Sophos Firewall: Managing APX on Sophos Central with DHCP server on Sophos Firewall

Disclaimer: This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment.


Overview

The Recommended Reads explains how to set up and manage Sophos access points from Sophos central while managing the DHCP server on the Sophos firewall.

Topology

Step 1: Configure access point Interface

Under the Web-admin GUI > CONFIGURE > Network > Port3



Step 2: Register an APX on Sophos Central

Under Sophos Central> My Products> Wireless> Manage Protection> Access Points> Register

Kindly see the references:

 Once Registered, You'll be able to see under the Wireless>Access Points live:

Step 3: Creating DHCP Server & Static IP MAC mapping on Sophos Firewall

Under the Web-admin GUI > CONFIGURE > Network > DHCP > Server > Add

Kindly see the references:

For the devices mentioned in the topology above.


Step 4: Checking of Static IP MAC mapping under the IPv4 lease

Once Saved, you can find the static IP MAC mapping under the DHCP > IPv4 Lease:


Step 5: Add a dedicated plain firewall rule for APX 320

*Ensure a rule for APX is present

Under the Web-admin GUI > PROTECT > Rules and policies > Add firewall rule

Kindly see the references:

  • Documentation: Add a firewall rule
  • Screenshot


Ensure to create a LINKED NAT rule as highlighted in the screenshot below:


Step 6: Creating Clientless Users

Under the Web-admin GUI > CONFIGURE > Authentication > Clientless users > Add

Kindly see the references:

  • Documentation: Adding  a single clientless user
  • Screenshot



Step 7: Create a Firewall rule for Wi-Fi to WAN

Under the Web-admin GUI > PROTECT > Rules and policies > Add firewall rule
You can use any desired authentication method; I have used clientless in my scenario here:






You can check the Devices1, Device2 & Device3 IPv4 leases under the DHCP > IPv4 lease:

You can check the Devices1, Device2 & Device3 live under the Sophos Central > Wireless > Devices:


Step 8: Options to explore on Wireless Access Points Sophos Central

Manage Protection > SSIDs > Basic Settings.

Advance Settings > Client Connection: The VLAN option can be found here

To use this option, you can add a VLAN Interface on Sophos Firewall Port3 to use and also add the VLAN DHCP Server:

And Create a DHCP Server for the new VLAN Interface created:




I hope this Recommended Read helped you meet your requirements and clarify your doubts.




Revamped RR Corrected Grammar & Font Size Added Horizontal Lines
[edited by: Erick Jan at 10:43 AM (GMT -7) on 28 Sep 2023]