Skip to content
Avanet

Sophos Connect Client Troubleshooting

If Sophos Connect does not connect, diagnosis begins at the endpoint: note the error time, read the message for this attempt under Events, and check only the affected path. Changing firewall rules, VPN policies, or certificates on suspicion makes analysis harder. This runbook covers the client on Windows and macOS; the installation guides for Windows and macOS cover installation.

Narrow down quickly

  1. Record the initial situation: Time with time zone, user, operating system, Sophos Connect version, IPsec or SSL VPN and profile source (.scx, .ovpn or .pro).
  2. Check local network: The physical adapter needs a valid IP address. A public name must be resolvable without a VPN.
  3. Read the event: Under Events, match the entry to the connection attempt. Preserve its exact wording and placeholder values.
  4. Separate client and remote-side faults: If the GUI or service does not start, continue on the endpoint. If the client reaches the gateway but fails at policy, authentication, or IKE, ask the firewall administrator to correlate the attempt.
  5. Check result: Reconnect after exactly one action and note a new time stamp.
  6. Escalate: Pass repeatable errors with event, VPN log and scvpntsr.zip; do not write access data in the ticket.

A status Connected only proves that the tunnel has been established. DNS, routing and access to a permitted internal destination are separate tests.

Read events correctly

The message under Events is the best first filter. However, it does not describe the ultimate cause in every case. For example, DNS resolution failed can only confirm that the client could not resolve the gateway name; Why the resolver used does not respond must be clarified separately.

Network, DNS and provisioning

  • No network connection: Ethernet or WiFi does not have an IP address. First, restore local connectivity without VPN.
  • DNS resolution failed: The gateway name cannot be resolved. Check whether a DNS server is assigned to the physical interface and run nslookup www.sophos.com in Command Prompt on Windows or in Terminal on macOS. At least one IP address is expected. If this public test fails, the next step lies with the local network or provider, not with the VPN policy.
  • DNS resolution failed for gateway: : Hostname in provisioning is invalid; for imported .ovpn, the firewall admin must check the SSL VPN settings.
  • Cannot connect to policy gateway: : Windows provisioning only. Compare gateway and user_portal_port with the gateway and the VPN Portal HTTPS port. Also check for a blocked outbound port or an unavailable policy gateway.
  • Import file contains a duplicate connection: : Windows provisioning only. Give each duplicate display_name value in the .pro file a unique name.
  • The connection data could not be added. Connection with name already exists: Check already imported connection and only delete it if the current profile source is available for re-import.

Authentication and profile status

  • User authentication of failed: Repeat entry carefully once. If the error repeats, the firewall admin must check the password status, user and VPN authorization. Multiple guesses can trigger locking mechanisms.
  • Server expected remote ID but got : Local ID on firewall and client profile do not match. Obtain current profile from firewall admin.
  • Possible pre-shared key mismatch : IPsec only. Preshared key and exported profile are not the same; do not transfer the key in the ticket or chat.
  • No SSL VPN policy is defined for this user: : The SSL VPN remote access policy does not contain matching members. This is a firewall-side authorization task.
  • The Single sign-on (SSO) option is grayed out: Windows only from Sophos Connect 2.4. In the .ovpn or .scx profile, sso_api_port and sso_api_domain are missing; import an updated configuration.
  • SSO Authentication failed due to Webview2 setup error: Repair or update WebView2 and the Windows update status; the client could not open the Microsoft login page.

IPsec events

  • UDP ports 500/4500 blocked: Local firewall or router blocks IKE/NAT-T. If you don’t manage the router, check with a mobile hotspot. If the same client works there, that is a strong indication of the original network path.
  • No response from gateway: : The IPsec gateway is not responding to IKE. The firewall admin must check accessibility and public WAN connection.
  • Received NO_PROPOSAL_CHOSEN notification from gateway: The Sophos Connect policy is inactive, or its phase 1 proposal no longer matches the exported profile. Do not weaken proposals blindly; compare the policy and profile in a controlled manner.
  • SA disabled or deleted by gateway: The gateway deleted the SA, for example after a policy change or manual disconnection. Reconnect once; correlate with the firewall timestamp when repeated.
  • Failure to add route [network/mask] prevented phase 2 completion: Windows only. After Phase 2 SA was set up, the route could not be set. Deactivate and reactivate the TAP adapter. If the error persists, open Command Prompt as administrator:
net stop scvpn
net start scvpn

The service is then expected to be running again and a new connection attempt will set the route. Stopping breaks existing Sophos Connect tunnels on this device.

