Skip to content
Avanet

Configure Sophos Switch VLANs securely

A VLAN design works only when VLAN membership, tagging, and PVID match at both ends of every link. On a Sophos Switch, you can manage these settings centrally in Sophos Fusion or locally on the switch. This runbook covers Layer 2 VLANs only: Tagged and Untagged ports, PVID, GVRP, Voice VLAN, and Ingress Filtering.

Routing between VLANs, Layer 3 switch interfaces, DHCP Snooping, PoE, LAG, and STP are separate topics. The DHCP example therefore shows only the required handoff of a VLAN to a Sophos Firewall and the sequence for creating the VLAN interface and DHCP server.

⚠️ Changes to the uplink or management VLAN can make the switch unreachable from the management system. Before the cutover, ensure that you have a documented recovery path, such as local console access or separate management access. Migrate a test port first and only then migrate additional ports.

Terms: Tagged, Untagged, and PVID

The three settings serve different purposes:

SettingEffect when sending or receivingTypical use
TaggedThe port is a member of the VLAN. Outbound frames retain that VLAN’s 802.1Q tag. Inbound frames with that tag can be assigned to this VLAN.Uplink to the firewall, an access point, or another switch
UntaggedThe port is a member of the VLAN. Frames from this VLAN leave the port without an 802.1Q tag. Only one Untagged VLAN is possible per port.Endpoint without VLAN support
PVIDThe switch assigns untagged frames arriving on the port to this VLAN ID.Access port: normally the same VLAN ID as the Untagged VLAN

An access port for VLAN 100 is therefore normally an Untagged member of VLAN 100 and has PVID 100. A typical client sends untagged frames; the switch internally classifies each frame as VLAN 100 and removes the tag when sending it back to the client.

A trunk port is a Tagged member of every VLAN that must be carried over the link. If the link also permits untagged traffic, its PVID determines the internal assignment. A Tagged VLAN and the PVID are not the same thing: the PVID turns an inbound untagged frame into a frame in a specific VLAN; it does not automatically permit all required Tagged VLANs.

For example, on a port connected to a phone with a downstream PC, the data VLAN can be untagged while the Voice VLAN is tagged or assigned dynamically. Here too, only one VLAN can be Untagged.

Create a VLAN and port plan

Before configuring, define the following for every link:

  • VLAN ID, name, and purpose;
  • responsible gateway and DHCP system, without configuring them a second time on the switch;
  • Tagged VLANs for each uplink;
  • exactly one Untagged VLAN and one PVID per access port;
  • management VLAN and an available recovery path;
  • Voice VLAN ID, detection method, and affected ports;
  • static VLAN membership or the intentional use of GVRP;
  • required Accept type and Ingress filtering state;
  • configuration authority: Sophos Fusion or the local switch interface.

Example for VLAN 100:

ConnectionTaggedUntaggedPVIDPurpose
Switch port 8 to the Sophos Firewall100according to the native/management designaccording to untagged trafficTrunk
Switch port 2 to the client–100100Access port

The VLAN ID must be identical on all participating devices. A VLAN name is only a local label and does not establish a connection between devices. VLAN 1 is the factory-default VLAN; without a custom VLAN configuration, all ports are assigned to this VLAN. Do not remove VLAN 1 from a management path without careful consideration.

Establish configuration authority and resolve conflicts

Local changes on the switch are not automatically synchronized with Sophos Fusion. To avoid persistently conflicting states, designate one interface as authoritative before making the first change.

In Sophos Fusion, navigate to the device through:

My Products > Switches > Switches > [Switch]

Under VLANs > VLANs, Configuration source, Ports configuration source, and Conflicts show where the settings originate and whether they differ. Under Port settings > Basic settings, you can see Untagged VLAN, Tagged VLAN, Configuration source, and Conflicts.

When you first register a switch or after a Factory Reset, all ports and LAGs may show conflicts. The local default values then differ from Not set in Sophos Fusion. The following rules apply:

  • Not set means that Sophos Fusion does not set this value; the switch uses its local configuration.
  • Resolve all conflicts under the port settings adopts the switch’s current values for all conflicts in Sophos Fusion.
  • Resolve conflicts handles an individual port or VLAN.
  • Import to Sophos Fusion imports the local VLAN configuration into central management.
  • A setting changed from Not set to a specific value at switch level does not automatically revert to Not set through inheritance from a site or stack configuration.

⚠️ Do not select Resolve all conflicts blindly. First compare the local and central VLAN matrices and decide which state is correct. After an import, you must still compare Tagged, Untagged, and PVID against the documented port plan.

