Sophos Firewall Remove GuestAP Interface - 夜莺博客

Sophos Firewall Remove GuestAP Interface

原文:Sophos Firewall Remove GuestAP Interface — theDXT (Daniel Keer)

By default, Sophos firewalls have a wireless network interface called GuestAP. Normally, this isn’t much of an issue, but if you don’t plan to use Sophos Wireless, it doesn’t make sense to keep the GuestAP network interface.

Image 10

In this post, I will show you step by step how to remove the GuestAP network interface on SFOS (Sophos Firewall Operating System).

What the GuestAP interface actually is

GuestAP is not a physical port. It is a virtual wireless interface that SFOS creates automatically so that the built-in wireless controller has somewhere to attach the default guest wireless network. When Sophos Wireless is provisioned — either on an integrated wireless model such as the XGS with a Wi-Fi radio, or on a firewall that manages external Sophos access points — the firewall needs an L3 interface on which the wireless clients land. GuestAP is that interface. It appears in Network > Interfaces alongside your physical ports, VLANs and tunnels, and by convention it carries the default “Guest” wireless network.

The reason it feels untidy is that it exists whether or not you ever deploy an access point. A firewall that sits in a data centre, a virtual appliance, or simply a site with a third-party wireless system will still show GuestAP in the interface list, and the wireless service will still be running in the background consuming a little memory and CPU. It also has a habit of turning up in interface pickers, zone lists and reports, which is confusing for anyone who did not configure it.

Two distinct things are happening here, and it helps to separate them before you start clicking:

  • The wireless networks — the SSIDs the firewall advertises or manages. The defaults are usually called GuestAP and Sophos (the latter is a hidden onboarding SSID used to discover access points).
  • The interface — the GuestAP L3 interface created by the wireless module, which disappears once no wireless network is bound to it.

Deleting the wireless networks removes the interface. You cannot delete the interface directly from the interface list; that is why people get stuck. This is the behaviour described in the Sophos community threads on the same subject, and it is the crux of the procedure below.

Should you remove it?

Removing GuestAP is safe and desirable if any of the following is true:

  • You do not use Sophos Wireless at all — no Sophos access points are connected or planned.
  • The firewall is a virtual appliance (SFV / software firewall) with no wireless capability.
  • Wireless is handled by a completely separate vendor (Cisco, Ubiquiti, Aruba, Meraki), so the Sophos wireless stack is dead weight.
  • You want a smaller, cleaner interface list and one less broadcast domain and DHCP scope to reason about.
  • You are tightening the configuration for an audit and want every active service to be intentional.

Do not remove it if:

  • You have Sophos access points registered to this firewall. Deleting the networks will break their SSIDs and disconnect clients.
  • You use the built-in hotspot feature to provide guest Wi-Fi through Sophos APs.
  • You are mid-deployment and your APs have not yet been onboarded but are on their way.

If in doubt, check Protect > Wireless > Access points first. An empty list means nothing is using the wireless stack and you are safe to proceed. A populated list means stop and reconsider.

Before you begin

  1. Back up the configuration. Go to Backup & firmware > Backup and firmware > Backup, and take a full backup. It is a two-minute step that turns any mistake into a non-event. If you prefer the CLI, the same backup can be taken with the system backup options from the console.
  2. Confirm no wireless is in use. Look at Protect > Wireless > Access points and confirm it is empty.
  3. Check what depends on GuestAP. If it is bound to a firewall rule, a zone, or hands out DHCP addresses, those references will be affected. Before deleting, search Rules and policies > Firewall rules and Network > DHCP for anything referencing GuestAP. Usually nothing does on a default build, but on a firewall someone has already customised the answer may differ.
  4. Have console or local access available. The management interface is not usually GuestAP, so there is very little risk of locking yourself out, but keep an out-of-band path available for any network change.
  5. Do this in a change window. Not because it requires downtime, but because if any wireless client is connected, it will drop the moment you delete the network.

The Process

  • Login to the Sophos firewall.

Image 11

  • Click on Protect > Wireless.

Image 12

  • Click on the Wireless networks tab.

Image 13

  • Delete the GuestAP and Sophos wireless networks.

Image 14

Now, when you look at your network interfaces, the GuestAP interface will be gone.

Image 15

Verifying the removal

There are three places worth checking after the change:

  1. Network > Interfaces — the GuestAP entry should be gone from the list. If it is still present, refresh the page; the interface list is cached in the browser more often than you would expect.
  2. Protect > Wireless > Wireless networks — should now be empty, or contain only the networks you genuinely use.
  3. Protect > Wireless > Access points — still empty, confirming nothing re-registered itself and recreated the interface.

