Plan and troubleshoot Sophos Switch PoE
Power over Ethernet (PoE) supplies access points, cameras or telephones via the same Ethernet cable as the data connection. However, three limits must be correct at the same time: The switch must support the PoE standard of the powered device (PD), the overall budget must be sufficient for all ports and each port must be able to provide sufficient power.
This runbook separates planning, configuration, and recovery. It applies to the documented PoE-capable Sophos Switch models and uses the labels found in the local switch interface, Sophos Fusion and the CLI. The model specifications describe technical capabilities; they say nothing about availability, delivery status or a current sales portfolio.
Important: Shutting down or resetting PoE will immediately interrupt a connected device. For access points, cameras, telephones or a device in the management path, a maintenance window, alternative access and a return path must therefore be available in advance. Never reset multiple unknown ports at the same time.
Quick procedure
- Determine the model budget, port standard and maximum demand of each PD. Keep the reserved load including operating reserve below the model budget.
- Check the cable run and PD first. Then record the current state and make changes either in Sophos Fusion or locally; do not alternate between the two interfaces.
- First change only one non-critical port. Check the supply, data connection and device service.
- Introduce keepalive first with Syslog. Only allow Reboot with Syslog after a controlled error test and limit reboots.
- Reset PoE only on a confirmed target port, exactly once, with a recovery path prepared.
Models, standards and power budgets
The following matrix lists the values specified in the Sophos documentation. The PoE power budget is the switch’s upper limit across all PoE ports, not guaranteed power per port.
| Model | PoE enabled ports | documented standard | PoE Power Budget |
|---|---|---|---|
| CS101-8FP | 8 | IEEE 802.3af/at | 110 W |
| CS110-24FP | 24 | IEEE 802.3af/at | 410 W |
| CS110-48P | 48 | IEEE 802.3af/at | 410 W |
| CS110-48FP | 48 | IEEE 802.3af/at | 740 W |
| CS210-8FP | 8 | IEEE 802.3af/at/bt | 240 W |
| CS210-24FP | 24 | IEEE 802.3af/at | 410 W |
| CS210-48FP | 48 | IEEE 802.3af/at | 740 W |
| CS1010-8FP | 8 | IEEE 802.3af/at/bt | 410 W |
Sophos documents the supply of IEEE-802.3af/at/bt-compliant devices. A device that requires proprietary or otherwise non-standard PoE may not be considered compatible based solely on a suitable connector. The CLI does provide a Legacy PoE mode for certain legacy devices; this is a targeted exception, not a general guarantee of compatibility.
Size your budget correctly
For each PD, record at least manufacturer, model, required IEEE standard, maximum power requirement, expected typical consumption, port and criticality. Don’t just reserve the currently measured consumption: an access point can require more when starting, with active radio modules or connected USB devices than when idle.
The planning rule is:
geplante PoE-Last = Summe der reservierten maximalen Portleistungen
freie Reserve = Modellbudget - geplante PoE-Last
Set the reserve to suit the location. It must cover planned expansion, startup peaks and the failure of other power sources. Even a generous reserve does not allow the documented model budget to be exceeded.
Calculation example: A CS110-24FP with a 410 W budget should run eight Class 4 devices and eight Class 3 devices. Reserve with the documented class maximums: 8 × 30,0 W + 8 × 15,4 W = 363,2 W. This leaves 410 W - 363,2 W = 46,8 W as a reserve. A lower value read in parallel for Consumed power is only the momentary measurement. 363,2 W remain reserved for planning; the measurement does not justify additional consumers.
Port classes show the maximum power that the Power Sourcing Equipment (PSE) can provide to the detected device:
| Class | documented maximum PSE power |
|---|---|
| Class 0 | 15,4 W |
| Class 1 | 4,0 W |
| Class 2 | 7,0 W |
| Class 3 | 15,4 W |
| Class 4 | 30,0 W |
| Class 5 | 45,0 W |
The class does not indicate the current consumption. To do this, read Mode-A/Mode-B power (W) or Total power output (W) locally or Output power (W) in Fusion.
