Skip to content
Avanet

Set up Sophos SSL VPN with Sophos Connect on macOS

SSL VPN on macOS was previously often set up with Tunnelblick or other OpenVPN clients. That remains possible, but it is no longer the only obvious option: since Sophos Connect 2.0, Sophos has also supported Remote Access SSL VPN on macOS.

This article describes the current standard approach using Sophos Connect on macOS and explains where OpenVPN-compatible clients fit as an alternative. To decide between Sophos Connect, SSL VPN, IPsec, mobile clients and ZTNA, start with Sophos Connect or SSL VPN: Which remote access solution is right?.

Decision and requirements

Which macOS VPN article is relevant?

These instructions apply to Sophos Firewall with SFOS and SSL VPN on macOS. Depending on the task, a different starting point may be more appropriate:

Sophos Connect does not directly support mobile platforms such as iOS and Android for IPsec and SSL VPN. OpenVPN-compatible clients or operating system features remain relevant on those platforms.

Requirements

  • Sophos Firewall with a configured SSL VPN remote access setup
  • User authorised for SSL VPN
  • Access to the VPN Portal or an administratively provided .ovpn file
  • Sophos Connect 2.0 or later
  • macOS Ventura 13 or later with Sophos Connect 2.0+
  • Mac with an Intel processor or Apple Silicon using Rosetta 2
  • no old Sophos SSL VPN Client installed in parallel
  • MFA/OTP configured if remote access is protected by it
  • firewall rules for traffic from the VPN zone

If the firewall-side SSL VPN configuration is not yet in place, set up Sophos Firewall SSL VPN Remote Access first.

Before an SFOS 22 MR1 upgrade, also check whether any legacy remote access IPsec configurations remain. SSL VPN is not directly affected, but many organisations reassess remote access at this point. The process is described in Migrate legacy remote access IPsec before SFOS 22 MR1.

Sophos Connect or an OpenVPN-compatible client?

For new macOS rollouts, evaluate Sophos Connect first because it is the Sophos client and has supported SSL VPN on macOS since version 2.0. OpenVPN Connect or Tunnelblick remain alternatives, but they should not inadvertently become a second, unplanned standard.

  • Sophos Connect: Suitable for managed Macs, a consistent support process and current SFOS environments. Important factors are the version, macOS requirements, Rosetta 2 on Apple Silicon and a current .ovpn profile.
  • OpenVPN Connect, Tunnelblick or another OpenVPN client: Suitable for an established OpenVPN process, special cases or a deliberate alternative to Sophos Connect. Important factors are the OpenVPN version, the correct download format, profile maintenance, DNS behaviour and clearly documented support ownership.

The client name matters less than the operating model: it should be clear which client is supported, which version is deployed, where the profile comes from and when users must import a new profile.

Set up Sophos Connect on macOS

1. Deploy Sophos Connect for macOS

Depending on the environment, Sophos Connect can be provided through Sophos Firewall, the VPN Portal or the Sophos Download Page. In managed environments, document which client version is deployed and whether Rosetta 2 is available on Apple Silicon devices.

SSL VPN on macOS requires Sophos Connect 2.0 or later. Do not continue using older internal instructions or installation packages without checking them. An existing old Sophos SSL VPN Client must be removed before installation because it cannot run in parallel with Sophos Connect.

Sophos Connect 2.0 MR1 includes several macOS-specific fixes, including DNS settings for SSL VPN connections and the option to save credentials. After an upgrade, reimport the profile if this option is required.

2. Obtain the OVPN configuration

The SSL VPN configuration is provided as an .ovpn file. Depending on the operating model, users download it from the VPN Portal or receive it through a controlled administrative process.

For Sophos Connect on macOS, follow these steps in the VPN Portal:

  1. Open the Sophos Firewall VPN Portal. The default address is https://<Firewall-FQDN>:443 unless the port has been changed.
  2. Sign in as the VPN user.
  3. Go to VPN.
  4. Under Sophos Connect client, select Download for macOS if the client has not already been centrally deployed.
  5. Under VPN configuration, select Download configuration for Windows, macOS, Linux for the required SSL VPN configuration.
  6. For Sophos Connect, select Use with Sophos Connect and OpenVPN Connect v2 clients. The OpenVPN Connect v3 option is intended for a corresponding OpenVPN v3 client.
  7. Store the .ovpn file securely and use it only for the authorised user.

