Configure QoS and Storm Control on Sophos Switch
Quality of Service (QoS) decides which traffic leaves a congested switch-port queue first. Bandwidth control sets a fixed ceiling for inbound or outbound traffic. Storm control drops broadcast, unknown multicast, and unknown unicast frames above a threshold. The functions complement one another but are not interchangeable.
First record traffic, markings, and whether Sophos Fusion or the local interface owns the configuration. Define QoS and queue mappings, then roll out port trust, bandwidth limits, and Storm Control gradually; add a policy only when needed. Verify saved values directly and test actual prioritization and thresholds under controlled load.
⚠️ Limits that are too low also drop legitimate traffic. Uplinks and ports for management, access points, phone systems, or servers may represent many devices. Document initial values, change a noncritical test port first, and keep independent management access.
Quick procedure:
- Open My Products > Switches > Switches > [Switch] > QoS in Sophos Fusion.
- Under General settings, set QoS status, Scheduling method, and Trust mode.
- Map CoS mapping and DSCP mapping to your marking design.
- Under Ports, set CoS mapping, then Bandwidth control and Storm control on a test port.
- Only if finer classification is required, add a policy under Policies and bind it to the intended ports or VLANs.
- Check synchronization, Configuration source, markings, throughput, and behavior under controlled load.
Which function solves which problem?
| Goal | Function | Important limitation |
|---|---|---|
| Prefer voice or video during congestion | QoS with CoS/DSCP mapping | Does not create bandwidth |
| Limit a port in either direction | Bandwidth control | A port limit, not a priority guarantee |
| Contain broadcast and unknown multicast/unicast frames | Storm control | Low thresholds drop legitimate frames |
| Match protocol, MAC, IP, VLAN, or service | Policies | Match and binding must select the intended traffic |
QoS becomes visible only when queues compete for the same egress capacity. A bandwidth limit deliberately creates a bottleneck. Storm Control is not a general rate limit: it evaluates its three documented frame classes separately per port.
Prerequisites and change plan
The switch must be registered, reachable, and synchronized with Sophos Fusion.
- License: Changes through Sophos Fusion require a valid Sophos Switch Support and Services subscription for every managed switch. Without it, local management continues but Fusion changes are unavailable. Check licensing and registration before the window; see Register Sophos Switch in Sophos Fusion.
- Permissions and source of truth: The Fusion account must be allowed to change switch settings. Locally, Privilege type: Admin can write; Privilege type: User is read-only. Local changes do not synchronize automatically, so choose one writing interface and avoid parallel changes.
Record the switch, port, VLAN, peer, speed, normal and peak load in both directions; priority applications; observed CoS/DSCP markings and intended queue; current status, scheduler, trust mode, all weights and port values; existing policies; every Configuration source; a reproducible test flow and baseline; and the maintenance and recovery path.
CoS uses the 3-bit IEEE 802.1p field in a VLAN tag (0–7); DSCP uses six IP-header bits (0–63). Untagged packets have no 802.1p field. Validate tagging and PVID first; see Configure Sophos Switch VLANs safely.
Not set is not an off switch
For global and port QoS settings, Not set means Fusion does not impose the value and the local configuration applies. This covers Status, Scheduling method, port CoS, Trust state, bandwidth, and Storm Control. To enforce a state, select an explicit value and verify Configuration source. Record the local value before overwriting it.
End-to-end example
This is an adaptable test plan, not a Sophos default. Port 12 connects an IT-managed site router that normalizes endpoint DSCP and marks approved voice as 46, other traffic as 0. The flow exits through uplink 48. Measured inbound load is 72 Mbit/s normally, 84 Mbit/s peak, and broadcast peaks at 640 kbit/s. A 100-Mbit/s contracted path needs protection while voice remains usable.
Name the eight UI queues Q1–Q8 locally. Map DSCP 46 to Q7 (“Voice”) and 0 to Q1 (“Best Effort”). As an initial WRR test, give Q7 weight 24 and every other queue 8: a relative 3:1 ratio, not percentages or guarantees. Set port-12 Ingress (kbps) to 92400 (84,000 plus 10% reserve, divisible by 16) and Broadcast (kbps) to 800 (640 plus 25%). Keep the documented initial values for other storm classes. Never copy endpoint values to uplink 48 without separate measurements.
Configure QoS globally
Open QoS > General settings.