Check cable runs before troubleshooting PoE
PoE and data rate share the physical path. In addition to the electrical supply, the cable category, shielding, patch panel, connector and the entire channel length must match the negotiated port speed. Sophos recommends appropriate shielding against alien crosstalk, shielded sockets and patch panels, no tight mixed cable bundles and no mechanical stress on the RJ45 ports.
| Port speed | Standard | Cable | maximum documented length |
|---|---|---|---|
| 100 Mbit/s | 100BASE-T | CAT5e, Class D or better | 100 m |
| 1 Gbit/s | 1000BASE-T | CAT5e, Class D or better | 100 m |
| 2,5 Gbit/s | NBASE-T / 802.3bz | CAT5e, Class D or better | 100 m |
| 5 Gbit/s | NBASE-T / 802.3bz | CAT5e, Class D, high alien-crosstalk environment | 55 m |
| 5 Gbit/s | NBASE-T / 802.3bz | CAT5e, Class D, low alien-crosstalk environment | 100 m |
| 5 Gbit/s | NBASE-T / 802.3bz | shielded CAT5e, class D | 100 m |
| 5 Gbit/s | NBASE-T / 802.3bz | CAT6, Class E or better | 100 m |
| 10 Gbit/s | 10GBASE-T | CAT6, Class E | 50 m |
| 10 Gbit/s | 10GBASE-T | CAT6A, S/FTP or better quality | 100 m |
In the event of sporadic PoE failures, test the entire route with a known, good, short patch cable. A link-up or lower negotiated data rate does not prove that the cable is healthy under full PoE load. Also include patch panels and couplings, especially for long or densely bundled cables.
Before the change
Before making a production change, record the values and dependencies needed for comparison and rollback:
- Switch model, firmware version and affected port
- current Total power budget and current total power consumption
- Configuration source of global and port related settings
- Port status, priority, limit type, configured limit, class and output power
- MAC and management IP address of the PD, if visible
- Keepalive mode, target IP, timer, Restart count and last Action taken
- VLAN, link status and reachable management path to PD
- Maintenance window, person responsible and permitted interruption duration
- alternative management path and, for a critical device, an alternative power supply or local access
Local changes on the switch are not synced to Sophos Fusion. Therefore, make changes to a centrally managed switch in Sophos Fusion. If Configuration source shows an unexpected source or conflict, first clarify the cause; do not overwrite local and central values alternately.
In Sophos Fusion, PoE is below Port settings > PoE on the selected switch. Locally it is under Configure > Power Supply. The interfaces sometimes use different labels: Fusion, for example, shows Enable/Disable, Auto/Manual and User power limit (W); On/Off, Autoclass/User defined and User Power Limit (W) appear locally.
Configure PoE budget and ports
Total budget
In Sophos Fusion under Port settings > PoE > Power budget:
- Note the existing value and the Configuration source.
- Enter the planned total value under Total power budget and select Update.
- Check the synchronization and the new value on the switch.
Check the Total power budget and the Consumed power locally under Configure > Power Supply > PoE. A configured threshold does not create additional capacity beyond the documented hardware limit.
Port limit and priority
In Fusion, edit the port under PoE port settings and then select Update. Mark it locally under PoE port settings, select Edit and save with Apply.
- Enabled: Enable or locally Status: On activates LLDP and the power supply at the port.
- Power limit type: Auto or Autoclass allows the recognized class to determine the maximum.
- Power limit type: Manual or User defined uses the set User power limit (W).
- A manual limit must protect the occupied port from overload, but must not fall below the documented maximum requirement of the legitimate PD.
- Priority decides which ports are switched off first when the overall budget is tight; it does not increase the overall budget or the port limit.
The order of priority is:
- Low: will be switched off first in case of shortage.
- Medium: Default; follows after all low ports.
- High: follows Low and Medium.
- Critical: is kept powered wherever possible at the expense of all lower priorities.
Only assign Critical to devices that are actually operationally necessary. If too many ports are critical, prioritization loses its purpose. After saving, test the real PD; a stored value does not yet prove sufficient supply.
Read PoE status correctly
| Status | Meaning | next step |
|---|---|---|
| Searching | default state; the switch is looking for a PD. | Check device, cable, standard and port activation. |
| Delivering | The port supplies power. | Check the output power and function of the device; an application error may still exist. |
| Disabled | PoE is disabled for the port. | Check configuration source and planned state, do not activate blindly. |
| Testing | The switch tests the PD. | Observe briefly and refresh; if the status persists, isolate the cable and PD. |
| Test Fail | The PD failed the test; PoE cannot be turned on or delivered. | Remove PD, check cable, check standard and port limit. |
| Fault | The switch detects an error when forcing the supply, such as voltage out of range, short circuit, or communication error. | Do not force port repeatedly; first isolate PD and wiring. |
In addition, Signature (Single or Dual), Mode-A/Mode-B class, output voltage, output current and power help narrow down the cause. Unexpectedly low power while the status is Delivering may simply indicate normal idle operation; the device specifications and functional test are what matter. Fault or Test Fail is not a reason for a reset loop.