SSL VPN on macOS currently uses the .ovpn file. Automatic .pro provisioning for SSL VPN is available in Sophos Connect only on Windows. Policy changes or changes to global SSL VPN settings therefore do not reach the Mac automatically; after relevant changes, download and import a current .ovpn file.

If the browser warns about the portal certificate, investigate the cause. In production environments, a valid VPN Portal certificate is preferable to a permanent browser exception. For hardening guidance, see Device Access and Local Service ACL on Sophos Firewall.

After changes to the gateway, port, certificate, DNS, lease range, authentication or SSL VPN policy, download and import the profile again. Updating the client alone does not update an old .ovpn profile.

3. Import the connection into Sophos Connect

Open Sophos Connect and import the .ovpn file. The connection should then appear in the connection list. If there are several profiles, use a clear name so that users and support staff do not accidentally select the wrong one.

If the import fails, first check the client version, file type and source of the configuration file. SSL VPN on macOS requires Sophos Connect 2.0 or later. Do not treat a profile downloaded for OpenVPN Connect v3 as a Sophos Connect profile.

When Microsoft Entra ID SSO is used, the profile must contain the current SSO configuration. If SSO stops working after a change, download and import the .ovpn file again. The firewall-side setup is described in Set up Microsoft Entra ID SSO for Sophos Connect and VPN Portal.

4. Establish the VPN connection

Select the imported connection and click Connect. Then sign in as the VPN user. If MFA or OTP is enabled, confirm the second factor as configured on the firewall.

After connecting, do not rely solely on the client status. What matters is whether the required internal destinations are reachable.

Verify the connection

Checks after installation

Test at least the following points with a test user:

  • Sophos Connect shows the connection as connected.
  • The user receives an IP address from the expected SSL VPN pool.
  • Internal DNS names resolve correctly.
  • Required servers and applications are reachable.
  • Internet behaviour matches the design: split tunnel or full tunnel.
  • Log Viewer shows the expected firewall rule for traffic from the VPN zone.
  • MFA is requested as planned.
  • Disconnecting and signing in again work.

If the connection is established but access does not work, the cause is often not the client but firewall rules, DNS, routing or NAT. For analysis, see Test firewall rules with Log Viewer, Policy Test and Packet Capture.

Acceptance test on macOS

After setup, document a genuine test case rather than only the green client status.

  1. Check the Sophos Connect version: The client version is compatible with the macOS version and supports SSL VPN.
  2. Test Apple Silicon: Rosetta 2 is available and the client starts reliably.
  3. Check the profile import: The .ovpn profile comes from the current firewall configuration.
  4. Test MFA: Sign-in with the correct and an incorrect factor behaves as expected.
  5. Test DNS: Internal names resolve correctly, not only IP addresses.
  6. Test access: Permitted destinations work and non-permitted destinations remain blocked.
  7. Check Log Viewer: Traffic from the VPN zone matches the expected firewall rule.
  8. Test reconnecting: Disconnecting and reconnecting work without changing profiles.

If the organisation uses several macOS versions, test at least one Intel Mac and one Apple Silicon Mac. In mixed-client environments, also check that Sophos Connect and Tunnelblick do not use different profiles or produce different DNS results.

Alternative: OpenVPN-compatible client

OpenVPN Connect or Tunnelblick can still be appropriate when Sophos Connect is not required or an existing OpenVPN process is deliberately retained. Document this approach as a separate operating standard so that Sophos Connect, several OpenVPN clients and old profiles do not circulate in parallel.

In the VPN Portal, the downloaded configuration option must match the client in use. Then check the .ovpn file, user sign-in and DNS behaviour. Do not adopt old blanket requirements for a particular OpenVPN version without verification; the current firewall version, client version and specific profile are what matter.

Operations and security

SSL VPN is a publicly accessible remote access service. Documentation should therefore cover not only installation but also ongoing operation:

  • Update Sophos Connect or the OpenVPN client regularly.
  • Enable and test MFA for remote access.
  • Review VPN groups regularly.
  • Restrict portal access through Device Access and Local Service ACL where possible.
  • Keep firewall rules for the VPN zone narrowly scoped and enable logging.
  • Remove old .ovpn files and outdated profiles.
  • Plan for syslog or central analysis if logs must be retained for longer periods.

