Skip to content
Avanet

Register a Sophos Switch in Sophos Fusion

A Sophos Switch can be managed locally via web interface and CLI or centrally via Sophos Fusion. Registration requires a working IPv4 configuration, DNS, Internet access and access to the required target domains. Registration and licensing are technically separate: the Switch can be registered without a valid subscription, but management and changes via Sophos Fusion require a Sophos Switch Support and Services subscription.

After powering on or restarting, 15 minutes remain to register the switch in Sophos Fusion, so prepare network, tenant, and assignment before you start this window.

Objective and stop conditions

At the end, the switch appears under My Products > Switches > Switches with the correct serial number and the intended site or stack reference. The technical target state is Synchronized; the support subscription must also be valid for operational acceptance. DHCP lease or static management address, DNS resolution and outgoing connections must continue to function.

Do not begin the technical registration while any of the following points remain unresolved:

  • Serial number, target tenant or intended site or stack are unclear.
  • The switch does not receive a suitable management address or does not reach its default gateway.
  • IPv4 DNS requests do not work.
  • A firewall, proxy or SSL/TLS inspection blocks necessary targets.
  • The effects of the default template on the pilot switch are not clarified.

Confirm the subscription in advance

The hardware purchase includes the local web interface and the CLI. A Sophos Switch Support and Services subscription for each switch used and managed via Sophos Fusion additionally unlocks the following services:

  • Management via Sophos Fusion, including ports, VLANs, configuration and status,
  • firmware updates,
  • 24/7 multichannel support,
  • Advanced RMA.

Without a valid subscription, the switch continues to operate and remains locally manageable, but changes through Sophos Fusion are not possible. If too few subscriptions are available, Sophos Fusion displays Oversubscribed; you must purchase the shortfall. No subscription, Expired subscription, and Suspended are also invalid acceptance states. Activate and manage the license under Profile icon > Licensing.

Keep these issues separate during diagnosis: a locally accessible switch that forwards traffic does not prove that Fusion management is licensed. Conversely, a license does not resolve DHCP or DNS problems or unblock destinations.

Preparation

Before cabling the switch, record its model, serial number, and location, as well as the intended tenant, site, or stack, in the change record. Also record:

  • the previous management IP configuration if the switch is not factory-new,
  • management VLAN, DHCP scope or static address, subnet mask, default gateway and DNS server,
  • upstream firewall, proxy, and SSL/TLS inspection rules,
  • existing local configuration and reachable local administrator access,
  • the maintenance window, abort time, and responsible person.

Start with a pilot switch. Limit temporary allow rules to the documented destinations instead of creating unrestricted Internet access. If you need a proxy or inspection exception, record both the previous state and the required final state.

Required domains

The switch must be able to resolve and reach the following FQDNs. A static IP record does not replace DNS.

Management and registration

PurposeDestination to allowEffect if blocked
Sophos Fusion managementfusion.sophos.comNo reliable connection to central management
Sophos services*.apu.sophos.comRequired Sophos services are not accessible
Initial registrationsophos.jfrog.ioSwitch cannot be registered in Sophos Fusion
Checking the current firmwarejfrog-prod-use1-shared-virginia-main.s3.amazonaws.comSwitch cannot verify the current firmware version

Region-specific configuration backups

The appropriate destination for the data region must be reachable:

tf-cswitch-backup-config-dump-eu-west-1-prod-bucket.s3.eu-west-1.amazonaws.com
tf-cswitch-backup-config-dump-eu-central-1-prod-bucket.s3.eu-central-1.amazonaws.com
tf-cswitch-backup-config-dump-us-east-2-prod-bucket.s3.us-east-2.amazonaws.com
tf-cswitch-backup-config-dump-us-west-2-prod-bucket.s3.us-west-2.amazonaws.com
tf-cswitch-backup-config-dump-ap-south-1-prod-bucket.s3.ap-south-1.amazonaws.com
tf-cswitch-backup-config-dump-ap-northeast-1-prod-bucket.s3.ap-northeast-1.amazonaws.com
tf-cswitch-backup-config-dump-ap-southeast-2-prod-bucket.s3.ap-southeast-2.amazonaws.com
tf-cswitch-backup-config-dump-sa-east-1-prod-bucket.s3.sa-east-1.amazonaws.com
tf-cswitch-backup-config-dump-ca-central-1-prod-bucket.s3.ca-central-1.amazonaws.com

Where security policy permits, you can allow the prefix tf-cswitch-backup-config-dump together with the domain amazonaws.com by using a wildcard or regular expression. A blanket rule for *.amazonaws.com is not required.