It is also worth checking Network > Interface > Zones afterwards. On some builds the deleted wireless network leaves behind a zone entry or a DHCP scope that is no longer bound to anything. Cleaning those up keeps the configuration honest. Similarly, review Network > DHCP for a server bound to GuestAP that now has no interface.

If the wireless networks will not delete

Occasionally SFOS refuses the delete, or the networks reappear after a reboot. The usual causes and fixes:

  • An access point is registered. Check Protect > Wireless > Access points. Deregister or delete the AP first, then delete the networks.
  • Something is referencing the network. A firewall rule, a hotspot definition or a DHCP server pointing at the SSID will block deletion. Remove the reference, then retry.
  • The browser session is stale. Log out, log back in, and retry before assuming a bug.
  • A stuck database entry. This is the last resort, and it should only be attempted on the serial console with a current backup in hand. On SFOS, administrators have historically cleared stubborn interface records from the advanced shell with psql against the corporate database:
    # WARNING: advanced shell, unsupported. Take a backup and open a Sophos support
    # case first unless you genuinely know what you are doing.
    psql -U nobody -d corporate -c "select * from tblinterface;"
    psql -U nobody -d corporate -c "delete from tblinterface where interface='GuestAP';"
    psql -U nobody -d corporate -c "select * from tbldhcpconf;"

    Editing the SQLite/PostgreSQL-backed configuration directly bypasses all validation and is not supported by Sophos. If the GUI path is available to you, always prefer it.

Frequently asked questions

  • Will this affect anything else on the firewall? No. Interfaces, zones, addresses, firewall rules, VPNs and the management plane are untouched. Only the wireless networks and the interface they created are removed.
  • Can I just disable it instead of deleting it? You can leave the wireless service idle, but the interface will remain listed. If the goal is a clean interface list, deletion is the only route.
  • Will it come back after a firmware upgrade? Normally no. On a factory reset, however, the default wireless networks are recreated and GuestAP will reappear — just repeat this procedure.
  • Does deleting the network free resources? Marginally. The wireless process uses very little RAM and CPU. The main benefit is clarity, not performance.
  • What about the Sophos hidden SSID? That is the onboarding network access points use to discover the firewall. If you never plan to deploy Sophos APs, delete it along with GuestAP as shown above.
  • I use the hotspot feature, can I delete GuestAP? Not without reworking the hotspot. Create your own wireless network on the interface you actually want, then remove the default one.

If you want to read more about wireless interfaces on a Sophos firewall, here is the Sophos documentation.

Recreating a wireless network later

Removing GuestAP is not a one-way door. If you decide six months from now that you do want Sophos-managed wireless, you simply create a new wireless network under Protect > Wireless > Wireless networks > Add. Give it an SSID, choose the security mode (WPA2-Enterprise or WPA2-Personal), pick the interface or zone that client traffic should land on, and select the method used to handle client traffic — bridged, where clients share the firewall’s LAN, or separated, where the firewall creates a VXLAN tunnel and gives the wireless network its own zone and L3 interface. Onboarding an access point afterwards will make that network available, and a new wireless interface will be created automatically. In other words, the interface is a consequence of the network configuration, never something you create by hand, which is exactly why removing it means removing the networks instead.

One caution when you do recreate it: if you bind the new wireless network to the LAN zone as bridged, wireless clients share the wired broadcast domain. If you want an isolated guest segment — which is what the default GuestAP effectively was — use the separated method so the firewall builds a dedicated zone and interface for you. That keeps guest clients off the internal VLAN without any extra switch configuration.

What changes permanently after the cleanup

Nothing about routing, NAT, firewall rules or the management plane changes. The only differences you will notice are cosmetic and operational: the interface list is shorter, there is no unused broadcast domain or DHCP scope, and the wireless reports in the dashboard have nothing to display. If you are documenting the firewall for an audit, note the change in your configuration register — a future administrator who factory-resets the device will see GuestAP reappear and may wonder whether it was ever intentionally removed. Recording the decision alongside the backup is enough to answer that question.

Summary

GuestAP is a default virtual wireless interface that SFOS creates for the out-of-the-box guest wireless network. Because the interface is owned by the wireless module, it cannot be deleted from Network > Interfaces — you have to remove the wireless networks that use it. The whole procedure is: back up, confirm no access points are registered, open Protect > Wireless > Wireless networks, delete the GuestAP and Sophos networks, then verify that the interface has disappeared from Network > Interfaces. Two minutes of work, and a noticeably tidier firewall.