For MFA fundamentals, see Enable MFA for Sophos Firewall WebAdmin, VPN Portal and Remote Access. For log files and service logs, see Sophos Firewall troubleshooting: services and logs.

macOS rollout checklist

  • The supported default client is defined: Sophos Connect or a deliberately selected OpenVPN client.
  • The Sophos Connect version is suitable for macOS Ventura 13 or later.
  • Rosetta 2 has been included in the rollout for Apple Silicon devices.
  • The .ovpn profile comes from the current SSL VPN configuration.
  • The download option matches Sophos Connect or the OpenVPN client version in use.
  • The lack of a .pro automatic update path on macOS is accounted for in the profile process.
  • The VPN Portal uses a valid certificate.
  • The user is included in the correct SSL VPN policy.
  • MFA behaviour is documented and tested with a test user.
  • DNS, the search domain and internal target systems have been tested on macOS.
  • Firewall rules for the VPN zone log the test traffic.
  • After profile changes, it is clear who informs users that they must reimport the profile.

Troubleshooting

Sophos Connect does not import the OVPN file

First check whether Sophos Connect 2.0 or later is installed and whether the file really comes from the current SSL VPN configuration. Then download the file again from the VPN Portal or redeploy it through the administrative process.

Internal names do not resolve

Check the DNS servers, search domains and SSL VPN configuration on the firewall. For Sophos Connect on macOS, also check the client version because Sophos fixed a DNS issue affecting SSL VPN connections on macOS in version 2.0 MR1.

If IP addresses work but names do not, the issue concerns DNS or the search domain. If IP addresses do not work either, routing, firewall rules or the return path are more likely causes.

The connection is established, but internal systems are unreachable

Check firewall rules, routing, NAT and the return path. Traffic from the VPN zone should be visible in Log Viewer. If no logs appear, the traffic probably does not reach the expected rule or logging is disabled.

If small requests work but larger file transfers or certain applications stall, also check MTU/MSS: Check Sophos Firewall MTU and MSS for VPN problems.

The connection no longer works after a profile change

After changes to the gateway, certificate, port, DNS, lease range or authentication, reimport the .ovpn profile. If only the client is updated while an old profile remains in use, it may continue to use old destinations, ports or DNS values.

The option to save credentials is not visible

Sophos re-enabled the option to save credentials in Sophos Connect 2.0 MR1 for macOS. After the update, reimport the configuration to make the option available. In environments with MFA, still check whether storing credentials fits the security model.

The connection drops on external networks

SSL VPN is often more tolerant than IPsec, but it is not immune to restrictive networks, captive portals, enforced proxies or unstable Wi-Fi. In these cases, test with a second network and assess whether split tunnel, the port, the protocol or ZTNA is a better fit.

Collect support data

If the problem is not immediately apparent, document the client logs, time, user, source network and target system. In the Sophos Connect Client, use three-dot menu > About > Generate technical support report to create a support package. The file is named scvpntsr.zip and contains connection events, configuration information and endpoint data. Before sharing it, check who is authorised to receive this information.

On the firewall, Log Viewer, sslvpn.log, openvpn-status*.log and the relevant firewall rule provide additional evidence. The log file mapping is documented in Sophos Firewall troubleshooting: services and logs.

FAQ

Does Sophos Connect support SSL VPN on macOS?

Yes. Since Sophos Connect 2.0, the Sophos Connect Client on macOS can use Remote Access SSL VPN.

Does Sophos Connect work on Apple Silicon?

Yes. Sophos Connect 2.0 and later supports Macs with Apple Silicon through Rosetta 2. Managed environments should therefore include Rosetta 2 in the rollout.

Is Tunnelblick still required?

Not necessarily. Tunnelblick remains an OpenVPN alternative, but Sophos Connect is the more manageable default client for many environments.

Why does DNS not work on macOS even though the SSL VPN connection is established?

Common causes include the DNS servers, search domain, an outdated profile or the client version. Sophos Connect 2.0 MR1 includes a fix for DNS settings with SSL VPN on macOS. The profile and firewall rules should still be checked separately afterwards.

Can Sophos Connect be used for SSL VPN on iOS or Android?

No. Sophos Connect does not directly support mobile platforms for IPsec and SSL VPN. Depending on the protocol, iOS and Android use OpenVPN-compatible clients or operating system features.