The manufacturer’s requirements specify FQDNs but no nonstandard ports. Do not open arbitrary additional ports. If filtering causes a problem, review the DNS, proxy, inspection, and firewall logs instead of broadly relaxing the egress policy.

Local bootstrap

All Sophos Switch models use the management address 172.16.16.239 in their initial state. For first-time local access:

  1. Connect the power cable, turn on the switch, and verify that the power LED is lit.
  2. Wait for the full start; it may take a few minutes.
  3. Connect a computer directly to an Ethernet port of the switch.
  4. Temporarily give the computer a free static address in the network 172.16.16.0/24, for example:
    • IP address: 172.16.16.200
    • Subnet mask: 255.255.255.0
  5. Enter 172.16.16.239 in a browser. The sign-in page appears.
  6. Log in with username admin and the current device password. The factory password is on the sticker on the back.
  7. Change the default password in a controlled manner or create a dedicated administrator account. Store the new credentials securely.
  8. Switch to Configure > System settings > IP address settings and open IPv4 management.

Variant A: DHCP

  1. Under Configuration, select the DHCP option.
  2. Save with Apply.
  3. Connect the switch to the intended management network.
  4. In the DHCP server, determine and document the assigned IP address on the basis of the MAC address or the new lease.
  5. Check that the lease, subnet, default gateway and DNS server correspond to the planned management network.
  6. Reopen the local web interface via the assigned address.

DHCP alone is not enough: the assigned DNS resolver must be able to answer the required public FQDNs via IPv4, and the default gateway must route the outbound traffic.

Variant B: Static IPv4 address

  1. Under Configuration, select the Static option.
  2. Complete the following fields:
    • Address: reserved management IP of the switch,
    • Subnet mask: mask of the management network,
    • Default gateway: router address of the management network,
    • DNS server 1: primary DNS resolver,
    • DNS server 2: optional secondary DNS resolver.
  3. Save with Apply.
  4. Connect the switch to the intended management network.
  5. Reset the admin computer to its original network configuration.
  6. Reopen the local web interface via the new static address.

Before selecting Apply, make sure that the static address is not already in use. If the interface is then unreachable, first check the administrator computer, VLAN, subnet, gateway, and documented address; do not immediately perform a factory reset.

Check the network before the 15-minute window

Complete the following points before the planned restart:

  1. In DHCP or IP address management, check that the management address is stable.
  2. On the DNS resolver used, test the resolution of all FQDNs required for the region.
  3. Search for the Switch IP in firewall and proxy logs and ensure that none of the required domains are blocked or modified by an inappropriate SSL/TLS inspection.
  4. Under Profile icon > Licensing check whether the support and services quantity is sufficient for the already registered and the newly added switches.
  5. Have the intended site or stack ready in Sophos Fusion. If you select neither, Sophos Fusion applies the default template.
  6. Have the serial number ready to paste. When adding multiple switches, enter exactly one serial number per line.

For 2.5, 5, or 10 Gbps ports, also verify that the existing cables and network components support the intended speed. This does not affect serial-number registration, but it prevents an unstable link from being mistaken for a registration fault.

Registration in Sophos Fusion

The exact path is My Products > Switches > Switches > Add switches.

  1. Open Add switches before the time window is started.
  2. Connect the switch to the management network and thus to the Internet.
  3. Turn on the switch. If it’s already on or the 15-minute window is unclear, do exactly one planned restart.
  4. You have 15 minutes from this startup to complete registration.
  5. Enter the serial number in Step 3. For a controlled pilot, register only the prepared switch; for an approved bulk registration, enter one serial number per line.
  6. Select the prepared site from the drop-down menu. Use the arrow next to a site to select one of that site’s stacks.
  7. Check the selection, serial number and tenant again.
  8. Click Register.

If you select neither a site nor a stack, the switch receives the default template. This is not a neutral state: its settings can be applied to the switch after registration.

Check registration and synchronization

Check the result under My Products > Switches > Switches. Serial number, model, location and site or stack must match the change. Check also the firmware version, the local management access via the documented IP address and the two crucial status values:

  • The support status shows a valid subscription.
  • The connection and configuration status reaches Synchronized.

No new error HTTP: 000 may appear in the switch log; firewall and proxy logs may not show blocked connections to the required FQDNs.

During synchronization, these states may appear:

StatusMeaning and response
Waiting for syncFusion changes are waiting for transmission; connectivity continues to be observed.
PendingSettings have been sent, Fusion is waiting for confirmation.
SyncingSynchronization is in progress; do not interrupt it by restarting the switch.
Out of syncThe switch has unsynchronized settings; do not queue further changes until you identify the cause.
Manual synchronization neededAutomatic synchronization failed; check details in the task queue.
Firmware too oldA newer firmware has been available for more than 180 days. Fusion blocks policy pushes until the firmware has been updated.

