Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to Connect VPN due to SSL CA Certificate Expired

Hello.

We have a client using Sophos Firewall installed in a VM. (Firmware 17.5.12)
They are have expired SSL CA Certificate and when they applied new SSL CA Certificate, it shows error and VPN users unable to connect.
So, now they are using expired certificate no avoid any connection issue for VPN users.

We did upgraded the firmware to 19.5.2 to get support from Sophos Team but more issues arise for our clients.
So, they roll back the firmware to 17.5.12. I have emailed Sophos Support same question as below, but they only replied with this link
https://support.sophos.com/support/s/article/KB-000035279?language=en_US
which did not help us to explain to our client.

Questions as below:
1. On Firmware 19.5.2, they unable to create new VPN user. Can we know the root cause?

2. On Firmware 19.5.2, some existing users have issue with Remote access VPN. Can we know the root cause?

3. On Firmware 17.5.12, user side now using expired SSL CA Certificate and have no issue.
    Is there any potential issues arise if users continue to utilize the expired SSL CA Certificate in the future?

4. How long can user utilize the expired SSL CA Certificate without replacing with new certificate?


Thank you.



This thread was automatically locked due to age.
Parents
  • Hello.

    Based on the link given by Sophos Support and Community, I have composed the answer. Kindly check and you may add some convincing answers.


    1. On Firmware 19.5.2, they are unable to create a new VPN user. Can we know the root cause?

         There’s a change in the configuration of the SSL VPN IPv4 lease range.
         On Firmware 19, it uses IP subnet value which is different from the earlier firmware version which uses IP range and subnet.
         Need to recreate the IP host for the local subnet.


    2. On Firmware 19.5.2, some existing users have issues with Remote access VPN. Can we know the root cause?

        Changes under SSL Global VPN configuration will require a user to re-download the configuration.
        Users who are using the old Sophos Connect Client are required to install new Sophos Connect and new configuration files.


    3. On Firmware 17.5.12, the user side now using an expired SSL CA Certificate and has no issue.
        Are there any potential issues that arise if users continue to utilize the expired SSL CA Certificate in the future?

        Sophos will stop distributing the Sophos branded version of the OpenVPN client binaries and will not provide future updates to it.


    4. How long can the user utilize the expired SSL CA Certificate without replacing it with new certificate?
       
        No functionality is changing. The client will keep working.

Reply
  • Hello.

    Based on the link given by Sophos Support and Community, I have composed the answer. Kindly check and you may add some convincing answers.


    1. On Firmware 19.5.2, they are unable to create a new VPN user. Can we know the root cause?

         There’s a change in the configuration of the SSL VPN IPv4 lease range.
         On Firmware 19, it uses IP subnet value which is different from the earlier firmware version which uses IP range and subnet.
         Need to recreate the IP host for the local subnet.


    2. On Firmware 19.5.2, some existing users have issues with Remote access VPN. Can we know the root cause?

        Changes under SSL Global VPN configuration will require a user to re-download the configuration.
        Users who are using the old Sophos Connect Client are required to install new Sophos Connect and new configuration files.


    3. On Firmware 17.5.12, the user side now using an expired SSL CA Certificate and has no issue.
        Are there any potential issues that arise if users continue to utilize the expired SSL CA Certificate in the future?

        Sophos will stop distributing the Sophos branded version of the OpenVPN client binaries and will not provide future updates to it.


    4. How long can the user utilize the expired SSL CA Certificate without replacing it with new certificate?
       
        No functionality is changing. The client will keep working.

Children