We have autoconnect enabled for users, and used to have MFA (Sophos) enabled. We had to disable MFA as it was causing grief for remote users with flakey Internet (and no other ISP options available). Internet connections would go down for a few seconds, then come back up. Normally, it wouldn't be an issue as it's only a few seconds. However, with MFA enabled, Sophos Connect IPSec would attempt to reconnect, and then prompt the user for their MFA code.
Is a configuration available that allows for a successful authentication using a Sophos MFA code to last for a given time period before asking for the code again?
Hi Andrew,
I can see 2 community posts with a similar issue.
Sophos Connect VPN Timeout - Discussions - Sophos Firewall - Sophos Community
As of SFOS version 19.0 up to the latest, IKEv2 is supported with IPsec remote access VPN. This means you can create a custom profile for the IPsec policy
Based on the previous comment by LuCar Toni
Please take note that if you make any changes in these settings, then all the users MUST redownload the config file. We suggest that you test this first before implementing it in production.
Hope this helps
Hello Andrew,
Good day and thanks for reaching out to Community.
The option for successful authentication to last for a given time or period before asking for code should be a feature request and not available as of the moment. Also, the feature of disabling the reconnect feature due to an intermittent internet connectivity is not yet available and is under internal FR SFSW-I-1434
You may reach out to Support to have this both requested and linked to your account as Feature Request.
Many thanks for your time and patience and thank you for choosing Sophos
Raphael Alganes
Community Support Engineer | Sophos Technical Support
Sophos Support Videos | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question use the 'Verify Answer' link.