Local changes are not automatically reflected in Sophos Fusion. After successful onboarding, do not configure the switch locally and in Fusion in parallel. Synchronized confirms the cloud connection and configuration synchronization; only a separate, approved functional test confirms the intended data-path configuration.

Error DOWNLOADER error Failed to download the package. HTTP: 000

The entry

DOWNLOADER    error    Failed to download the package. HTTP: 000

In this workflow, the entry indicates that the switch could not reach one of the registration destinations. 000 is not a regular HTTP status returned by a web server. Do not conceal the error with repeated registration attempts.

Check in this order:

  1. Time and Source IP: Record the exact error time and the current management IP of the switch.
  2. Addressing: Check the DHCP lease or static address, subnet mask, and default gateway.
  3. DNS: Resolve sophos.jfrog.io and jfrog-prod-use1-shared-virginia-main.s3.amazonaws.com through the exact DNS servers assigned to the switch.
  4. Firewall and proxy: Filter the logs by source IP and both FQDNs. Blocking sophos.jfrog.io prevents registration; blocking the S3 destination prevents the current firmware version from being checked.
  5. SSL/TLS inspection: Check whether inspection, certificate substitution, or authentication rejects the device’s access. Configure only the necessary, documented exception.
  6. Other Sophos Targets: Also check fusion.sophos.com and *.apu.sophos.com for resolution and allowed outbound access.
  7. Regional backup domain: For complete Fusion functionality, check the backup destination for the data region. Successful registration alone does not prove that this destination is reachable.
  8. Only after correcting the issue, start a new registration cycle.

A broad “allow any” test is acceptable only if it is strictly time-limited, restricted to the individual switch IP, and recorded in the change. After the test, replace it immediately with the FQDN allow rules listed above. If HTTP: 000 persists, retain the DNS responses, firewall or proxy decision, switch log, timestamp, model, serial number, and firmware version for escalation.

Clearly limit repetitions, restart and reset

Sophos specifies no numerical maximum for registration attempts. However, each startup has a strict limit:

  • Each boot or restart opens a 15-minute registration window.
  • If the switch is not registered after 15 minutes, it must be restarted and the registration process restarted.
  • Clicking on Register outside the window does not replace the restart.
  • A re-registration attempt requires only a restart, not a factory reset.

Therefore, make no more than one repeat attempt after you have demonstrably corrected the cause. If that attempt also fails, do not continue in a restart or reset loop. Reassess the logs and network path and escalate the case if necessary.

Also, do not restart with Pending, Syncing or a running firmware activity, these states are not a request to reopen the 15-minute window.

Return

Go back depending on the status reached.

Before successful registration

  1. Stop further attempts and disconnect the switch from the production uplink if necessary without interrupting the power supply during a recognizable write or update process.
  2. Return the admin computer to its original DHCP or static configuration.
  3. Only the management addressing was changed, log in locally via the last documented address and restore the previous DHCP or static configuration.
  4. Remove temporary wide firewall, proxy or inspection exceptions; reset existing rules to their documented baseline state.
  5. Document the error pattern, logs and dismantling carried out. The boundary from the previous section applies to restart and reset.

After successful registration

Do not try to “undo” a successful registration with an unplanned reset. Fusion may already have transferred the default template or the selected site or stack configuration. Therefore:

  1. Do not send any further fusion changes and do not force manual synchronization.
  2. Document the switch, serial number, tenant, site or stack, status, and applied template.
  3. If the effect on the data path is possible, take the pilot switch from the production path in a controlled manner or wire it back to the pilot connection provided in advance.
  4. Do not remove domains as long as the switch is still managed by Fusion, but replace a temporary rule that is too broad with the exact allowlist.
  5. If a deregistration, a tenant change or a factory reset seems necessary, stop here and use a separately tested process.

Use the local administration route for diagnosis and stabilization as needed. Changes made locally are not synchronized in Sophos Fusion.

Final documentation

Put this information in the change:

  • serial number, model, management IP and DHCP lease or static parameters,
  • DNS servers used and successful resolution of the required targets,
  • allowed domains, including the data region,
  • registration time within the 15-minute window,
  • Tenant and selected site or stack,
  • Screenshot or export of the final status overview,
  • firmware version and any warning Firmware too old,
  • the result of the local access test,
  • removed temporary rules or remaining exact allowlist,
  • If a failure occurs: HTTP: 000 log, firewall/proxy decision and number of controlled restarts.

This allows a later problem to be assigned to local addressing, DNS, domain filtering, registration, licensing or downstream synchronization.