- Speed of each device: 100 Mbit/s, 1, 2.5, 5, or 10 Gbit/s.
- Number and speed of uplinks as well as required SFP, SFP+, or DAC connections.
- PoE requirement of each device according to
802.3af,802.3at, or802.3bt, in case of 802.3bt additionally type or power class, and its maximum power consumption. - Total PoE power with operational reserve; the number of PoE-capable ports is not the same as the number of devices that can be powered simultaneously.
- Existing cable category, length, shielding, patch panel, and outlets per section.
- Installation location, rack space, power supply, grounding, cooling, and permissible noise level.
- Number of locations and switches, administrators, desired central view, as well as required Sophos Fusion functions.
For the local GUI, a Windows, macOS, or Linux device is needed, a wired or wireless connection to the same network as the switch, and the individual default password from the sticker on the back. All models have a local GUI.
The eleven documented models in comparison
FP here designates a model with PoE and a higher power budget; P also offers PoE in CS110-48P, but a smaller budget than CS110-48FP. All ports of a PoE model are PoE-capable. The total budget still limits how many devices can be supplied with their requested power at the same time.
Ports and uplinks
CS101-8andCS101-8FP: 8 copper ports with 10/100/1000 Mbps; 2 uplinks with 1 Gbps SFP.CS110-24andCS110-24FP: 24 copper ports with 10/100/1000 Mbps; 4 uplinks with 1/10-Gbit/s SFP+.CS110-48,CS110-48P, andCS110-48FP: 48 copper ports with 10/100/1000 Mbps; 4 uplinks with 1/10-Gbps SFP+.CS210-8FP: 8 copper ports with 100/1000/2500 Mbit/s; 4 uplinks with 1/10-Gbit/s SFP+.CS210-24FP: 16 copper ports with 10/100/1000 Mbit/s as well as 8 copper ports with 100/1000/2500 Mbit/s on ports 17–24; 4 uplinks with 1/10-Gbit/s SFP+.CS210-48FP: 32 copper ports with 10/100/1000 Mbit/s as well as 16 copper ports with 100/1000/2500 Mbit/s on ports 33–48; 4 uplinks with 1/10-Gbit/s SFP+.CS1010-8FP: 8 copper ports with 100/1000/2500/5000/10000 Mbit/s; 4 uplinks with 1/10 Gbit/s SFP+.
PoE
The following information first states the standard and total budget, then the documented maximum number of devices per power class:
CS101-8: no PoE.CS101-8FP: 802.3af/at, 110 W; 7 × 15.4 W or 3 × 30 W.CS110-24: no PoE.CS110-24FP: 802.3af/at, 410 W; 24 × 15.4 W or 13 × 30 W.CS110-48: no PoE.CS110-48P: 802.3af/at, 410 W; 26 × 15.4 W or 13 × 30 W.CS110-48FP: 802.3af/at, 740 W; 48 × 15.4 W or 24 × 30 W.CS210-8FP: 802.3af/at/bt, 240 W; 8 × 15.4 W, 8 × 30 W or 4 × 60 W.CS210-24FP: 802.3af/at, 410 W; 24 × 15.4 W or 13 × 30 W.CS210-48FP: 802.3af/at, 740 W; 48 × 15.4 W or 24 × 30 W.CS1010-8FP: 802.3af/at/bt, 410 W; 8 × 15.4 W, 8 × 30 W, or 6 × 60 W.
Design and cooling
CS101-8: Desktop or wall mounting, fanless.CS101-8FP: Desktop or wall mounting, fanless, external power supply.CS110-24: 1U rack, fanless.CS110-24FP: 1U rack, 2 fans.CS110-48: 1U rack, 1 fan.CS110-48PandCS110-48FP: 1U rack, 3 fans.CS210-8FPandCS210-24FP: 1U rack, 2 intelligent, temperature-controlled fans (Smart Fans).CS210-48FP: 1U rack, 3 intelligent, temperature-controlled fans (Smart Fans).CS1010-8FP: 1U rack, 3 fans.