1. Select Status and Scheduling method
Choose Enabled for a centrally managed rollout. Disabled disables it; Not set leaves the local value.
- Strict priority: Always serves the highest queue first and can starve lower queues.
- WRR: Weighted Round Robin shares service according to weights. Each of eight queues needs a Queue weight from
0to128;128is highest. Sophos does not document whether0disables, minimizes, or varies by model/firmware. - Not set: Keeps the local scheduler.
WRR is usually the controlled starting point. Give every required queue a weight above 0; use 0 only after model/firmware-specific proof. Test every queue under contention. Use Strict Priority only with bounded high-priority load. For the example use Q7=24, all others=8. Weights are relative, not kbit/s or percentages.
2. Select Trust mode
- DSCP: uses the Layer-3 IP marking.
- 802.1p: uses CoS in the VLAN tag.
- 802.1p-DSCP: translates between Layer-2 and Layer-3 markings when designed to do so.
Use DSCP only with consistently marked traffic from a trusted or separately enforced source. Use 802.1p in a controlled tagged Layer-2 design and translation only as part of a documented end-to-end plan.
⚠️ Sophos documents per-port Trust state only for incoming CoS/802.1p. It is not a per-port DSCP-trust switch. Untrusted therefore does not protect against endpoint-set DSCP. Enforce or normalize DSCP upstream, or do not deploy Trust mode: DSCP on that segment.
The example permits DSCP only because IT manages the router and captures confirm 46 and 0. Save with Update.
Map CoS and DSCP to queues
Capture the marking that actually arrives, map it, save it, and test under contention. Marking alone does not provide priority.
CoS mapping
| CoS | Typical traffic |
|---|---|
7 | Network control, highest priority |
6 | Voice/video signaling |
5 | Voice media |
4 | Video media |
3 | Critical applications |
2 | High-priority data |
1 | Medium-priority data |
0 | Best effort, lowest priority |
This documents typical use, not a recommendation. Capture values from phones, access points, or applications, map only observed values, and select Update. The DSCP example leaves existing CoS mappings unchanged.
DSCP mapping
| DSCP | Typical traffic |
|---|---|
56–63 | Network control, highest priority |
48–55 | Voice/video signaling |
40–47 | Voice media |
32–39 | Video media |
24–31 | Critical applications |
16–23 | High-priority data |
8–15 | Medium-priority data |
0–7 | Best effort, lowest priority |
Prioritize only intentionally assigned values. In the example, captured DSCP 46 maps to Q7 and 0 to Q1. Select Update and trace both to uplink 48. Do not prioritize a whole high category merely because of this table.
Configure ports
Open QoS > Ports and edit a test port first. Measure uplinks independently because they aggregate devices.
1. Set CoS and Trust state
In CoS mapping, choose CoS 0–7; Trust state: Trusted to accept inbound CoS; Trust state: Untrusted not to trust it; or Not set for the local value. Verify Configuration source. Trust only controlled infrastructure whose markings were tested. For an ordinary edge port use Untrusted and the role’s intended CoS. This trust applies only to CoS/802.1p.
2. Set Bandwidth control
Egress (kbps) limits outgoing and Ingress (kbps) incoming bandwidth. Values must be multiples of 16 from 16 through 10,000,000; 0 disables that direction and Not set uses the local value. Derive limits from measurements, above permitted peaks but below protected capacity. In the example set Ingress (kbps): 92400; preserve the initial egress value. Select Update, verify the source, and expand only after a successful test.
3. Set Storm control
Storm Control separately limits inbound Broadcast (kbps), unknown Multicast (kbps), and unknown Unicast (also kbit/s). The abbreviated labels mean unknown multicast/unicast, not all such traffic. Each value is a multiple of 16, from 16 through 10,000,000; 0 disables that class and Not set uses local configuration.
Measure each class, choose a threshold above legitimate peaks, round to a multiple of 16, change one edge test port, select Update, and retest name resolution, DHCP, discovery, and required multicast. Measure uplinks separately. In the example change only Broadcast (kbps) to 800; preserve multicast and unicast values. There is no universally safe low default.
Add a QoS policy only when needed
Under QoS > Policies, protocol-based policies can target ports or VLANs. The example needs none because verified DSCP 46/0 and mapping already classify both flows.
