Sophos Switch software features

Download datasheet

Sophos Switch Series: Features and configuration options

All Sophos switches offer a broad feature set and extensive configuration options. The following is a non-exhaustive list of key features and capabilities that are available via Sophos Central, the Local User Interface, or both.

Management and configuration Feature availability by model
Active Threat Response

All models (requires a valid Sophos support subscription)

Integration with Sophos MDR/XDR

All models (requires a valid Sophos support subscription)

Switch auto-discovery

All models

Dynamic VLAN configuration

All models (GVRP)

IEEE 802.1D MAC Bridging/STP (RSTP-compatible)

All models

Link Aggregation Groups (LAGs), # of ports supported

All models, up to 8

LAG size

All models, 8

IGMP snooping

All models

802.1x Authentication

All models

802.1x MAC Authentication Bypass (MAB): host, port, and fallback

All models

Syslog collection

All models

IP/MAC ACL

All models

Jumbo frames

Yes, 
CS101-8/8FP: Size 9K, per system setting,
 Other models: Size 10K, per port setting

Auto-negotiation for port speed and duplex

All models

MDI/MDIX auto-crossover

All models

IEEE 802.1D MAC Bridging/Spanning Tree Protocol (STP)

All models

IEEE 802.1w Rapid Spanning Tree Protocol (RSTP)

All models

IEEE 802.1s Multiple Spanning Tree Protocol (MSTP)

All models

Edge port/port fast

All models

IEEE 802.1Q VLAN Tagging

All models

Guest VLAN and voice VLAN

All models

IEEE 802.3ad Link Aggregation Control Protocol (LACP)

All models

Unicast/multicast traffic balance over trunk port

All models

IEEE 802.1AX Link Aggregation

All models

Spanning Tree Instances (MSTP/CST)

All models

IEEE 802.3x Flow Control and Back Pressure

All models

IEEE 802.3 10Base-T

Sophos Switch 100 Series only

IEEE 802.3u 100Base-TX

All models

IEEE 802.3z 1000Base-SX/LX

All models

IEEE 802.3ab 1000Base-T

All models

IEEE 802.3bz Multi-Gigabit Ethernet

All models that support 2.5 GE and above

IEEE 802.3 CSMA/CD access method and physical layer specifications

All models

Storm control

All models

Port mirroring

All models

DHCP relay

All models

Security and visibilityFeature availability by model
Max. ACL groups 

128 for all models

Max. ACL entries per group 

2 for CS101-8/8FP; 8 for all other models

IP Source Guard

All models (Uses 1 ACL group if enabled)

IEEE 802.1x Authentication Port-Based

All models

IEEE 802.1x Guest VLAN 

All models

IEEE 802.1ab Link Layer Discovery Protocol (LLDP) 

All models

IEEE 802.1ab LLDP-MED 

LLDP MED PoE models only

DHCP snooping 

All models

Cisco Discovery Protocol (CDP) compliance

All models

MAC address filtering

All models

Priority tag - packet ingress filtering

All models

Quality of service Feature availability by model
IEEE 802.1p Priority Queuing

All models

IP TOS/DSCP Priority Queuing

All models

Continuous Power over Ethernet (PoE)

All models with PoE except CS101-8FP

ManagementFeature availability by model
IPv4 and IPv6 Management 
IP Assignment Supports DHCP or Static Address  

All models

SSH

All models

HTTPS

All models

SNMP v1/v2c/v3 

All models

SSH, Web Interface, and REST API 

All models

Sophos Central

All models

RFC and MIB supportFeature availability by model
DHCP Client  

All models

RFC 854 Telnet Server 

All models

RFC 2865 RADIUS (for 802.1x Authentication)

All models

RFC 1643 Ethernet MIB

All models

RFC 1213 MIB-II 

All models

RFC 1157 SNMPv1/v2c 

All models

RFC 2618 RADIUS Authentication Client MIB 

All models

RFC 1493 Bridge MIB 

All models