INTEGRATION

Sophos Captive Portal
Integration

Sophos Firewall ships a hotspot module. It gets guests online — it does not tell you who they are or give you a way to bring them back. Useroam fills that gap without touching your Sophos deployment.

Firewall captive portal settings screen

What the Sophos integration does

Useroam Cloud takes the guest arriving through the Sophos Firewall (SFOS) hotspot, presents a captive portal in your brand, verifies their identity and writes access records to signed, timestamped storage. No separate logging server required.

How the integration works

Hotspot and captive redirect

The guest network and hotspot are configured on the Sophos Firewall; unauthenticated traffic is redirected to the Useroam Cloud captive portal.

Portal and walled garden

A branded welcome page is designed in Useroam Cloud; the portal and verification services are added to the walled garden so they stay reachable before login.

RADIUS authorisation

The guest verifies their identity over SMS or WhatsApp; the verified mobile number becomes the RADIUS username for the session and the firewall authorises access.

Syslog and signed logs

Access and NAT records are collected from the firewall over syslog, signed with a trusted timestamp and retained for a configurable period. Any record needed for an audit is served from the panel.

The welcome screen carries your brand

The captive portal is designed in the panel with your logo, colours and background image, and published with a live per-device preview. The same screen doubles as a placement for your campaigns and announcements.

Useroam captive portal settings screen: branded welcome page with live per-device preview

What to know on the Sophos side

XGS serisiXG serisiSFOSAPX
  • Runs on Sophos XGS and XG series appliances with current SFOS releases.
  • Guest SSIDs broadcast by APX series access points managed through Sophos are supported.
  • The guest network runs on its own rule set — your internal security and existing Sophos rules are unchanged.

A marketing layer on the same network

The Sophos integration is not only about getting guests online: every guest who connects becomes permissioned data. The Bumerang modules run from the same panel, with no additional deployment.

Campaigns

Welcome and win-back flows go out automatically over WhatsApp/SMS, and the return visit is measured in the panel.

Explore →

Surveys

Happy guests are routed to a Google review, unhappy feedback comes to you — your reputation is fed by the WiFi.

Explore →

QR Menu

Multilingual menu and order-from-table, with reporting on which item drew interest and when.

Explore →

Other integrations

Useroam is vendor-agnostic: even when sites run different devices, everything is managed from one panel.

Your hardware is ready. Let's open the guest network.

Send us your model and we will plan the integration steps together and open a demo environment the same day.

Frequently asked questions

Do I need extra hardware or a licence for Sophos guest WiFi?
No extra hardware. Useroam runs with the Sophos appliance you already own. Licensing depends on your device segment and the plan you choose.
How are access logs handled?
Access and NAT records are collected from the firewall over syslog, signed with a trusted timestamp from an accredited timestamping authority, and retained for a period you configure. Nothing is stored on site, and any record needed for an audit is exported from the panel.
Does it work with Sophos APX access points?
Yes. It is compatible with guest SSIDs on APX series access points managed through the Sophos Firewall, and the corporate network stays behind its own rule set.