Sophos Switch software features
Sophos Switch Series: Features and configuration options
All Sophos switches offer a broad feature set and extensive configuration options. The following is a non-exhaustive list of key features and capabilities that are available via Sophos Central, the Local User Interface, or both.
Management and configuration | Feature availability by model |
---|---|
Active Threat Response | All models (requires a valid Sophos support subscription) |
Integration with Sophos MDR/XDR | All models (requires a valid Sophos support subscription) |
Switch auto-discovery | All models |
Dynamic VLAN configuration | All models (GVRP) |
IEEE 802.1D MAC Bridging/STP (RSTP-compatible) | All models |
Link Aggregation Groups (LAGs), # of ports supported | All models, up to 8 |
LAG size | All models, 8 |
IGMP snooping | All models |
802.1x Authentication | All models |
802.1x MAC Authentication Bypass (MAB): host, port, and fallback | All models |
Syslog collection | All models |
IP/MAC ACL | All models |
Jumbo frames | Yes, |
Auto-negotiation for port speed and duplex | All models |
MDI/MDIX auto-crossover | All models |
IEEE 802.1D MAC Bridging/Spanning Tree Protocol (STP) | All models |
IEEE 802.1w Rapid Spanning Tree Protocol (RSTP) | All models |
IEEE 802.1s Multiple Spanning Tree Protocol (MSTP) | All models |
Edge port/port fast | All models |
IEEE 802.1Q VLAN Tagging | All models |
Guest VLAN and voice VLAN | All models |
IEEE 802.3ad Link Aggregation Control Protocol (LACP) | All models |
Unicast/multicast traffic balance over trunk port | All models |
IEEE 802.1AX Link Aggregation | All models |
Spanning Tree Instances (MSTP/CST) | All models |
IEEE 802.3x Flow Control and Back Pressure | All models |
IEEE 802.3 10Base-T | Sophos Switch 100 Series only |
IEEE 802.3u 100Base-TX | All models |
IEEE 802.3z 1000Base-SX/LX | All models |
IEEE 802.3ab 1000Base-T | All models |
IEEE 802.3bz Multi-Gigabit Ethernet | All models that support 2.5 GE and above |
IEEE 802.3 CSMA/CD access method and physical layer specifications | All models |
Storm control | All models |
Port mirroring | All models |
DHCP relay | All models |
Security and visibility | Feature availability by model |
---|---|
Max. ACL groups | 128 for all models |
Max. ACL entries per group | 2 for CS101-8/8FP; 8 for all other models |
IP Source Guard | All models (Uses 1 ACL group if enabled) |
IEEE 802.1x Authentication Port-Based | All models |
IEEE 802.1x Guest VLAN | All models |
IEEE 802.1ab Link Layer Discovery Protocol (LLDP) | All models |
IEEE 802.1ab LLDP-MED | LLDP MED PoE models only |
DHCP snooping | All models |
Cisco Discovery Protocol (CDP) compliance | All models |
MAC address filtering | All models |
Priority tag - packet ingress filtering | All models |
Quality of service | Feature availability by model |
---|---|
IEEE 802.1p Priority Queuing | All models |
IP TOS/DSCP Priority Queuing | All models |
Continuous Power over Ethernet (PoE) | All models with PoE except CS101-8FP |
Management | Feature availability by model |
---|---|
IPv4 and IPv6 Management IP Assignment Supports DHCP or Static Address | All models |
SSH | All models |
HTTPS | All models |
SNMP v1/v2c/v3 | All models |
SSH, Web Interface, and REST API | All models |
Sophos Central | All models |
RFC and MIB support | Feature availability by model |
---|---|
DHCP Client | All models |
RFC 854 Telnet Server | All models |
RFC 2865 RADIUS (for 802.1x Authentication) | All models |
RFC 1643 Ethernet MIB | All models |
RFC 1213 MIB-II | All models |
RFC 1157 SNMPv1/v2c | All models |
RFC 2618 RADIUS Authentication Client MIB | All models |
RFC 1493 Bridge MIB | All models |