Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Sophos Firewall: Enable separate (3rd) input box for SSLVPN MFA instead of Password+OTP.

Disclaimer: This information is provided as-is for the benefit of the Community. Please contact Sophos Professional Services if you require assistance with your specific environment.


Overview

This Recommended Read describes how to configure Sophos Connect Client login using SSL VPN MFA instead of the normal setup of Password + OTP. 

Sophos Connect Provisioning file

It's possible to turn on separate input for MFA/OTP in the case of SSLVPN using the Sophos Connect Cient and Sophos Connect provisioning file (pro).

Below is the configuration:

 

Sample .pro file:

[

    { 

        "gateway": "<Enter your gateway hostname or IP address>",

        "user_portal_port": 443,

        "otp": true,

        "2fa": 1,

        "can_save_credentials": true

     }

]

Step1: Sophos Connect Client 1st Login

You’ll be asked for a Username/Password/ OTP (3rd separate input box). Click the checkbox for saving username/password. 

 

Step2: Logging next time in Sophos Connect Client

As username and password are saved, it’ll prompt only for OTP.

   


 



Updated Links
[edited by: Raphael Alganes at 11:55 AM (GMT -7) on 24 Oct 2024]
Parents
  • Why is this only working with SSL? And not with IPsec connections?

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

  • Is there a way to include the second factor field in an existing connection without using the provisioning templates?

    In most cases, the users are no longer in the house with their notebooks and the Sophos Connect applications already installed there and therefore do not have direct access to the Sophos Firewall (via the next gateway IP address in the template) and therefore cannot obtain the latest provisioning from the firewall.

    Is there a trick here to add the field for an existing imported connection?

Reply
  • Is there a way to include the second factor field in an existing connection without using the provisioning templates?

    In most cases, the users are no longer in the house with their notebooks and the Sophos Connect applications already installed there and therefore do not have direct access to the Sophos Firewall (via the next gateway IP address in the template) and therefore cannot obtain the latest provisioning from the firewall.

    Is there a trick here to add the field for an existing imported connection?

Children