Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Disable auto reconnect for VPNs with Sophos Connect

Hi peoples,
So maybe i'm doing this wrong... im currently testing 2FA for VPN users.

We are using the Sophos Connect client with IPSec into an XGS 116.

Currently using DUO for the 2FA.

Everything is connecting up fine, but i want to enable the option to give users the ability to save their username and password. Whenever the Sophos Connect client disconnects it automatically tries to reconnect and i cant find any option to turn this off.

The auto reconnect has a couple of issues.

* The client itself doesnt say its lost the connection so i see an auth message pop up for the 2fa, but there is no sign in the sophos connect client that it has disconnected. Actually i havent checked the log option (i dont expect end users to do this), but the tray icon does not change and if i open the tray icon it still says its connected.

Only after it fails the reconnect the first time does the sophos connect client start to show something is happening.

This means on the first reconnect i have no idea what is trying to do a 2FA connection, obviously i cant just accept a 2fa connection if i have no idea where it came from. After it fails the re connect it attempts to auto reconnect a second time.
When the 2fa fails the second time it the stops trying to reconnect and clears the saved credentials.

I was using the the Sophos Connect Admin to configure the scx file.

Is there a new way of configuring the scx file as the install file for the SC Admin says (legacy on it) and im not sure where to download a current copy of the Sophos Connect Admin setup.


Does anyone have any advice on this? Is there a better client for end users (even if its third party)? Ideally i would like a client which tries to auto connect but doesnt wipe the saved credentials.

Thanks,
Martin



This thread was automatically locked due to age.
  • Hello Martin,

    Thank you for contacting the Sophos Community.

    You can enable the option to Allow users to save their username and password from the Advanced Settings of the Remote Access IPsec configuration.

    The Sophos Connect Admin is the one that says (Legacy on it), you can download it from the Remote Access VPN > Download Client.

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • MFA is not well implemented in Sophos Connect. We also have permanent reconnects because client was disconnected because energy saving and (endless) reconnecting (what always fails because MFA code is needed but there is no fresh MFA query from client).

    There are other MFA related bugs known and not fixed:

    - provisioning is not working for OTP users who are not creating themselve in user-portal before (so any user with OTP needs to login 2x to get a config via provisioning)


    - the connect provisioning will give any user with OTP an connection error (the provisioned config is connecting right after the provisioning login of the user -> connection failed because OTP code can used only 1x)