Continuous PoE Power on a switch reboot
The Continuous PoE Power local function reboots the switch while maintaining PoE supply to the PDs. However, it does not prevent interruption of data forwarding during switch restart and does not replace UPS or redundant supply.
Procedure in the local interface:
- Check whether the model supports the function and all devices have a stable supply.
- Document management path and expected data disruption.
- Click on the profile icon and select Continuous PoE Power.
- Select Apply; the switch restarts.
- After returning, check port status, budget, link, VLAN and reachability of all PDs.
The CS101-8FP does not support Continuous PoE Power. For this model, plan a power interruption during a restart or power the PD by other means.
Introduce PoE keepalive safely
PoE Keepalive monitors a PD and can turn its port power off and on again. It is not a substitute for correct monitoring: a ping can fail due to routing, VLAN, ACL, ICMP filtering, boot time or an incorrect IP even though the device is healthy.
In Sophos Fusion the function is under Port settings > PoE keepalive, locally under Configure > Power Supply > PoE keepalive. First switch keepalive globally with On/Off or locally with Turned on/Turned off. Then edit the selected ports under Advanced configuration with Edit and save with Apply.
Modes and fields
- Mode: Auto first checks via LLDP and switches to ping if the PD cannot be reached via LLDP.
- Mode: Force Ping pings the specified device.
- IP address or locally Specified IP address must clearly belong to the PD on the port.
- Ping interval: 1 to 3600 seconds.
- Ping: Maximum number: 1 to 255 consecutive failed attempts before the action.
- Action type: Syslog logs the failure but does not restart the PD.
- Action type: Reboot with Syslog turns PoE off and on again and generates a Syslog message.
- Power recovery interval: 1 to 600 seconds, while PoE remains off during a keepalive reboot.
- Maximum number of restarts: limits restart attempts. If the option is deselected, the switch is allowed to continuously restart an unresponsive PD.
- PoE startup time: 50 to 1200 seconds of waiting time after the reboot before testing begins.
- LLDP retention time: 30 to 600 seconds for retaining LLDP packets.
Always set Maximum number of restarts in the pilot. An indefinite reboot cycle can render a broken or slow-starting endpoint permanently unusable and obscure the cause.
Recommended pilot flow
- Select a non-critical port and confirm its IP/MAC mapping and the ping path from the switch to the PD.
- Start with Syslog, not with an automatic restart. Match Ping interval, failed attempts and PoE startup time to normal packet losses and real boot time.
- Create a controlled outage. Under Status of supplying port, check the values Polling method, Management IP address and Action taken.
- Only after correct detection switch to Reboot with Syslog and set Maximum number of restarts to a limited value.
- After exactly one test restart, check the service, Syslog, Restart count and the last action.
Locally, Refresh updates table Status of supplying port. In Advanced configuration, Refresh can reset the displayed Restart count. Therefore, record the counter beforehand as operational evidence.
Accurate CLI checks and controlled reset
Only use CLI commands if the management path, target port and impact are clear. The documented test commands run in the Privileged EXEC Mode:
show power detail
show power inline
show power inline gigabitethernet 0/1
show power detailshows global PoE admin status, PSE operational status and maximum power supply, among others.show power inlineshows the PoE state of each PSE.show power inline gigabitethernet 0/1limits the output to the example interface0/1. Replace interface type and ID with the real target port. Documented types aregigabitethernetandport-channel; the ID combines slot and port with a slash.
Power-cycle a specific port
The documented reset commands run in the Interface Configuration Mode of the selected port:
power reset interval 10
power reset
In the example, the first line sets the power-off duration to 10 seconds. This CLI command permits 1-300 seconds:
power reset interval <1-300>
power reset
power reset switches the PoE supply off for the interval set with power reset interval and then on again. Before executing, check that the CLI is in the interface configuration mode of exactly the confirmed target port. Do not reset a port channel or multiple ports on suspicion.
Safe process:
- Record the overall status with
show power detail, and the target port’s status and power with the targetedshow power inlinequery. - Match MAC/IP, physical labeling and responsible person. Re-examine the alternative management route.
- Set the interval in the Interface Configuration Mode of the confirmed port and execute
power resetexactly once. - Wait for the documented boot time of the PD; don’t reset again immediately.