Limits of the series
- CS101: eight 1-Gbit/s copper ports and two pure 1-Gbit/s SFP ports. These two models do not have an RJ45 console port. They are the only fanless desktop/wall models in the overview.
- CS110: pure 1-Gbit/s copper ports, but four SFP+ ports for 1 or 10 Gbit/s. Only
CS110-24is fanless. 802.3bt is not part of this series. - CS210: 2.5-Gbit/s copper ports and four SFP+ uplinks. Only
CS210-8FPadditionally supports 802.3bt; the 24- and 48-port models provide 802.3af/at. - CS1010: eight copper ports up to 10 Gbit/s, four SFP+ ports, and 802.3bt. It is not a desktop replacement for
CS101, but a 1U rack model with fans.
The rack models have an RJ45 console port. For the serial connection, 115200 bits/s, 8 data bits, no parity, 1 stop bit, and no flow control apply. The CLI can display and configure switch settings and is thus a local management path.
Properly dimensioning ports, uplinks, and cables
Copper links
The negotiated speed can only be achieved if the port, device, the entire permanently installed route, and the patch cables match.
- 100 Mbit/s, 100BASE-T: CAT5e/Class D or better, 100 m.
- 1 Gbit/s, 1000BASE-T: CAT5e/Class D or better, 100 m.
- 2.5 Gbit/s, NBASE-T according to 802.3bz: CAT5e/Class D or better, 100 m.
- 5 Gbit/s, NBASE-T according to 802.3bz: CAT5e/Class D up to 55 m at high and up to 100 m at low crosstalk. With shielded CAT5e/Class D or CAT6/Class E and better, 100 m is possible.
- 10 Gbit/s, 10GBASE-T: CAT6/Class E up to 50 m. CAT6A/Class EA with S/FTP or better quality allows 100 m.
For multi-gigabit routes, tight cable bundles, strong mechanical stress on RJ45 ports, and mixed route qualities should be avoided. Proper shielding, shielded outlets, and patch panels reduce crosstalk. Sophos recommends cables with an Ethernet bandwidth of up to 500 MHz. Before selecting a model, not only the printed cable category but the entire installed route is checked.
SFP and SFP+
CS101 offers two 1-Gbit/s SFP ports. All other models offer four SFP+ ports for 1 or 10 Gbit/s. Required transceivers or DAC cables are not included with the switch and must be selected to match the opposite port, medium, connector type, wavelength, and distance.
An SFP+ port does not make an incompatible transceiver or a faulty fiber optic link compatible. Therefore, before procurement, both sides of the connection and the permissible speed are documented. Never look directly into a powered optical transmit port.
Plan PoE without surprises
For each supplied device (Powered Device), the standard and maximum power consumption from its datasheet are recorded. After that, two independent limits apply:
- Port limit: The switch port must support the required standard, 802.3bt type, and the necessary power class. Only
CS210-8FPandCS1010-8FPare documented with 802.3bt; however, the model specifications only indicate devices up to 60 W for them. Therefore, a 802.3bt label alone is not a guarantee of compatibility. Devices requiring 90 W are not covered by the documented values. - Total Budget: The sum of all simultaneously possible consumers must fit within the switch’s PoE budget. For example, 48 PoE-capable ports on the
CS110-48Pdo not mean 48 simultaneously available 30-W supplies.
The PoE specifications in the model overview are class limits. For mixed devices, the actual maximum requirement is calculated and a reserve for startup peaks, replacement devices, and growth is provided. Access points, cameras, and phones are not generally treated as equally large consumers.
If PoE Max lights up amber permanently, the requested power exceeds the total limit and no further devices can be supplied. On PoE models, the button LED Mode switches the left port LED between speed and PoE display. A green PoE display means that the port is supplying power; an amber display indicates a fault on the CS110-/CS210 PoE models.
The detailed interpretation of mixed PoE loads and the systematic troubleshooting is described in Planning PoE for Sophos Switch and Troubleshooting.
Local administration or Sophos Fusion?
Both paths are possible. Before operation, it is determined whether changes are made in Sophos Fusion or directly on the switch.
Local administration
- Scope: a single switch.
- Access: Web-GUI via the switch IP, CLI via the console or management services such as SSH, and REST API directly on the device.
