Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

  • Sophos XG V 19.5 IPSEC IKEv2 Remote Access VPN

    Hi Guys, is IKEv2 finally included in v 19.5 for Remote Access VPN? Thanks a lot, Dustin
  • L2TP slow on XG

    Hello Community, I'm migrating from a SG550 (UTM) to a new XGS5500 (SFOS 19.5). Both firewalls connected to the same ISP. If I connect to the UTM via L2TP I can copy a file via CIFS with around 5 MB/s, which is almost equal to the bandwidth of the client…
  • Sophos Connect - Does the User Portal have to be on the WAN interface for it to work?

    As title suggests - we noticed that Sophos Connect only seems to work if the User Portal is enabled on the WAN interface. This raises a point though > with MFA enabled this should be secure, however for people who were yet to setup MFA, would they…
  • Automatically Push Sophos Connect Upgrade

    Hello Community Members, Good day. I have one issue, where we have Sophos Connect Client rolled out to our users for remote working. When it was rolled out the version was 2.2.75 and current version is 2.2.90. We have to manually upgrade Sophos Connect…
  • Sophos XG v19- VPN IPSEC connected but cannot acces LAN

    IPSEC Remote Access is connected but cannot access LAN resources. I recently configured an IPSec remote access VPN. However, IPSec clients are unable to access authorized LAN resources. SFOS 19 Below is my configuration: IPsec (sophos connect) Authentication…
  • Another issue with the Sophos Connect Client - Importing of user profiles is too limited or restricted...

    This is discussed in this, now closed, thread. Sophos Connect with multiple users on the same PC My specific scenario is as follows. I am a network admin for multiple clients that use Sophos firewalls. I invariably have various different user…
  • Sophos Connect 2.2 Help Opens Internet Explorer...

    This is discussed, in the thread, below but the thread appears to have been prematurely closed as the issue, whilst answered, has clearly not been resolved. community.sophos.com/.../sophos-connect---internet-explorer It is less than a month before…
  • Sophos Client Connect - run_logon_script yes/no (Not working)

    When I download the .ovpn file from the user portal and open it in a text editor, there is line that says run_logon_script no. I tried just setting that to run_logon_script yes, but it does not have any affect. Looking for some assistance getting this…
  • L2TP Pool too small / Allow leasing IP addresses from RADIUS

    Hello Community, we have many L2TP-VPN Users and the /24 IP Scope is too small for all our VPN Users. If I read the documentation right, it is not possible to use a lager pool then /24. For us a /23 Pool will fit. Actually, we use a mix of SSLVPN and…
  • Sophos Connect Client can't be installed on Surface Pro 9?

    Morning, I have two identical Microsoft Surface Pro 9 (with the Microsoft SQ3 processor) and freshly installed WIndows 11. Both get the same error when trying to install Sophos Connect:l Here's a video of the failing installation: https://imgur.com…
  • Invalid Pase 2 ID Prosal. One user

    Everyone seems to be able to connect to the VPN, but me. I get this fault. We are using only one profile for IPSEC, although there are a few profiles in the system. I see support for if there are multiple profiles in use, but I do not see anything for…
  • TLS engine error: FLOW_TIMEOUT through IPSec Remote Access Tunnel

    Hello community, we are facing a strange behavior since we´ve updated our XGS4500 to SFOS 19.5.0 GA-Build197 . Some website are not fully accessible through IPSec Remote Access Tunnel (via Sophos Connect Client). The first line of the above SSL…
  • How to setup L2TP Client VPN and OSPF routing in SFOS 19.5?

    Hello Community, I have a working L2TP VPN dialup and a working OSPF routing over our site firewalls. From the L2TP network I can reach all local networks (connected to the firewall itself), but I can't reach any network in the site locations. I figured…
  • Sophos Connect (2.2.75.0506) - Service Unavailable

    I've read through previous discussions on this issue and have not come to a full resolution as of yet. We've had an uptick in users reporting the 'Service Unavailable' issue with their Sophos Connect clients and I'm attempting to identify the root cause…
  • LOCAL_ACL Violation IPSEC VPN

    Hi, I set up an IPsec VPN but I am getting Local_ACL violations... I want to access it from my LAN PC 172.16.16.19 The Firewalls WAN IP is 192.168.178.50 Traffic is allowed I only added 1 Firewall-Rule. I pass everything to everything... …
  • Automatic Sophos Connect Installation

    Hello! I am trying to write a script that will be able to install Sophos Connect onto computers that do not currently have it. Is there a good link to get the Sophos Connect .exe file from that doesn't require going into the firewall section to do…
  • Sophos Connect Provisioning file

    Hello guys, we have a Sophos XGS 3300 cluster (1 9.0.1 MR-1-Build365) and are using Sophos Connect Client for our HO users. All users have an IPSEC and and a SSL VPN profile in the connect client. In the future we want to use the provisioning file …
  • Connection could not be loaded

    We had problems using the SCC when connections close unexpectedly after about 60 minutes. So we have changed the settings in the IPsec profile. We have changed the key life in phase 2 from 3600 to 36000 and have changed the dead peer detection to re…
  • Sophos Connect Client - DNS Issues on multiple destinations - Service issues (NCL-1383) - Workaround

    Hi, I did seee many posts about DNS server not set correctly (or not reset) in Sophos Connect 2.2 when you connect to multiple destinations via ipsec. We did create a workaround with the following powershell script that should be executed after…
  • IPSec VPN No Internet Once Connected

    Hello, I am having issues connecting with Sophos Connect. I am at the point where the local computer can connect to the VPN and receives the correct vIP address, however the remote network address stays at 0.0.0.0/0 and the client has no network connection…
  • IPsec Remote Access profiles for different usecases

    We have the following challenge: On our XGS, we've setup IPsec remote access via Connect Client for our laptop users. This is working quite well. We use Azure MFA for authentication and are able to limit each users access right by user based firewall…
  • Sophos Connect constantly re-authenticating when machine sleeps

    I have a RADIUS/NPS/Azure AD setup for Sophos Connect VPN. Everything works well for the most part. The only issue I'm having is when you are connected to the VPN and you put your laptop to sleep, Sophos Connect continually tries to re-authenticate…
  • Allow Sophos Connect connection through local XGS firewall

    Hello, Company A Site A (public ip aaa.aaa.aaa.aaa) XGS 116 with remote access VPN configured Company B Site B (public ip bbb.bbb.bbb.bbb) XGS 2100 with remote access VPN configured How to allow pc with Sophos Client installed…
  • No access to network drives

    Hello all, we are using XG230. I connect my Lenovo Laptop over my Samsung Xcover via Hotspot with the Internet. After that i start thr Sophos VPN Client on the Laptop. Everything works fine. In the Windows Explorer i can see the Network drives in…
  • L2TP VPN stopped working

    Hi, We have an established L2TP VPN tunnel that has been working for years. Local authentication on the firewall. The firewall is XG ver 19.01 MR-1 Build 365, and a copule of days ago the VPN just stopped working. Around the same time we imported…