Configure a VLAN in Sophos Fusion

1. Create the VLAN

For the selected switch, open:

VLANs > VLANs
  1. Click Add VLAN.
  2. Set VLAN ID, Name, optionally Description, and a color. The color is only a visual aid.
  3. Select the ports under Tagged ports and Untagged ports according to the port plan.
  4. Click Save.

For VLANs other than the default VLAN, the uplinks carrying them must be selected under Tagged ports. Only one Untagged VLAN can be assigned per port. Use Edit to change an existing VLAN; to remove VLANs, select them and click Delete.

2. Cross-check the port view

Under:

Port settings > Basic settings

Untagged VLAN and Tagged VLAN must show the same port role as the VLAN view. This cross-check identifies common errors, such as a VLAN that exists on the firewall but has not been permitted as Tagged on the uplink.

3. Set ingress rules and align the PVID

Open:

VLANs > Ingress filtering

For each port, set Accept type, Ingress filtering, and Priority ingress filtering in this Fusion view. On access ports, the PVID must match the Untagged VLAN. The documented local path for editing the PVID is:

Configure > VLAN settings > PVID and ingress filter

Edit the PVID directly in Sophos Fusion only if the Fusion interface in use actually provides an editable field for it. Otherwise, set it locally using the path above. Account for this local setting when resolving configuration-source conflicts and, if it is to be centrally managed going forward, import it deliberately with Import to Sophos Fusion.

Save changes in Sophos Fusion with Update. Clear discards changes that have not yet been saved.

Configure a VLAN locally on the switch

Sophos recommends using Sophos Fusion to configure centrally managed devices. If the local interface has deliberately been designated as authoritative, use:

Configure > VLAN settings > 802.1Q
  1. Select Add.
  2. Enter VID and Name.
  3. Select Apply to create it.
  4. Select the VLAN and open Edit.
  5. Set ports to Tagged, Untagged, or Forbidden.
  6. Deliberately set GVRP advertisement to Turned on or Turned off.
  7. Confirm with the check mark, then select Apply.

Local VLAN names are optional, can be no more than 32 characters long, and must not contain the characters ", \, %, &, ?, ', !, ;, |, or +.

Then open:

Configure > VLAN settings > PVID and ingress filter

Select the affected ports, choose Edit, set PVID, Accept type, Ingress filtering, and Priority ingress filtering, and save with Apply.

The local VLAN table shows the effective port state:

  • F: Forbidden
  • T: Tagged
  • U: Untagged
  • V: Voice VLAN
  • Gu: Guest VLAN
  • Gv: GVRP
  • R: RADIUS

After local changes, do not assume that the configuration has automatically been saved to Sophos Fusion. Either import the values deliberately with Import to Sophos Fusion, or leave the central configuration in a state that does not overwrite the local state.

Use Ingress Filtering correctly

Accept type and Ingress filtering are separate checks:

  • All: accepts Tagged and Untagged frames.
  • Tagged: accepts only Tagged frames and discards Untagged frames.
  • Untagged: accepts only Untagged frames and discards Tagged frames.
  • Ingress filtering: On: according to the Sophos interface, discards Tagged frames whose VID does not match the port’s PVID.
  • Ingress filtering: Off: forwards frames according to the switch’s VLAN configuration.
  • Priority ingress filtering: On: discards frames with VLAN ID 0, meaning frames with 802.1p priority tags only.

802.1Q membership also applies: if a port receives a Tagged frame for a VLAN of which it is not a member, the frame is discarded.

For a pure access port, Untagged with a matching PVID is the restrictive choice. On a pure Tagged uplink, Tagged is the obvious choice. On a trunk with multiple Tagged VLANs, Ingress filtering must be tested especially carefully: the documented PVID check would discard Tagged frames whose VID differs from the PVID. Therefore, do not enable it indiscriminately; first verify every permitted VLAN over a test link.

⚠️ Configure VLAN memberships and PVID correctly before tightening Ingress Filtering. Otherwise, a working trunk or management access can fail immediately.

Configure GVRP deliberately

GARP VLAN Registration Protocol (GVRP) manages VLAN memberships dynamically using Join and Leave messages. For small, stable networks, static Tagged memberships are easier to audit. GVRP is useful when dynamic registration is explicitly part of the design and all participating devices are controlled.

Under:

VLANs > GVRP
  1. Enable GVRP with Turn on and select Update.
  2. Enable Status only for the intended ports.
  3. Enable Restricted VLAN on uplinks that may learn only VLANs already configured on the switch. Join messages for other VLANs are then ignored.
  4. Change Join time(ms), Leave time(ms), and Leave-all time(ms) only when the timers are coordinated across the network.
  5. Save with Update; Clear discards unsaved changes.

