Skip to content
Avanet

Install Sophos Connect Client on Windows

Sophos Connect is the central Sophos client for many remote access scenarios with Sophos Firewall. On Windows, the client can use IPsec and SSL VPN connections depending on the firewall configuration. The client version, Windows platform, configuration file and firewall setup must all be compatible.

This guide covers installation on Windows and the most important checks after importing the connection. To choose between IPsec, SSL VPN, mobile clients and ZTNA, first read Sophos Connect or SSL VPN: Which remote access solution is right?.

Which article should I use?

Sophos Connect on Windows is only one part of remote access operations. A different starting point may suit your task better:

This separation prevents troubleshooting in the wrong place. An installed client does not prove that VPN Portal, authentication, the profile, firewall rules, DNS and the return path are configured correctly.

Requirements

  • Sophos Firewall with a configured remote access setup
  • Sophos Connect Client in a version compatible with the firewall and platform
  • Windows 10 or Windows 11, as 64-bit or Windows ARM with current Sophos Connect versions
  • Configuration file for IPsec (.scx) or SSL VPN (.ovpn), or a provisioning file (.pro)
  • No old Sophos SSL VPN Client installed in parallel
  • User account with VPN permission and working MFA, if enabled
  • Firewall rules for traffic from the VPN zone or the remote access zone in use

To use Sophos Connect with Microsoft Entra ID SSO, Windows requires Sophos Connect 2.4 or later and a suitable SSO configuration on the firewall. The procedure is covered in Set up Microsoft Entra ID SSO for Sophos Connect and VPN Portal.

Sophos Connect supports Windows ARM from version 2.5. If old software packages are still distributed internally, verify which version is actually installed before rollout. For the rollout, pilot group and update check, see Check and safely update the Sophos Connect Client version.

The platform boundary also matters: plan new deployments of current Sophos Connect versions for Windows 10 or Windows 11. Do not continue old 32-bit installations as the new standard merely because older client versions once supported them.

1. Download Sophos Connect Client

Download Sophos Connect Client either through the VPN Portal of the Sophos Firewall or directly from the Sophos website. By default, VPN Portal is available at https://<Firewall-FQDN>:443. After signing in, go to VPN > Sophos Connect client > Download for Windows to download the Windows installer.

In managed environments, individual users should not install arbitrary client versions. Use a defined package with an approved version, rollout group and rollback plan. This is especially important when using Windows ARM, SSL VPN through Sophos Connect or provisioning files.

Update Sophos Connect regularly. New releases include not only feature changes but also updated components such as OpenVPN, strongSwan and OpenSSL.

For larger environments, the installation source must be unambiguous. If old MSI files, a VPN Portal download and software distribution exist at the same time, the helpdesk can quickly deploy inconsistent client versions.

2. Install Sophos Connect Client

Before installation, remove any existing old Sophos SSL VPN Client. Sophos Connect cannot run in parallel with another VPN client that is already installed. According to Sophos, upgrading Sophos Connect is not a simple in-place update either: uninstall the existing version, then install the current version.

Start the installation using SophosConnect.msi. Accept the licence terms, click Install, then complete the wizard with Finish.

After installation, verify the version directly in the client or through software inventory. This is particularly important for Windows ARM, Entra SSO, provisioning files and recurring service errors, because small version differences can change the symptoms.

Sophos Connect Client Setup for Windows
Sophos Connect is installed using the Windows MSI and should come from an approved source.
Sophos Connect Client Setup for Windows - installation process
The required Sophos Connect components and services are installed during setup.
Sophos Connect Client Setup for Windows - installation complete
After installation, the client is available but does not yet contain an imported connection.

3. Download the connection file

When first launched, Sophos Connect requires a connection configuration. Depending on the remote access design, this is an IPsec, SSL VPN or provisioning file.

Typical connection files:

  • IPsec Remote Access: .scx; exported from the Remote Access IPsec configuration.
  • SSL VPN: .ovpn; from VPN Portal or an administrative export.
  • Automatic import through provisioning: .pro; a centrally prepared provisioning file.

For a classic IPsec configuration, export the file in WebAdmin:

  1. On Sophos Firewall, open VPN > Sophos Connect Client.
  2. Export the connection.
  3. Store the file securely and distribute it only to authorised users.

For SSL VPN, the configuration is usually provided through VPN Portal or the remote access configuration. The exact source depends on how remote access is configured on the firewall. The detailed procedure for .ovpn import, VPN Portal and SSL VPN tests is described in Set up Sophos SSL VPN with Sophos Connect on Windows.

Distribute profiles in a controlled manner. After changing the gateway, certificate, DNS, user group, IP pool, SSO or authentication, do not rely on old files in download folders. Re-export and re-import the affected connections, or update them correctly through provisioning.