- Changes: directly on the switch via Web-GUI, CLI, or REST API.
- User:
Adminwith full access orUserwith read access. - Suitable for: deliberately standalone operation and device-specific administration; SNMP complements local monitoring.
Sophos Fusion
- Scope: centralized view and management of multiple devices and locations.
- Access: cloud-based management after registration.
- Changes: central in Sophos Fusion.
- User: Accounts and permissions in Sophos Fusion apply regardless of local accounts.
- Suitable for: identical settings on multiple switches, virtual stacks, and Sophos-wide functions.
⚠️ Important: Changes via Web-GUI, CLI, or REST API are not synchronized with Sophos Fusion. If a switch is managed in Sophos Fusion, production changes must therefore be made there. Local emergency changes are documented and then either replicated in Sophos Fusion or reverted on the switch. Otherwise, the switch and Sophos Fusion show different configurations.
Sophos Fusion offers virtual stacks in addition to central switch management. In this case, switches are managed as a group; the physical connections still use regular Ethernet, SFP, or SFP+ ports and can be designed to be redundant or more powerful with LAG. Active Threat Response is also a Sophos Fusion feature. A Sophos firewall is not required for a Sophos switch for this.
When to manage locally?
Local management is suitable when a single switch is deliberately operated without cloud management, an isolated environment does not allow registration, or local maintenance access is required. In this case, backups, firmware updates, user accounts, and changes for this switch must be maintained and documented individually. The Web-GUI, CLI, and REST API can display and configure settings; SNMP provides additional local monitoring.
The local GUI is accessed via the IP address of the switch. The default address is 172.16.16.239, the username admin, and the individual default password is on the sticker on the back. Upon first login, the GUI requires a password change. The new password must be 10 to 32 characters long, contain at least one letter, at least one number, and at least one of these special characters: @ ~ % * # + - =.
Under People, additional local accounts can be created:
- Admin: is allowed to view and change all switch functions.
- User: may only view settings.
A local admin account can change the password of other accounts, but not the password of the default account admin. This password can only be changed by admin itself or Sophos Fusion. Local accounts are not equivalent to the administrator identities in Sophos Fusion.
The REST API is addressed directly on the individual switch and uses a Bearer-Token generated per session. According to Sophos, it may only be used for configuration or administration by trained personnel. Authentication, token lifecycle, device-related API checks, and secure automation are covered in the guide Manage Sophos Switch via CLI and REST API.
When to use Sophos Fusion?
Sophos Fusion is suitable if multiple switches, branches, MSP customers, or additional Sophos components are to be managed centrally. The serial number alone does not replace network planning or a subsequent functional check. The guide Connect Sophos Switch and register in Sophos Fusion guides you through connection, initial login, registration, and validation.
After the decision, it is explicitly recorded in the operating manual:
- Location for configuration changes:
Sophos Fusionorlokale Verwaltung, - for local administration the allowed configuration paths: Web-GUI, CLI and/or REST API as well as, if applicable, SNMP for monitoring,
- responsible administrator group,
- Management network and allowed access paths,
- Backup and firmware process,
- Exception procedure for local emergency changes,
- Procedure to reproduce local emergency changes in Sophos Fusion or to revert them on the switch.
Practical limits before ordering
- Installation: Only
CS101-8andCS101-8FPare desktop/wall models. All other models are intended for rack use. Their installation must be carried out by qualified personnel and exclusively in an area with restricted access, such as a dedicated technical room or distribution cabinet. Adequate airflow, stable mounting, a grounded rack, the prescribed chassis grounding of the switch, and a power supply suitable for the maximum load are also required. Models with fans should not be placed unchecked in a quiet workroom. - Temperature: The documented operating temperature of all eleven models is 0 to 40 °C. In the closed rack, the actual ambient temperature generated there counts.
- Reset: Pressing Reset for seven seconds resets the switch, including the login password, to factory settings. This is not a normal troubleshooting step and will erase the configuration.
Validate selection and commissioning
Before the purchase
- Each device port is assigned to a specific model port and its speed.
