Skip to content
Avanet

Configure Sophos Connect on Sophos Firewall

Sophos Connect is configured on the firewall under Remote access VPN > IPsec. For a working connection, the IPsec profile, authentication, user group, IP pool, DNS, firewall rules and distributed client profile must all match. This article covers the complete firewall-side configuration for IPsec Remote Access.

For SSL VPN, use the separate guide Set up Sophos Firewall SSL VPN Remote Access. If the decision between IPsec, SSL VPN, mobile clients and ZTNA has not yet been made, start with Sophos Connect or SSL VPN: which Remote Access solution fits?.

Configuration at a glance

  1. Under Remote access VPN > IPsec, enable IPsec Remote Access and select the WAN interface and an eligible IKEv1 profile.
  2. Configure a PSK or digital certificates and define the Local/Remote ID.
  3. Select authorised users or their main group and check the group setting.
  4. Enter the connection name, IP pool and internal DNS servers.
  5. Define Split or Full Tunnel and the remaining Advanced Settings.
  6. Configure firewall rules and the required entries under Administration > Device access.
  7. Export the .scx file, import it with a test user and test the connection again after restarting the client.

Requirements and planning

The setup requires WebAdmin access, an unused VPN address range, internal DNS servers for internal names, defined target networks and services, and users or groups with an MFA concept. Before upgrading to SFOS 22.0 MR1 or later, migrate Legacy Remote Access IPsec, as this legacy configuration can block the upgrade.

Define the following before configuring the connection:

  • local users, the AD main group, RADIUS or Microsoft Entra ID SSO;
  • a dedicated VPN pool that does not overlap with LAN, WLAN, VLANs, Site-to-Site VPNs or common home networks;
  • internal DNS servers and a DNS suffix if required;
  • permitted servers, networks and services instead of blanket LAN access;
  • Split or Full Tunnel;
  • MFA, the support process, profile distribution and client updates;
  • a documented fallback if a new profile or client version causes problems.

For the MFA configuration, see Set up Sophos Firewall MFA.

Use the correct profile types

  • .scx: Sophos Connect IPsec profile with general and advanced settings.
  • .tgb: IPsec profile for older or third-party clients, containing general settings only.
  • .ovpn: SSL VPN profile from the SSL VPN configuration or VPN Portal.
  • .pro: Provisioning file for Windows 10 and 11 that loads configurations through the VPN Portal after sign-in and automatically retrieves later configuration changes. On macOS, the IPsec profile is imported as an .scx file.

For new Sophos Connect IPsec deployments, .scx is the appropriate standard. After general IPsec changes, export both .scx and .tgb again; if only Advanced Settings change, a new .scx is sufficient. If a value in the .pro file itself changes, such as the VPN Portal port, that file must also be updated.

Provisioning simplifies distribution but makes the client dependent on the VPN Portal. If the portal must be available from the internet, permit access under Administration > Device access as narrowly as possible. A permanently and broadly exposed portal increases the attack surface; Device Access and Local Service ACL on Sophos Firewall explains the background.

Configure IPsec Remote Access

In current SFOS versions, the configuration is under Remote access VPN > IPsec. Older interfaces and the existing screenshot may still show VPN > Sophos Connect Client.

Sophos Connect Client WebAdmin configuration

WAN interface and IPsec profile

Enable IPsec remote access and select the WAN interface through which clients reach the firewall. The public IP or DynDNS/FQDN, upstream routers, port forwarding and WAN failover behaviour must match this interface.

For IPsec Remote Access, SFOS only allows IKEv1 profiles where Dead Peer Detection is disabled or set to Disconnect. The profile determines the IKE and IPsec parameters and must match the security concept and all deployed clients.

Authentication and IDs

The usual authentication options are Preshared key and Digital certificate. A PSK is quick to configure but must be strongly protected and replaced in every affected profile if compromise is suspected. MFA additionally protects the user sign-in but does not replace the PSK or certificate.

Digital certificates have specific requirements in SFOS 22.0:

  • IPsec supports RSA certificates, but not ECDSA certificates.
  • The Local and Remote Certificate require a Certificate ID.
  • External certificate must not be selected for this connection.
  • Locally signed and third-party certificates must not be combined arbitrarily. Use certificates generated on the firewall for both sides, or certificates issued by the same third-party CA, and upload its Signing CA to the firewall.

Sophos recommends a Local ID for the firewall and a different Remote ID for the clients. Possible types are DNS name, IP address, email and, for certificates, DER ASN1 DN [X509]. The IDs are not interchangeable display names: the client profile and firewall must use the same expected values.

Before deployment, also check certificate validity, private keys, the renewal process and certificate distribution. A later certificate change affects not only the firewall but also exported profiles and client acceptance testing.

Users and groups

Under Allowed users and groups, enter only authorised users or groups. For directory users, IPsec Remote Access uses the main group. For group-based access, a dedicated VPN group must therefore be used as the main group. If that is not possible, allow individual users; do not permit a broad main group solely because of a secondary VPN group.

Additionally, under Authentication > Groups, check that IPsec remote access is enabled for the main group. The setting is off by default for imported AD groups and migrated groups, and on for newly created local groups. If a user belongs to several groups, the policy of the group at the top applies; individual user policies take precedence. Connect Active Directory to Sophos Firewall explains group order in more detail.

Disabling IPsec Remote Access for a group disconnects its active users and prevents them from signing in again. Before the first classic Sophos Connect sign-in, an AD user normally has to sign in to another Authentication Client, such as the user portal. With .pro provisioning, the firewall can automatically create and assign the user during the first sign-in. Guest users are not supported for Remote Access.

Connection name, IP pool and DNS

Use a name that users and support staff understand, such as homeoffice or remote-access-ipsec. The IPsec lease range must be within a subnet of at least /24, for example 10.250.10.10 to 10.250.10.200 in 10.250.10.0/24. It must not also be used for SSL VPN, L2TP or PPTP, and must not overlap with internal networks, Site-to-Site networks or common home networks such as 192.168.0.0/24 and 192.168.1.0/24.

Size the pool for the maximum number of simultaneous users. Record the pool, reserved addresses and associated firewall rules in IPAM or the network documentation so that later changes do not silently introduce overlaps.

For internal FQDNs, distribute the internal DNS servers and a DNS suffix if required. External resolvers such as 1.1.1.1, 8.8.8.8, 9.9.9.9 or 208.67.222.222 do not resolve internal zones. The tunnel may therefore appear green even though applications fail because DNS returns the wrong results.

Idle Time and Advanced Settings

Choose Disconnect when tunnel is idle and the time interval so that unused connections end without unnecessarily interrupting normal work sessions. If Sophos Connect cannot reconnect automatically after an idle disconnect, select Disconnect and then Connect in the client.

Short timeouts are more suitable for occasional administrative access, while longer values suit stable work sessions. With OTP/MFA, test reconnection with the selected value and document the behaviour for the helpdesk.

Advanced Settings are included in .scx, but not in .tgb:

  • Use as default gateway: Full Tunnel for all traffic or Split Tunnel for internal resources only.
  • Permitted network resources: Networks reachable through the Split Tunnel.
  • Send Security Heartbeat through tunnel: Send the Sophos Endpoint heartbeat through the VPN tunnel.
  • Allow users to save username and password: Enable only if this fits the MFA and security concept.
  • Prompt users for 2FA token: Show a separate OTP field.
  • Run AD logon script after connecting: Enable only required scripts, such as drive mappings, and test them with a test user.
  • Connect tunnel automatically: Establish the tunnel when the user signs in.

When Prompt users for 2FA token is enabled, the SCCLI command-line tool does not work. Sophos Connect also does not support challenge-based OTP; it technically sends the password and OTP to the authentication server in passwordotp format.

After saving, use Export connection to export the configuration and distribute it securely. Profiles contain security-relevant connection data and must not be stored in open locations.

Firewall rules and Device Access

Sophos Connect only establishes the tunnel. Productive access still requires firewall rules. For internal targets, create the narrowest possible rule from VPN to the required destination zone and enable logging at least during deployment.

Sophos Connect Client - add a firewall rule for VPN/LAN
  • Source Zone: VPN
  • Destination Zone: LAN or the internal zone that is actually required

With a Full Tunnel using Use as default gateway, an additional rule from VPN to WAN and a suitable NAT and Security Policy design are required.

Sophos Connect Client - add a firewall rule for VPN/WAN
  • Source Zone: VPN
  • Destination Zone: WAN

Under Administration > Device access, permit IPsec from the required WAN zone. Allow the VPN Portal only from the zones genuinely needed for downloads or provisioning. If the firewall itself is used as a DNS resolver or ping target, DNS or ping must also be permitted from the VPN zone.

Test a firewall rule with Log Viewer, Policy Test and Packet Capture helps with rule analysis. After deployment, explicitly define which Remote Access rules remain logged and which events are additionally sent to Sophos Central or Syslog. For Full Tunnel connections, Web Protection, Application Control and other security policies apply as they do to other client networks.

Validate and operate the connection

Then install Sophos Connect on Windows or macOS and check the following with a test user:

  • The profile imports without errors and sign-in with MFA succeeds.
  • The client receives an address from the intended pool.
  • Internal FQDNs and central systems are reachable.
  • Log Viewer shows hits on the expected rule.
  • Split Tunnel blocks unauthorised targets, or Full Tunnel sends internet traffic through the firewall and NAT as planned.
  • Reconnection works after a network change and after restarting the client or endpoint.
  • The test client uses the documented profile version; provisioning applies changes traceably.

Record the following for ongoing operation:

  • the responsible VPN group and leaver process;
  • MFA resets and the process for locking and unlocking users;
  • the current profile version or change date;
  • known log and support paths for the helpdesk;
  • another check for Legacy Remote Access IPsec and client profiles before SFOS upgrades.

For changes to the pool, DNS, gateway, certificates, groups or Advanced Settings, define an owner, change date, fallback and a new acceptance test.

Troubleshooting

Failed to validate certificate after a restart

If the first connection works but Failed to validate certificate appears after restarting the endpoint or Sophos Connect, the Local and Remote Certificate are often not signed by the same CA.

Check the Local and Remote Certificate for consistent CA assignment and Certificate IDs. Either use certificates generated on the firewall, or use certificates signed by the same third-party CA and upload that CA’s Signing CA to the firewall, or switch to a PSK. Then export and import the profile again and retest the connection after another restart.

Remote Access IPsec fails after an HA failover

If Remote Access IPsec worked before a role change in the HA cluster but no new connection can be established afterwards, the symptoms match NC-175860 only if the Appliance Certificate had also been regenerated beforehand. If either condition is missing, investigate the connection with the standard IPsec troubleshooting process.

Sophos fixed this issue in SFOS 22.0 MR2 Build 546, dated 14 July 2026. Sophos specifies neither the version in which the issue was introduced, nor an official workaround, nor an unambiguous log message.

Before making changes, record the firmware version and build, HA mode, current roles and Last status change on both HA appliances. The diagnosis should also include the exact failover time, Authentication Type, selected Local and Remote Certificates with their Certificate IDs, the distributed client profile version and the corresponding entries from strongswan.log. HA logs are not synchronised between the appliances, so inspect the logs on the node that processed the failed connection attempt.

If the cluster is below the fixed version, first review the approved upgrade path to SFOS 22.0 MR2 Build 546 or a newer supported version. Then, during a maintenance window, perform a controlled role change on an Active-passive cluster. A real remote client on an external network must be able to reconnect afterwards; then verify internal reachability, the expected firewall rule and the IPsec logs.

⚠️ Do not regenerate or replace the Appliance Certificate merely on suspicion, and do not redistribute profiles without a documented reason. Sophos does not describe these actions as a workaround for NC-175860.

User cannot sign in

First check that the main group is listed under Allowed users and groups and that IPsec remote access is enabled under Authentication > Groups. Then check the authentication server, MFA, password status, locked user and required initial sign-in. Test AD, RADIUS or Entra ID separately from the VPN first. With Microsoft Entra ID SSO, the methods under Authentication > Services must be assigned correctly before the profile is exported.

If no IKE config found appears, also compare the IPsec profile, Local ID and Remote ID between the firewall and client profile. If only individual directory users are affected, check the main group, UPN, email address and group mapping. Sophos Connect supports ASCII characters only in usernames; names containing umlauts or other UTF-8/UTF-16 characters may therefore fail even with the correct password.

Connection is green, but traffic or internet access is missing

In Log Viewer, check whether traffic from the VPN zone matches the expected rule. If there are no hits, check client routes, Permitted network resources, source and destination networks and Packet Capture; if the rule matches, narrow the issue down to routing, the return path, DNS and NAT. Device Access is only relevant here if the firewall itself is the target, for example for DNS or ping. For Full Tunnel, VPN to WAN and SNAT must be correct. Continue with Sophos Firewall IPsec VPN troubleshooting for deeper tunnel analysis.

Client or provisioning uses old values

After general changes, re-export manually distributed .scx and .tgb files; if only Advanced Settings changed, replace only .scx. Remove old versions from circulation. For .pro, first check VPN Portal availability, the portal port, gateway, certificate, user sign-in and MFA. With Entra SSO, gateway must match the Redirect URI.

Connection drops approximately every four hours

During IKEv1 rekeying, another OTP request can disconnect the tunnel. Fix IPsec Remote Access timeouts after four hours explains the cause, a longer rekey interval and the security trade-off.

Large transfers stall or IPsec fails only on external networks

If sign-in, DNS and small transfers work but larger transfers fail, check MTU and MSS. If IPsec fails only in hotels, guest Wi-Fi, mobile or tightly filtered corporate networks, that network may block IPsec. In that case, check whether SSL VPN or another Remote Access design suits these users better.

FAQ

Can Sophos Connect be tested from the LAN zone?

No. SFOS does not support IPsec Remote Access connections from the LAN zone. For a realistic test, the client must connect through an external network such as a mobile hotspot.

Can a user receive a fixed IPsec VPN address?

Yes. Under Authentication > Users > [user] > IPsec remote access, enable the feature and enter a conflict-free address from the intended VPN addressing plan.