A .pro file does not simply contain the gateway for the subsequent VPN tunnel. Sophos Connect first uses the gateways defined in the file to reach VPN Portal and retrieve the .scx and .ovpn configurations assigned to the user. The tunnel then uses the gateways in those configuration files.

Check these provisioning requirements deliberately:

  • IPsec provisioning requires Sophos Connect 2.1 or later.
  • Remote users need access to VPN Portal. For access from the WAN, VPN Portal must be allowed for the WAN zone under Administration > Device access > Local service ACL. This increases the publicly reachable attack surface, so use MFA, a valid certificate and portal hardening.
  • The gateway in the .pro file must be reachable as an FQDN or IPv4 address. With Entra ID SSO, this value must match the Redirect URI of the Entra ID server on the firewall.
  • The default locally signed portal certificate can cause an Untrusted certificate error during provisioning. For production rollouts, VPN Portal should use a certificate trusted by the clients.
  • Depending on the profile, changes are retrieved through Edit connection > Update policy. After SSO, certificate or fundamental profile changes, still verify whether the current file must be imported again.

A provisioning file simplifies distribution but does not replace technical acceptance of the connection. For setup and GPO distribution, see Configure Sophos Connect on Sophos Firewall.

4. Set up Sophos Connect Client

Setup takes only a few steps:

  1. Open Sophos Connect.
  2. Select Import Connection.
  3. Import the appropriate connection file.
  4. Check the connection under Connections.
  5. Click Connect.
  6. Sign in with the VPN user and confirm MFA, if enabled.

After a successful sign-in, Sophos Connect should show the connection as connected. Do not stop at the green status: test DNS, internal destinations and firewall rules. If the connection is established but no traffic flows, see Test firewall rules with Log Viewer, Policy Test and Packet Capture.

With Entra ID SSO, also verify that the SSO flow uses the expected Microsoft Entra ID server and that Conditional Access or MFA works as intended. A successful local sign-in does not prove that SSO, group mapping and VPN permissions are correct.

On shared Windows devices, the user signing out should select Force SSO re-login in the Sophos Connect menu. This prevents the next user from taking over the existing SSO session and requires them to sign in with their own Microsoft Entra ID account.

Sophos Connect on Windows - GUI
The connected client shows network details relevant to DNS and access tests.
Sophos Connect on Windows - import configuration
Import the connection file deliberately; do not reuse old profiles without checking them.
Sophos Connect on Windows - sign-in
When the connection starts, the client requests the user sign-in and, depending on the design, MFA or SSO.
Sophos Connect on Windows - connection properties
Connection properties help with support cases, profile comparisons and fault analysis.

Checks after installation

Check the following after installation:

  • The Sophos Connect version matches the platform, especially for Windows ARM.
  • The imported file matches the intended protocol: IPsec or SSL VPN.
  • The user is authorised in the correct VPN group.
  • MFA works and does not block the connection process.
  • The client receives a suitable VPN IP address.
  • Internal DNS names resolve.
  • Firewall rules for the VPN zone allow only the required destinations.
  • Old profiles have not been reused accidentally.

If legacy Remote Access IPsec configurations still exist before an SFOS 22 MR1 upgrade, first read Migrate legacy Remote Access IPsec before SFOS 22 MR1.

Acceptance test for Windows

A green client status is not sufficient for acceptance. For a reliable rollout, a test user should verify the following:

  1. Check client version: The version matches Windows 10/11, Windows ARM and the internal release.
  2. Import profile: .scx, .ovpn or .pro is recognised correctly.
  3. Test SSO: Entra SSO starts only where intended.
  4. Test MFA: OTP, RADIUS MFA or Entra MFA behaves as documented.
  5. Test DNS: Internal FQDNs resolve correctly.
  6. Test access: Permitted destinations work and unauthorised destinations remain blocked.
  7. Check Log Viewer: Traffic from the VPN zone matches the expected firewall rule.
  8. Test reconnect: Network changes, standby and reconnection are traceable.

In mixed environments, test at least one standard Windows 10/11 device and one Windows ARM device if ARM is used in production. If macOS clients are also used, document their behaviour separately.

Rollout notes for managed Windows clients

Manual installation may be sufficient for a small number of users. In larger environments, manage Sophos Connect through the normal software distribution or endpoint management system.

Clarify the following before a broad rollout:

  • Which Sophos Connect version is approved?
  • Which Windows versions and CPU architectures are in use?
  • Is IPsec, SSL VPN, Entra SSO or provisioning used?
  • Are there users with OTP, RADIUS MFA or Entra MFA?
  • How are new profiles distributed?
  • How are old profiles removed or marked as obsolete?
  • How is Sophos Connect uninstalled before an upgrade and reinstalled afterwards?
  • How is Force SSO re-login enforced on shared devices?
  • Who checks DNS, firewall rules and reconnect behaviour after client updates?
  • Which logs and screenshots does the helpdesk need for support cases?

