XGS V21 doesn't have Connect in the user portal anymore?

I am trying to figure out a remote access problem for a user and am a bit frustrated that the documentation doesn't match what I have. I recently upgraded from and XG210 that did have and use the Connect app to an XGS2100 because the XG was EOL. When we log into the user portal this is what we get now.

There is no Connect app. The download for windows leads to something called the Client Authentication Agent which isn't discussed in the help file linked to the Remote Access/SSL VPN page. It still references the Connect app. It is mentioned if you click on the ? in the user portal. But it doesn't indicate if we have to update certificates or anything like that. With the connect app we had to download a configuration file specific for each user and import it into Connect. It appears the Client Authentication App doesn't care as I can use the same configuration to log in multiple users.

Should we remove the Connect app from the client when installing the new Client Authentication Agent?

Is there any logging for the new agent to help diagnose connection failures?



Added TAGs
[edited by: Raphael Alganes at 11:20 AM (GMT -7) on 31 Mar 2025]
  • Hello Mark,

    you are at the wrong place, there is a new VPN-Portal where all VPN related things have moved to. This usually runs on a different port.

    You can find your settings for this under Administration/Admin- and Usersettings.

    My VPN-Portal has this:

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

    • Hello,

      You can review below KBA:

      docs.sophos.com/.../index.html

      Mayur Makvana
      Technical Account Manager | Global Customer Experience

      Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
      If a post solves your question please use the 'Verify Answer' button.

      • Thank you. I was able to get the client and config file downloaded and installed. It was the same as my old XG on V20. The problem I have now is the connected client has no routes to the permitted network resources (the local network/LAN on the firewall). When connecting to the old XG210 the routes were inserted by the client. Am I missing something else in the configuration?

        • Apparently I have to use ##ALL_SSLVPN_RW as the source networks and devices when configuring the firewall rule. Setting the source networks to a host object specifying the ip range assigned to the SSL VPN's does not work like it did in V20 on the XG210.