Disclaimer: This information is provided as-is without any guarantees. Please contact Sophos Professional Services if you require assistance with your specific environment.
When wireless users do not need to be part of the internal network or administrators do not want to allow them access to the internal network, configuring the Separate Zone wireless network is the best option.
This article describes the steps required to configure the Separate Zone wireless network.
Separate zone (default): The wireless network is handled as a separate network, having an IP address range of its own. Using this option, after adding the wireless network you have to continue your setup as described in the section below (Next Steps for Separate Zone Network).
Note – When switching an existing Separate Zone network to Bridge to AP LAN or Bridge to VLAN, already configured WLAN interfaces on Sophos UTM will be disabled and the interface object will become unassigned. However, you can assign a new hardware interface to the interface object by editing it and thus re-enable it.
Applies to the Following Sophos Products
Sophos UTM
Next Steps for Separate Zone Networks
When you created a wireless network with the option Separate Zone, a new corresponding virtual hardware interface will be created automatically, e.g., wlan0. To be able to use the wireless network, some further manual configuration steps are required. Proceed as follows: