I am not an expert on the Sophos UTM but I know enough to be dangerous.
Recently, under Remote Access > SSL > Settings, we made a change to the port being used which required every employee using the VPN to download a new config/profile on every device…