Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[SOPHOS AP55C ] Unable to migrate Sophos AP55C from Sophos XG105 to Sophos Central Wireless

 Hello,

Since the management of AP WIFI on Sophos Central is free, we migrate the APs of our customers on Sophos Central Wireless.

I'm writing to you because we have a problem with the migration of a WIFI AP on a Sophos XG to Sophos Central WIFI.

Our customer has a Sophos AP55C WIFI for 2 years, I tried to perform the following manipulations:

1 - Update of the Model AP Firmware on its last version (11.0.018)

2 - Creation of the SSID on Sophos Central

3 - Creation of the firewall rule to let all the flows from the AP WIFI to the WAN pass without IPS...

5- Removal of the terminal on the Sophos XG105 (version SFOS 17.5.9 MR-9)

6- Add the terminal on Sophos Central WIFI with its serial number

Unfortunately, this did not work, although I have done this for other customers with no problems on APs of the same range (AP55C / Sophos XG105 (with low firmeware than it))

Is someone have the same problem ?

Regards,

Raphaëlle B



This thread was automatically locked due to age.
Parents
  • Hello there,

    Thank you for contacting the Sophos Community

    Make sure you are disabling the Wireless module from the XG

    (System >> Administration >> Device Access. And Disable all of the Wireless Protection for all of the Zones)

    Regards,

  • Hello,

    Thank you for your help !

    I have disable Wireless Protection for all zones but it still doesn't work.

    I thought it could have been the router but there is no router between the firewall and the provider. It is the firewall that acts as the router.

    Regards,

    Raphaelle B

  • Hello there,

    Thank you for the screenshot.

    Have you also disabled Wireless Protection from Wireless >> Wireless Settings >> Global Settings?

    If the issue remains, if you do a tcpdump do you see the packets leaving the XG?

    Regards,

  • is there a DHCP server, serving IP addresses for the AP?

    Is it on XG?

    If this is on XG, you can see, if it received an IP address.

    If it did not receive IP address, check this KB and enable DHCP global scope 

    Next, check the IP address it received in Firewall, TLS and Webfilter logs. Probably there is a port or URL to Sophos central beeing blocked or beeing intercepted by HTTPS decryption.

    Make sure all ports are open and all requested URL by the AP are excluded from TLS and HTTPS scanning.

    Check this thread for ports and URL required from documentation AND a port beeing undocumented and needed, at least for APX, maybe also for 55C.

    Also, there is a need for the APs to allow NTP to ANY address.

  • Hello,

    I have disabled Wireless protection on Global Settings + Device access

    But it still dosn't work :/

    Regards,

    Raphaelle B

Reply Children
No Data