- Uplinks, peer devices, transceivers or DAC cables, and the desired redundancy are defined.
- All PoE consumers are recorded with standard, maximum power, and for 802.3bt with type and power class, and are checked against the documented model limits.
- Port limits and total budget match with documented reserve.
- Cable type, length, shielding, sockets, and patch panel support the target speed.
- For rack models, qualified installation personnel, a restricted-access area, stable mounting, airflow, grounded rack, chassis grounding, and a suitable power circuit are ensured; rack depth and noise are appropriate for the location.
- It is determined whether changes are made in Sophos Fusion or locally; locally permitted GUI, CLI, and API interventions as well as SNMP monitoring are documented.
- Availability, support status, and product lifecycle were checked for the specific part number.
After the installation
- Compare model and serial number with the order and documentation.
- Power must light up green; Fault must be off.
- Check connection status, negotiated speed, and expected VLAN assignment on each occupied port.
- For PoE devices, check supply, negotiated class, and remaining total budget; PoE Max must not light up due to overloading.
- Check every uplink under load in both directions, not just the connection LED.
- Sign in through the established management path and check the model, firmware, management address, and administrator access.
- In local administration, test a
Useraccount with read-only access and a personalAdminaccount with the intended rights. - Make a small, reversible change in Sophos Fusion management and check if the switch adopts the expected state. Do not reconfigure locally in parallel.
- Perform a planned restart during the maintenance window and then check management, uplinks, PoE devices, and end devices again.
Check product life cycle before procurement and contract renewal
This model overview deliberately does not provide end-of-sale or end-of-life dates. Hardware information, documented functionality, commercial availability, and product lifecycle are different statements. Therefore, before new purchases, expansions, and contract renewals, the specific model designation and part number are checked in the Sophos Product Lifecycle Calendar. An older project plan or the mere presence of a model in the technical documentation is not sufficient.
Narrow down typical errors
The local GUI is not reachable
First, check whether the client and switch are using the same reachable network and whether the current switch IP is known. For a switch in factory default state, set up the temporary client addressing for the initial login; the default address of the switch is 172.16.16.239. Then check the connection LED, cable, local client firewall, and any possible IP address conflict. Resetting to factory settings is only justifiable after a backup and deliberate approval, because it deletes the entire configuration and the login password.
The default password does not work
The password is individual for each switch and is on the sticker on the back. Do not use the password from another device. If it has already been changed, use the documented access. For a switch managed by Sophos Fusion, the password can be reset via Sophos Fusion. Resetting to factory settings is not an equivalent procedure to changing the password.
Settings differ between local administration and Sophos Fusion
Stop further changes and compare the local configuration with the configuration in Sophos Fusion. Then determine which version should apply and implement it completely in one place. Do not correct alternately locally and in Sophos Fusion.
A copper connection only reaches a lower speed
Check the port limits of both devices, autonegotiation, and the entire cable run. For 2.5, 5, or 10 Gbit/s, especially check cable length, category, shielding, patch panels, outlets, tight bundles, and crosstalk. For testing, connect the end device directly with a short, known suitable patch cable. If it reaches the target speed there, the installed cabling is the likely cause rather than the switch model.
An SFP or SFP+ uplink does not establish a connection
Check whether both sides support the same speed, whether the correct transceiver or DAC is used, and whether the transmit and receive fiber are correctly crossed. On CS101, the SFP ports are limited to 1 Gbit/s. On the other models, SFP+ supports 1 or 10 Gbit/s, but the counterpart and module must match for this.
A PoE device does not start or restarts
First, compare the required PoE standard, and for 802.3bt also the type and power class, with the model limits documented above. Then check the port status, LED Mode, PoE Max, and the remaining total budget. Do not randomly disconnect other consumers: record their power consumption and recalculate the sum. If the fault exists only over the building cabling, test the cable route, patch panel, and contacts separately.
The switch is too loud at the workplace
Compare the model with the hardware overview. Only CS101-8, CS101-8FP, and CS110-24 are fanless. For a model with a fan, check airflow, temperature, and blocked openings; do not disable or cover the fan. If the location is generally noise-sensitive, the installation site or model choice must be corrected.