If needed, open Add policy and set only required fields: Class name, Ports binding, source/destination MAC address, source/destination IP address, VLAN and priority, Service with Ethertype and Service Type, Protocol or Custom IANA IP protocol number, and Action plus its value. Ethertype identifies Ethernet payload protocol; Service type uses DSCP. Bind narrowly and verify the offered action rather than copying one from another Sophos product.
Select Save, then verify Ports binding, Binding source, matches, Action, and Configuration source. Open Class name and Save to edit; select and Delete policy to remove.
Validate the effect
1. Check configuration
Verify Status, Scheduling method, eight WRR weights, Trust mode, mappings, each port’s CoS, Trust state, ingress/egress and three storm values, plus Configuration source. For policies verify binding, match, action, and source. After synchronization, reload to exclude stale values.
2. Check marking and queue mapping
Capture packets at a suitable point and compare actual VLAN CoS/IP DSCP with the mapping. A missing source marking cannot be fixed by the queue mapping. For DSCP, deliberately send a high value from an untrusted endpoint; capture before and after normalization and test under congestion. If enforcement does not defeat the attempt, do not deploy Trust mode: DSCP.
3. Test QoS under controlled load
Measure latency, jitter, loss, and throughput without contention, then add controlled best-effort traffic on the same egress and repeat. In the example, captures must show 46 and 0 through uplink 48, mapped to Q7/Q1. Only congestion proves whether Q7=24 protects voice while queues weighted 8 continue receiving service.
4. Test limits and Storm Control
Load one bandwidth direction at a time. The example must show Ingress (kbps): 92400 and the expected source; useful throughput must not exceed the limit and may be lower due to overhead. Never create an uncontrolled production storm. Use an isolated bounded test: legitimate broadcast peaks must work, while load above 800 must be limited. Test ARP, DHCP, DNS, discovery, and production multicast before and after; record drop counters if the model exposes them.
Operations and lifecycle
Review QoS after firmware, topology, or application changes and during the established network review. Record mappings, scheduler and weights; trusted CoS ports and source; DSCP enforcement; measurement and reserve behind every limit; policy owner/match/binding/action/removal date; normal and congestion results; local exceptions and Configuration source. After firmware replacement or upgrade, reread values and repeat affected positive and load tests. Remove obsolete policies or trust exceptions in a controlled change.
Common problems
Voice or video is not prioritized despite QoS
Confirm Enabled, capture the arriving mark, check Trust mode and CoS Trust state or DSCP enforcement, trace the mapping, inspect the scheduler and all eight weights, and ensure the test congests the same egress port.
Low-priority traffic stops completely
With Strict priority, check for a continuously busy higher queue; remove the cause or move to planned WRR. With WRR, compare all weights, replace unproven 0 on required queues, and retest each queue.
Throughput is unexpectedly low
Check whether Ingress (kbps) and Egress (kbps) were reversed, units are kbit/s and values multiples of 16, and local values behind Not set. Restore the documented initial limit and retest. If one class is affected, inspect policy, mapping, and scheduling.
DHCP, ARP, or discovery fails intermittently after Storm Control
The class threshold is probably below a legitimate peak. Restore that class only, retest, measure its peak, and remember that uplinks aggregate devices. Do not raise all three classes together.
A policy misses or captures too much traffic
Compare Ports binding and Binding source with ingress/VLAN; verify source/destination direction, VLAN ID/priority, Ethertype, DSCP Service Type, protocol value, and Custom IANA number against captures; verify action, then narrow one criterion at a time.
Sophos Fusion shows values but behavior differs
Check synchronization and target switch, read Configuration source, and compare every Not set with local configuration. For policies also check Binding source.
Rollback
Reverse the change using recorded values. Not set, 0, and Disabled are not synonyms.
- Remove a new policy with Delete policy, or restore its original match, binding, and action and select Save.
- Under Ports > Storm control, restore only changed classes;
0disables, Not set delegates locally. - Under Ports > Bandwidth control, restore changed Ingress (kbps) and Egress (kbps).
- Restore port CoS and Trust state.
- Restore mappings, Trust mode, Scheduling method, and all weights.
- Restore Status: Disabled centrally disables; Not set delegates locally.
- Select Update (or policy Save) and await synchronization.
- Repeat the original positive tests for management, applications, voice/video, DHCP, DNS, and required multicast.
If a limit disrupts management, stop using that unstable path. Use the independent access and revert the last port value first. Finally verify every Configuration source, intended configuration, normal operation, and controlled-load behavior.