  • Failed to load connection info into strongSwan: Windows only; charon-svc.exe or the strongSwan service is not running. Start in Command Prompt as Administrator:
net start strongswan

If the service does not start or fails again, do not continue in a restart loop, but back up the support report and Windows events.

SSL VPN events

  • Policy mismatch error. Will download policy and retry connection.: A Windows connection created from .pro downloads the changed policy and reconnects automatically. With TCP, the client detects the change while connected; with UDP, the inactivity timer may have to expire first.
  • Policy mismatch error. Import a new policy for this connection.: A manually imported .ovpn is out of date. Obtain and import a new user-specific .ovpn from the VPN portal.
  • Compression mismatch error. Will retry connection.: For .ovpn, reconnect manually; a provisioned connection tries it automatically.
  • Server certificate cannot be verified: . Do you want to continue? During provisioning, the VPN Portal presents a certificate that the endpoint cannot verify, usually the firewall’s self-signed certificate. Continue only after verifying the gateway and certificate through a trusted channel. The firewall administrator should assign a publicly trusted certificate for Admin console and end-user interaction, or distribute the Sophos Firewall CA to managed endpoints’ trust stores. Do not disable certificate validation.
  • Could not connect to untrusted server: : The certificate warning has been canceled. First clarify identity and chain of trust, then try again.
  • Timed out waiting for server response: The SSL VPN override hostname or DDNS record does not resolve to the correct public address, or neither is configured and the WAN interface has no public address. For a Windows .pro connection, use Update policy after the firewall administrator corrects the settings. For .ovpn, download and import a new file.

Fix GUI and service errors

Interface does not open or respond

On Windows, open Task Manager > Details, select scgui.exe, choose End task, and open Sophos Connect from the desktop shortcut. On macOS, open the Sophos Connect process in Activity Monitor, select Force Quit, and open the application from Launchpad. This closes the unresponsive interface; it does not fix the underlying cause. If the problem returns, record the version and preserve scgui.log.

Service is unavailable

On Windows, the event means that scvpn is not running. Open Command Prompt as Administrator:

net start scvpn

For Service Unavailable after a hanging IPsec disconnect on macOS, first close the GUI in Activity Monitor. Then reload the documented service in Terminal with administrator rights:

sudo /bin/launchctl unload -w /Library/LaunchDaemons/com.sophos.connect.scvpn.plist
sudo /bin/launchctl load -w /Library/LaunchDaemons/com.sophos.connect.scvpn.plist

Reopen Sophos Connect and see if the message has disappeared. These commands interrupt the tunnel. If an error recurs, do not reload services repeatedly, but save logs and reports.

More local SSL VPN service errors

  • Management port is unavailable: Sophos Connect could not occupy TCP port 25340 for communication with OpenVPN. Check what other local application is using the port and only terminate it if its function is known. Then reconnect.
  • OpenVPN service is unavailable: If the OpenVPN service startup type is Disabled, change it to Manual, then restart the Sophos Connect service once.
  • Failed to create temporary file: Restart device. The client was unable to create the temporary file to pass connection attributes.
  • Failed to write to pipe or more generally SSL VPN error: Reconnect once. If the error persists, restart the device; then escalate with logs instead of continuously restarting.
  • Sophos Connect can’t establish a tunnel after installing both clients: This official diagnosis concerns the installation order of Sophos Connect and the legacy Sophos SSL VPN Client. If a legacy environment genuinely requires both, Sophos documents this sequence: uninstall both, install the old Sophos SSL VPN Client first, then install Sophos Connect. If the old client is no longer required, do not reinstall it; use the approved target setup.
  • Auto-connect and Update policy are grayed out: These options are unavailable for a manually imported .ovpn. On Windows, create the connection from a .pro file; auto_connect_host enables Auto-connect, and Update policy becomes available after the first successful connection. Provisioning files and these options aren’t available on macOS.
  • An upgrade or uninstall leaves old processes running on macOS with Sophos Endpoint installed: Tamper Protection can prevent Sophos Connect daemons from unloading. Restart the Mac once. If removal is still required, follow the managed macOS removal process rather than killing daemons repeatedly.

