Choose Sophos Switch models and management
The choice of model depends on the number and speed of ports, uplinks, PoE standard and budget, as well as the installation location. Afterwards, it …
Sophos Switch provides the managed access layer for wired devices, access points, and firewall uplinks. These guides cover model selection and registration, ports, PoE, VLANs, Layer 3 and security features, monitoring, troubleshooting, firmware, backup, and controlled replacement.
First select the model, PoE budget, uplinks, and management path, then commission the switch locally or in Sophos Fusion in a controlled manner. Next build ports, VLANs, routing, and access security. Fleet status, discovery, monitoring, diagnostics, and Active Threat Response follow during operation; firmware, backups, recovery, and replacement form the controlled maintenance and migration path.
Select the model, port and PoE requirements, and local or central management. Connect the switch, register it in Sophos Fusion, and verify reachability, licensing, and an initial controlled configuration synchronization.
The choice of model depends on the number and speed of ports, uplinks, PoE standard and budget, as well as the installation location. Afterwards, it …
This runbook covers the local bootstrap, required network access, registration, and validation in Sophos Fusion—including HTTP 000 troubleshooting and …
Build ports, PoE, LAG/LACP, and STP; configure VLANs and Layer 3 routing; and add DHCP, multicast, QoS, 802.1X, port security, and ACL functions in a controlled manner. Planning the access layer for XGS HA also belongs here.
This runbook covers basic port configuration, a controlled LAG rollout, loopback detection and spanning tree, including conflicts, validation and …
Plan the PoE budget, port limits and priorities on Sophos Switch, interpret measurements correctly and troubleshoot problems without uncontrolled …
A practical runbook for VLAN membership, PVID, Voice VLAN, GVRP, and Ingress Filtering on Sophos Switch.
This runbook combines VLAN interface addressing with static IPv4 and IPv6 routes, validation, rollback, and targeted troubleshooting.
DHCP Relay carries DHCP between subnets; DHCP Snooping protects Layer 2 against unauthorized DHCP servers. This guide separates the two tasks and …
IGMP Snooping distributes IPv4 multicast selectively within the VLAN, while MLD Snooping does the same for IPv6. This guide covers planning, safe …
This runbook prioritizes time-sensitive traffic, limits bandwidth per port, and protects against broadcast, multicast, and unknown-unicast storms.
A safe rollout for port-based access control: establish AAA reachability first, test one access port, and only then expand 802.1X, MAC limits, and DoS …
This runbook explains ACLs, ACEs, port ranges and port binding, and shows a staged rollout with management protection, tests, troubleshooting and …
An architecture and operations runbook for Sophos Switch in front of an XGS HA pair, with a separate HA link, redundant switch paths and controlled …
Manage fleets, sites, and stacks; inspect neighbors and address tables; use the CLI and REST API safely; and apply SNMP, diagnostics, and Live Discover. Operate Active Threat Response only with a verified data path and rollback path.
Operations guide for fleet status, synchronization, configuration sources, site and stack inheritance, and controlled bulk actions.
This runbook separates local device access from the tenant-level Sophos Fusion API and covers secure authentication, MAC-filter changes, task …
The runbook consistently separates topology discovery from the management of address tables. It documents all visible fields, secure change processes, …
This runbook sets up SNMPv3 polling and notifications with authenticated users, encrypted communication, minimum OID permissions, and controlled …
A safe diagnostic workflow for administrators that preserves useful evidence, avoids unnecessary intervention, and cleanly reverses temporary changes.
Run or adapt switch queries in Live Discover and reliably evaluate client, time, and delivery data.
This runbook covers the prerequisites, data path, status checks, and recovery path for API-driven host isolation on Sophos Switch.
Update firmware with pre-checks and a recovery path, create and restore backups, and replace, reset, migrate, or remove a switch from Sophos Fusion in a controlled sequence.
Maintenance runbook for firmware updates, validation, dual-image rollback, and TFTP recovery, clearly separating Fusion and local management.
This runbook separates Fusion and local .cfg backups, covers scheduling, download, and restore, and prevents gaps caused by unsynchronized changes or …
Operational runbook for replacement, factory reset, account migration, removal and RMA, with an external .cfg backup and conflict checks.
Sophos lifecycle planning needs End-of-Sale, Last Renewal, End-of-Life, successor products and clear checks before renewal, migration or hardware …
Sophos Switch provides switching, PoE, VLAN, routing, and port-security functions. Sophos Fusion is the central management path; the local web interface, CLI, and REST API remain switch-side operating paths. The Sophos licensing overview explains which management model requires a subscription.
Clear boundaries apply to adjacent tasks:
This keeps each guide within the task the switch actually performs and routes licensing, firewall, wireless, and hardware-service work to the responsible product workflow.