On shared Windows devices, verify that Sophos Connect starts reliably for all affected users. Sophos Connect 2.5 MR1 includes a fix for an issue where the client did not start automatically for additional Windows users when it had been installed by another user.

Troubleshooting

Sophos Connect does not start or shows service errors

First verify that the Sophos Connect service is running and that a current client version is installed. For older installation packages, a clean reinstallation of the approved version is usually worthwhile. If several Windows users share the same device, also check that the client starts automatically and correctly in each user context.

The connection imports but does not connect

The usual causes are user permissions, MFA, the certificate, preshared key, firewall version or an incorrect file type. Do not mix IPsec and SSL VPN profiles. For provisioning files, also check the gateway, VPN Portal port, certificate, SSO configuration and reachable Microsoft endpoints when Entra SSO is involved.

Provisioning shows Untrusted certificate or does not load a profile

First verify that the gateway entered in the .pro file is reachable and that the WAN zone can access VPN Portal under Administration > Device access > Local service ACL. Then check the certificate chain, FQDN, VPN Portal port and, for Entra ID SSO, whether the value matches the Redirect URI. The firewall’s default locally signed certificate is not an appropriate trust basis for a managed production rollout.

SSO status is unclear after an internet interruption

In Entra SSO environments, an internet interruption can produce confusing status information. Sophos Connect 2.5 MR1 includes a fix for SSO users. Nevertheless, verify whether the tunnel is actually disconnected, whether the client is reconnecting and whether the firewall uses the expected Microsoft Entra ID server under Authentication > Services.

OTP is requested differently during reconnect

If users with classic OTP or MFA use IPsec and SSL VPN in parallel, test the reconnect behaviour. Sophos Connect 2.5 MR1 fixes a difference in sign-in verification between IPsec and SSL VPN for credential users with OTP.

The connection is established, but internal systems are unreachable

In this case, the cause is often not the client but firewall rules, routing, DNS or NAT. Log Viewer should show whether traffic from the VPN zone matches the expected rule. For IPsec-specific cases, see Sophos Firewall IPsec VPN troubleshooting.

The connection no longer works after a profile change

After changing the gateway, certificate, VPN Portal port, DNS, IP pool, user group, Entra SSO or authentication, redistribute or re-import the profile. A client update does not automatically replace an old profile.

The connection is established, but large transfers stall

If sign-in, DNS and small requests work but large file transfers or certain applications stall, also check MTU/MSS. This pattern often indicates fragmentation, PPPoE, nested tunnels or an asymmetric path. The procedure is described in Check Sophos Firewall MTU and MSS for VPN issues.

Collect support data

If the cause is not immediately visible, document the time, user, Windows version, CPU architecture, Sophos Connect version, profile type, source network and destination system. In Sophos Connect, three-dot menu > About > Generate technical support report creates scvpntsr.zip. It contains VPN configurations, connection events and endpoint information and should only be shared with authorised recipients in a controlled manner.

On the firewall, use Log Viewer, sslvpn.log, IPsec logs, Packet Capture and the affected firewall rule in parallel. The log file mapping is described in Sophos Firewall troubleshooting: services and logs.

FAQ

Which operating systems are compatible with Sophos Connect Client?

Current Sophos Connect versions support Windows 10 and 11 as 64-bit systems. Windows ARM is supported from Sophos Connect 2.5.

Is macOS supported for SSL VPN?

Yes. Since Sophos Connect 2.0, Sophos Connect Client on macOS can also use Remote Access SSL VPN. For details, see Install Sophos Connect Client on macOS.

Can Sophos Connect Client be used on mobile platforms?

No. Sophos Connect does not directly support mobile platforms such as Android and iOS for IPsec and SSL VPN. Depending on the protocol, use operating system features or OpenVPN-compatible clients.

Does Sophos Connect Client support Windows ARM?

Yes. Windows ARM is supported from Sophos Connect 2.5.

Does Sophos Connect support Entra ID SSO on Windows?

Yes. Sophos Connect supports Microsoft Entra ID SSO on Windows with Sophos Connect 2.4 or later and SFOS 21.5 or later. The firewall and Entra configuration must be set up accordingly.

When do I need a provisioning file?

A .pro file allows Sophos Connect to retrieve the .scx and .ovpn configurations assigned to the user automatically from VPN Portal. This simplifies distribution and updates but requires a reachable VPN Portal with a trusted certificate and does not replace checks of SSO, MFA, DNS and firewall rules.

Must profiles be re-imported after a firewall change?

Yes, after changing the gateway, certificate, VPN Portal port, DNS, IP pool, user group, SSO or authentication. Otherwise, the client continues to use old connection details.

Can Sophos Connect Client be used with older Windows versions?

For current Sophos Connect versions, plan for Windows 10 or 11. Older Sophos Connect versions had different platform support tables but should not be used as the target standard for new rollouts.