A VLAN must be enabled locally under GVRP advertisement before it can be advertised. After convergence, check the local VLAN table to see which memberships were learned as Gv. GVRP replaces neither a documented trunk list nor a security decision. Unexpectedly learned VLANs are a reason to check Restricted VLAN, port status, and the peer device.

Configure Voice VLAN

A Sophos Switch supports exactly one Voice VLAN. It prioritizes VoIP traffic but does not replace an end-to-end QoS configuration on the firewall, WAN, and peer devices.

Open:

VLANs > Voice VLANs

Global settings

Under Voice VLAN status, the following options are available:

  • Not set: use the local Voice VLAN configuration;
  • Disabled: turn off Voice VLAN;
  • Auto: automatically detect and assign VoIP devices;
  • OUI: detect devices based on the Organizationally Unique Identifier in their MAC address.

Then configure:

  1. Set Voice VLAN ID to the VLAN ID already defined in the plan.
  2. Select VLAN priority tag according to the QoS design.
  3. Set DSCP to a value between 0 and 63 only if that value is used throughout the network.
  4. If required, enable 802.1p CoS status and specify CoS priority. 5 is the usual priority for voice media, while 6 is typically used for voice and video signaling.
  5. Set Aging time so that dynamic port assignments are removed after voice traffic ends. New voice traffic during this period resets the timer.

Port settings

Enable Voice VLAN only on ports where phones are expected. CoS mode determines how traffic is marked:

  • Source: apply QoS attributes to packets whose source MAC contains a recognized OUI;
  • All: apply QoS attributes to all traffic assigned to the Voice VLAN.

Save with Update and check Operation status. For a phone with PC passthrough, also verify that the data VLAN is untagged and the Voice VLAN is carried separately.

OUI settings

When Voice VLAN status: OUI is selected, go to OUI settings, click Add, enter the phone manufacturer’s OUI address and Description, and save with Save. Select obsolete or overly broad entries and remove them with Delete. A device is assigned correctly only if its source MAC matches an entry and Voice VLAN is enabled on the port.

DHCP example with Sophos Firewall

The following example uses the values from the official Sophos procedure:

  • Sophos Firewall Port6 is connected to switch port 8.
  • Switch port 8 carries VLAN 100 as Tagged.
  • A client is connected to switch port 2; this port carries VLAN 100 as Untagged and uses PVID 100.
  • Firewall VLAN interface: VLAN_100 on Port6 with 172.16.100.1/24.
  • DHCP range: 172.16.100.2 through 172.16.100.254.

The technical dependency, and therefore the mandatory sequence on the firewall, is: VLAN interface first, DHCP server second. The DHCP menu can select the VLAN only after the interface exists. The official procedure describes the complete setup faithfully in this order:

  1. Create VLAN 100 on the switch.
  2. Assign switch port 8 as Tagged and switch port 2 as Untagged; check PVID 100 for the access port.
  3. Create the VLAN interface on the Sophos Firewall.
  4. Bind the DHCP server to this VLAN interface.
  5. Only then connect the client or move its port into production.

For a production change, the following staged sequence involves less risk because the target network is ready before the first access port is migrated:

  1. Create the VLAN interface on the Sophos Firewall in advance.
  2. Bind the DHCP server to it and check its settings.
  3. Create VLAN 100 on the switch, add uplink port 8 as Tagged, and verify the Tagged path to the firewall.
  4. Only then configure a test port as an Untagged member of VLAN 100, set its PVID to 100, and migrate a test client.
  5. Test DHCP, the gateway, and the explicitly permitted destinations before migrating additional access ports.

Before changing the uplink or management VLAN, ensure that independent management or rollback access is available. Do not remove the previous management VLAN until reachability over the intended path has been confirmed.

Switch

In the local interface under Configure > VLAN settings > 802.1Q:

  1. Create VID 100 with Name VLAN100.
  2. Select port 8 under Tagged and port 2 under Untagged.
  3. Enable GVRP advertisement only if GVRP is used in the design.
  4. Under PVID and ingress filter, for port 2, set PVID 100 and configure the required Accept type and Ingress filtering.

The official example sets, on port 8, PVID 100, Ingress filtering: On, and Accept type: All. This is suitable only if untagged traffic on this link is to be assigned to VLAN 100. For a pure Tagged trunk or a trunk with multiple VLANs, instead set PVID, Accept type, and Ingress filtering according to your own port plan and test every VLAN.

