This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Couple of questions for Sophos wireless

Hi, I have a couple of questions with regards to Sophos wireless on the UTM

1. How many acccess points can be connected?
2. How much of a performance hit does this have?
3. If you have more than 1 UTM in an organisation, can the access points be load balanced or go into failover?
4. Do the access points run if the UTM is down?
5. Can anybody offer their experiences with these? We are possibly looking at 150x 15c's and a smaller number of 55c's/100x

 

regards,

Louis



This thread was automatically locked due to age.
  • hi louis,

    i have some ap running with my utms at work.. cant answer all but some...

    1. dont know.. hope some sophos staff or someone with greater count of installation can answer this..

    2. no performance problems at my site.. but only running 3 AP30

    3. no.. only if the utms itself are running in ha mode (master/slave)

    4. no. if utm is down the "intelligence" of the AP is down...

    hope that helps..

     

     

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • Hi,

    thanks for the fast reply.

    With regards to #3, we have a master/failover UTM setup. I'm just wondering what happens when we a master/master setup and where the AP's will intitally set themselves up?

    #4 is a little bad too. I know the ubiquiti's still continue to run if the controllers go down but they will lose functionality like guest access due to there being no centralised authentication. But surely if you have a network/SSID setup with radius authentication or just a PSK, you would think the AP would continue to function?

    Louis

  • #3 only have ha/failover running so i have no experience in master / master environment

    #4 if i shutdown my utm-ha-cluster no more wlan is reachable... so i think complete functionality is lost..

    maybe some others can jump in and answer more detailed ..

     

    greets

    zaphod
    ___________________________________________

    Home: Zotac CI321 (8GB RAM / 120GB SSD)  with latest Sophos UTM
    Work: 2 SG430 Cluster / many other models like SG105/SG115/SG135/SG135w/...

  • Louis, this really is a conversation you need to be having with your reseller.  Depending on the power of the UTM running them, there are limitations on the number of REDs+SSIDs you should run.

    3. The configurations on Master and Slave are nodes are identical, allowing the Slave to become Master within milliseconds and causing virtually nothing apparent to the users.

    4. If the UTMs go down and an SSID is 'Bridged to AP LAN', it will be able to transmit traffic between wireless and wired clients in that Ethernet segment.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • BAlfson said:
    4. If the UTMs go down and an SSID is 'Bridged to AP LAN', it will be able to transmit traffic between wireless and wired clients in that Ethernet segmen

    dont think so. i thougth only with ap55, ap100. my ap30 goes down if my utm is offline. the ap55 still sends wireless network. 

    correct info about guestsegments and bridged to ap lan.


    Sophos Platinum Partner 
    Sophos Certified Architect
    (Ceritfied UTM Architect / Certified XG Architect)

  • Hi Louis,

    Check the Sizing guide here, to know the number of AP supported by various UTM models. SSID supported by AP:

    >> AP10, AP15 and AP30: total 8 SSIDs 

    >> AP 50 and above; total 16 SSIDs

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Sachin, the real issue is the number of tunnels between an AP and a UTM.  For example, if there are three 'Separate Zone' SSIDs on an AP, are those all handled with a single tunnel back to the UTM or does each SSID get its own tunnel?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

    Nice question, I am not sure about the answer but I think 3 SSIDs = 3 separate channel bands which means individual tunnels for each SSIDs.

    I will discuss it with my team and update you soon.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • How much load on the wireless is a "seperate zone" compared to a "bridge to vlan"

    Is the communication to the UTM secure for the config or the seperate zone.

    IDEA: with sophos central (connecting via https), it would be good if the magic address of 1.2.3.4 could be configured on the AP and the wireless could https to a UTM from an external source?

  • Put that in as a feature request.

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.