How to manage switch from Central?

I am confused. How is Sophos switch managed from Central?

I added some port settings, VLANs, including Voice VLAN settings, but those settings are not available on Sophos Central at all.

Did I miss something?

For example, on local switch interface:

On Central:



Added TAGs
[edited by: Erick Jan at 6:10 AM (GMT -8) on 11 Jan 2024]
Parents
  • You will need "Sophos Switch CSxxx-xxxx" + "Support & Services", the switch by default is on VLAN1, and will accept DHCP, or if DHCP fails has a fallback default IP, if the switch is able to initially get an IP address from DHCP, and you put the Serial Number in Central within a 15-miinute window, then your switch is managed from Central.

    You can pass down configurations, or group policies for groups of switches from Central, manage firmware, port naming, configuration and backups.

    More features will be coming to Switch Central over time, until everything is done entirely from Central.  You also have the ability to send batch CLI commands to configure or request info from the switches via Central.

    If you want to change the native or management VLAN, you would make the adjustment in Central by creating your VLANS, and then under Networks assigning the Management VLAN to a network.  For your use case above, just add VLANS from Central after the swithc is registered.  Adding VLANs from the switch first will not sync back up to Central (yet).

  • put the Serial Number in Central within a 15-miinute window, then your switch is managed from Central.

    But that's only if the Support and Services subscription is purchased? What are the options for home users, is the Support & Services license still enforced and required with the home license?

    Any idea how much this support licence would cost per year for one switch?

    Ok, this site Avanet states here www.avanet.com/.../

    Subscription price

    Sophos sets the price for service and support here at 10% of the hardware price, and at 8% for a 3-year license.

    Admittedly, at the current time, the features of the Sevice are very weak. It’s a bit like choosing Autopilot when you buy a Tesla. First and foremost, you buy the potential that will follow. In the case of the switch, these would be features such as Synchronized Security or XDR/MTR functions.

  • Remember to work with your local Sophos SE and Account reps, and your Sophos partner of choice, they will work with you to ensure you get what you need and fully explain capabilities and roadmap items. It also ensures your feedback goes to the teams responsible for making things happen for Sophos Switch. A home use license of Sophos Switch is not a thing yet, but the switches are powerful and managed via local UI if you dont use Central, or just buy the Support with it and manage it in Central for 3 years.   The ability to send configuration changes from Central to multiple switches at once, or pull requests directly out of multiple switches at once can be extremely useful, plus backup, utilization, poe info, network configuration, vlan, QoS, LAG and LACP, Location data, group policy by site and of course much more to come.

    Also, i would argue the Tesla illustration is misplaced, our switches have never run anyone off the road Smiley

  • Another user also asked where do we download the firmware updates from to install locally from the switch's web UI?

    From the site:

    If the subscription is no longer renewed, there is of course no more telephone support, the warranty service is standard again, the Central Management is in read-only mode and the firmware updates have to be installed locally again.

    If it's true that support cost is 10% of the hardware cost, then $50 a year is not too much to complain about. And if firmware can be installed manually even without the support subscription, where do we get these firmware updates from? 

    I bought the switch from Corporate Armor, but wasn't aware the support subscription was required. oops... home users have a harder time finding out this info and who these partners are.

  • Do you have a Central Dashboard set up? Check in "Protect Devices" do you see the following section?

Reply Children