Sophos Firewall

In the WebAdmin interface:

Network > Interfaces > Add Interface > Add VLAN
  • Name: VLAN_100
  • Interface: Port6
  • VLAN ID: 100
  • IP assignment: Static
  • IPv4/netmask: 172.16.100.1/24

Save. Only then go to:

Network > DHCP > Add
  • Name: VLAN_100_DHCP
  • Interface: VLAN 100-172.16.100.1
  • Start IP: 172.16.100.2
  • End IP: 172.16.100.254

Save. This example demonstrates only VLAN transport and DHCP assignment. Reachability of other networks or the internet also depends on zones, firewall rules, routing, and, where applicable, NAT on the firewall.

Validate after every change

Check the effective data path, not just the configuration screen:

  1. In Sophos Fusion, wait until the switch is synchronized. Check Configuration source, Ports configuration source, and Conflicts.
  2. Open the VLAN under VLANs > VLANs and compare Tagged/Untagged memberships with the port plan.
  3. Under Port settings > Basic settings, cross-check the same values from the port perspective.
  4. In the local VLAN table, check the codes T, U, V, or Gv; investigate unexpected F entries.
  5. Check the PVID and Accept type of every changed port.
  6. Reconnect a test client or renew its DHCP lease. It must receive an address from the correct range, the expected netmask, and 172.16.100.1 as its gateway.
  7. Ping the gateway and then test only the explicitly permitted destinations.
  8. Perform negative tests: a Tagged frame with an unauthorized VLAN ID must not reach another VLAN; an untagged frame must not be accepted on a Tagged-only port.
  9. For Voice VLAN, check Operation status, the detected MAC/OUI, VLAN assignment, and voice quality.
  10. For GVRP, observe the expected Gv memberships and their removal after a controlled link change.

Troubleshooting

Client does not receive a DHCP address

  • In VLAN 100, is the client port really U, with PVID 100?
  • For VLAN 100, is the firewall uplink T on the switch?
  • Does the firewall VLAN interface use the same physical parent interface and VLAN ID?
  • Was the DHCP server created only after the VLAN interface, and is it bound to VLAN 100-172.16.100.1?
  • Does Accept type discard the incoming frame type?
  • Does Ingress filtering discard the VLAN ID because the PVID differs?
  • Is there still a conflict between the local and Sophos Fusion configurations?

An address from another subnet usually indicates an incorrect Untagged VLAN or PVID. A self-assigned address is more likely to indicate a broken VLAN path or an unreachable DHCP server.

Tagged VLAN does not reach the firewall or downstream switch

  • Check VLAN membership at both ends of the link; the VLAN ID must be permitted on both sides.
  • Ensure that the port is not inadvertently Untagged or F instead of T.
  • With Accept type: Tagged, the peer must not send untagged frames.
  • For multiple Tagged VLANs, test Ingress filtering and the PVID check individually.
  • Do not confuse a GVRP-learned membership (Gv) with a static Tagged membership (T).

Switch is no longer reachable after the change

  • Revert the last change to the management VLAN, Untagged membership, PVID, and uplink.
  • Use the prepared local or separate management access.
  • Check whether VLAN 1 or the previous management VLAN was removed from the port too early.
  • Only after restoring access should you decide whether to import the local configuration with Import to Sophos Fusion or correct the intended central configuration.

Voice device is not assigned to the Voice VLAN

  • Voice VLAN status must not be Disabled or unintentionally Not set.
  • Check Voice VLAN ID and port Status.
  • For OUI detection, compare the first three bytes of the device MAC with OUI address.
  • Check Operation status and the local VLAN table for V.
  • For phones with PC passthrough, check the data VLAN, Voice VLAN, and PVID separately.
  • If the assignment disappears after a call ends, take Aging time and MAC aging into account.

GVRP learns no VLANs or the wrong VLANs

  • Check the global state, port Status, and the VLAN’s GVRP advertisement.
  • Check whether Restricted VLAN is intentionally rejecting a VLAN that has not yet been configured locally.
  • Do not change Join time(ms), Leave time(ms), and Leave-all time(ms) in isolation on only one device.
  • Replace unexpected dynamic VLANs with a static configuration or disable GVRP on the affected port.

Sophos Fusion continues to show conflicts

  • Document Configuration source and the local VLAN table first.
  • If the switch state is correct, use Import to Sophos Fusion or Resolve conflicts as appropriate.
  • If the intended central configuration is correct, explicitly set and synchronize the VLAN and port values there.
  • After a Factory Reset with conflicts across all ports, do not assume that Not set means the same as the local default value.
  • Then validate Tagged, Untagged, PVID, and management reachability again.