- Repeat both
showchecks and test the service externally. If error persists, stop further retries and isolate PD, cable and port.
Other documented PoE commands
The following syntaxes are documented, but not all of them are necessary for troubleshooting:
set poe global power threshold <value>
power inline { enable | disable }
power inline limit { auto | <value> }
power inline priority { critical | high | medium | low }
power legacy mode {enable | disable}
set poe global power threshold <value> runs in Global Configuration Mode and changes the global budget. The other commands run in Interface Configuration Mode. Before making a change, retain the old value and the correct configuration source.
Legacy PoE mode is only available on CS110-24FP, CS110-48P, CS110-48FP, CS210-8FP, CS210-24FP, CS210-48FP and CS1010-8FP according to the CLI documentation. Only activate it for an identified legacy device that is not IEEE 802.3af/at compliant and specifically requires non-standard PoE. Clarify voltage/PoE requirement, manufacturer approval and impact beforehand. The mode remains deactivated for unknown devices.
Troubleshoot systematically
No power, status searching
- Check whether the port in Fusion is Enable or local On and check Configuration source for central/local discrepancies.
- Compare PD requirement and IEEE standard of switch model. Check total free budget and manual port limit.
- Replace the cable run with a short, known good cable.
- Test the same PD on a confirmed suitable PoE port and then a compatible test device on the original port.
This isolates faults in the PD, cable and switch port. Change the configuration only after completing this isolation.
Test Fail or Fault
- Document port status, voltage, current, class and signature.
- Turn off PoE at the port or physically disconnect the PD; do not repeatedly force power delivery.
- Check the line for short circuits, damaged connectors, faulty patch panels and moisture.
- Test the PD with a suitable external supply or on a known good port. Test the original port with a known good cable and a compatible test device.
- If Fault persists without the problematic route, stop using the port and start the hardware/support process.
Device restarts repeatedly
- Check whether Consumed power is close to the total budget and whether low-priority ports are being shut down.
- Compare the port limit with the maximum PD requirement; correct a User power limit (W) that is too low.
- Check keepalive logs, Restart count, Action taken, destination IP, VLAN, ICMP path, LLDP and boot time.
- Temporarily set Reboot with Syslog to Syslog for suspected false alarms. Disable unlimited reboots and set a cap.
- Test cable and PD under load.
Delivering but device or network service not reachable
PoE may work correctly in this case. Check link, speed/duplex, VLAN association, DHCP, gateway, ACL and the service of PD separately. A PoE reset is only justified if a controlled power cycle is agreed as recovery; it does not repair incorrect VLAN or IP configuration.
Total budget is not enough
- Record current port power and configured limits. Reconcile the connected loads with the reserve plan instead of blindly disabling unused ports.
- Prioritize critical devices without setting all ports to Critical. Correct excessive manual reservations using only the PD specification.
- If the planned maximum load and reserve exceed the model budget, distribute the consumers to suitable PSEs or change the power architecture. A higher threshold does not produce additional hardware performance.
Rollback and recovery
If a change unexpectedly shuts down devices or compromises management access:
- Stop further port changes and automatic keepalive restarts. Confirm the last changed port by label, MAC and IP.
- Restore the documented previous value for budget, port limit, priority, or keepalive from the original configuration source. For central management, use Sophos Fusion and wait for the synchronization; avoid local counterchanges.
- For Fault, first disconnect PD or cable. If there is no electrical fault, you can only reset the confirmed port once in a controlled manner.
- If remote access is lost, use the prepared local or alternative management path.
- Check supply, data path and service again. Then log the cause, time, port, status and action.
A Switch reboot is not the first troubleshooting step. If it is still necessary after the configuration has been secured, check the support for Continuous PoE Power. Even with this function, the data connection fails during the restart.
Final inspection
Don’t complete the work until these results are proven:
- Total power budget, reserved maximum load and free reserve correspond to the plan; the model budget remains adhered to.
- Production ports show the planned limit type and correct priority. The PDs are stable on Delivering; Class, signature, voltage, current and power are plausible. Test Fail and Fault do not occur.
- Data link, VLAN, IP reachability and application service are working.
- Keepalive uses confirmed IP/MAC allocation and polling method. The pilot produces the expected Syslog message and never exceeds the set restart limit; Restart count and Action taken are documented.
show power detailand the targetedshow power inlinequery confirm steady state after a CLI change.- Configuration source conforms to the intended management model, without unintentional local deviations.
- Update the documented return path before closing the alternative management path.