Connected but DNS or traffic is not working

First draw a clear dividing line:

  • Internal IP address accessible, internal FQDN not: Check DNS server, search domain and profile status. If DNS changes while an IPsec tunnel is active, Sophos Connect will only show the new values ​​after disconnecting and reconnecting.
  • After a disconnected full tunnel, web access no longer works: Particularly under macOS, internal DNS servers can remain on the physical adapter. Disconnect and reconnect local Wi-Fi or Ethernet connection. If this is repeated, document the version, profile and time; Do not permanently overwrite DNS manually.
  • Neither internal IP nor name accessible: This is not evidence of a client error. Check VPN IP, destination network, return route, NAT and firewall rule on the Sophos Firewall. Check firewall rules with Log Viewer, Policy Test and Packet Capture takes care of this diagnosis.
  • Only IPsec setup or SAs fail: The firewall side runbook is Sophos Firewall IPsec VPN Troubleshooting.
  • SSL VPN policy or gateway configuration is incorrect: The configuration belongs in Setting up SSL VPN Remote Access, not in a client service workaround.
  • Small requests work, large transfers hang: Check MTU/MSS along the path with Check Sophos Firewall MTU and MSS for VPN problems.

Received connection reset from gateway: appears in scvpn.log for SSL VPN when the firewall settings change, an administrator disconnects the user, or Sophos Firewall restarts. Import a current configuration and reconnect. Client logs alone cannot prove which firewall-side action occurred.

Back up logs and technical support reports

To get started, open Events or select Open VPN log from the three-dot menu. Preserve the current failure before restarting: each log is rotated only once. After an endpoint or client restart, for example, the previous session is in openvpn.log.old and the current session is in openvpn.log. The logs have no documented maximum size; .txt files aren’t rotated.

For Received connection reset from gateway, Sophos documents scvpn.log as being in the installation folder but doesn’t publish a version-independent Windows or macOS log-directory path. Don’t guess or hard-code one. Use Open VPN log or the support report so the client resolves the installed location. The macOS service commands above deliberately use the documented absolute path /Library/LaunchDaemons/com.sophos.connect.scvpn.plist.

Sophos Connect generates scvpntsr.zip via three-dot menu > About > Generate technical support report. The archive contains:

  • openvpn.log: SSL VPN connection attempts, status, virtual interface, packet flow and errors.
  • charon.log: strongSwan, IKE, ESP, security events, configuration changes and packet flow.
  • scvpn.log: Login, connection, disconnection and other VPN events.
  • scgui.log: Sophos Connect, OpenVPN and WebView2 versions and SSO logins.
  • configs.txt: Details of imported .pro, .ovpn and .scx connections; Sophos describes this file as containing no personal information.
  • route.txt: Endpoint routing tables.
  • ipconfig.txt: IP configuration of the endpoint.
  • systeminfo.txt: Endpoint system information.

The report still contains configurations and endpoint data and is treated as confidential support material. Before passing on, store it in accordance with internal guidelines and only make it available to authorized bodies.

Escalate cleanly

An actionable case contains operating system and build, Sophos Connect version, profile type and source, error time with time zone, exact event text, expected destination, result by IP and by name, and scvpntsr.zip. If there is suspicion on the firewall side, the corresponding log viewer excerpt and the relevant IPsec or SSL VPN logs are added; Sophos Firewall Services and Logs classifies them.

Escalate if a service fails again after a single controlled start, the same error is reproducible in a shared profile, certificate identity remains unclear, or client and firewall timestamps conflict. A support case can be submitted in a structured manner using Prepare and open Sophos support ticket.

FAQ

Should you re-import the profile first if a Sophos Connect error occurs?

No. First save the timestamp and event. A new import is appropriate if the message explicitly shows a policy, ID, PSK or profile status conflict. Otherwise it can obscure the original condition.

Is Connected proof that VPN access works?

No. Additionally check VPN IP, internal name resolution, a permitted destination and the expected firewall rule. This means that the tunnel, DNS and policy are confirmed separately.

Can scvpntsr.zip be sent directly via email?

Only if internal data protection and support regulations allow this. The archive contains VPN configurations, logs, routing, IP and system information and belongs in a controlled transmission path.