Sophos Connect or SSL VPN: Which remote access solution fits?
Sophos Connect and SSL VPN aren’t direct alternatives: Sophos Connect is the client software; IPsec and SSL VPN are tunnel types that this client can establish on supported Windows and macOS devices. There is no Sophos Connect client for Linux or mobile devices. On those platforms, use an OpenVPN-compatible client for SSL VPN and evaluate an appropriate operating-system or third-party client separately for IPsec.
For most managed Windows and macOS devices, Sophos Connect is the sensible default client. You then choose between IPsec and SSL VPN. This article has been checked against SFOS 22.0 MR2 and the client lines current on September 8, 2026: Sophos Connect 2.5 MR1 for Windows and 2.0 MR1 for macOS.
⚠️ Don’t use PPTP for new deployments. SFOS 22 can still configure PPTP, but the protocol itself defines neither encryption nor authentication. PAP, CHAP, or MS-CHAPv2 don’t make it a modern target architecture. Inventory existing dependencies and migrate them to current IPsec, SSL VPN, or application-specific access.
Decide in one minute
- Managed Windows or macOS devices, with IPsec stable in the pilot: Sophos Connect with current remote access IPsec is usually the first choice.
- IPsec fails in hotels, guest networks, or tightly filtered external networks: Test Sophos Connect with SSL VPN. SSL VPN often passes such networks more easily, but this is an operational tendency, not a guarantee.
- Linux, iOS, iPadOS, or Android: Use an approved OpenVPN client for SSL VPN. OpenVPN isn’t an IPsec client; validate an IPsec solution separately against the platform and SFOS profile.
- Only a few fixed applications or RDP/SSH targets: Evaluate clientless SSL VPN or Sophos ZTNA instead of granting broad network access.
- Legacy Remote Access IPsec exists: Migrate and delete it before upgrading to SFOS 22.0 MR1 or later.
Make the final choice only after a pilot using the real platform, authentication, MFA, user network, and required internal targets. A green tunnel status alone isn’t a successful access test.
ZTNA is the narrower fit when users need only defined applications and identity- and device-based access instead of network reachability. It doesn’t replace a VPN for every administration tool, protocol, or complex network path.
Keep client, protocol, and platform separate
The following planning limits apply when choosing a client. Because versions, platform support, and known issues change, Check and safely update the Sophos Connect Client version covers version selection, piloting, acceptance testing, and rollback planning before a rollout or update:
| Platform | Tunnels with current client | Profile delivery |
|---|---|---|
| Windows 10/11, 64-bit | IPsec and SSL VPN with the 2.5 line | .scx, .ovpn, and .pro |
| Windows 10/11 on ARM | IPsec and SSL VPN from 2.5 | .scx, .ovpn, and .pro |
| macOS / Sophos Connect before 2.0 | IPsec: .scx; SSL VPN: third-party client .ovpn | no .pro |
| macOS 13+, Intel / 2.0 | IPsec and SSL VPN | .scx, .ovpn; no .pro |
| macOS 13+, Apple Silicon / 2.0 | IPsec and SSL VPN; Rosetta 2 | .scx, .ovpn; no .pro |
| macOS 14+, Intel / 2.1+ | IPsec and SSL VPN | .scx, .ovpn, .pro |
| macOS 14+, Apple Silicon / 2.1+ | IPsec and SSL VPN; native ARM | .scx, .ovpn, .pro |
| Linux | Linux: SSL VPN with OpenVPN; check IPsec separately | .ovpn |
| Android / iOS | Android and iOS: see file paths below | .tgb, .ovpn / VPN Portal |
For new Windows deployments, use the 2.5 line: it supports 64-bit Windows 10 and 11 and Windows on ARM. Windows 11 Enterprise Multi-session, including Azure Virtual Desktop, isn’t supported. Old 32-bit Windows systems stop at Sophos Connect 2.4 and belong in an operating-system migration plan, not a new VPN target architecture.
Separate the macOS client branches: before 2.0, Sophos Connect uses .scx for IPsec, while SSL VPN requires a third-party client with .ovpn. With 2.0, IPsec (.scx) and SSL VPN (.ovpn) are imported directly; macOS 13+ is supported, and Apple Silicon uses Rosetta 2. From 2.1, the baseline is macOS 14+; Intel and Apple Silicon are supported, with native ARM on Apple Silicon. .pro provisioning is now documented for both VPN types. Manual profiles remain an option. Before rollout, check the package version, architecture and files actually available from the portal, and validate each combination in a pilot. Microsoft Entra ID SSO is documented for Windows from Sophos Connect 2.4 and macOS from 2.1, not macOS client 2.0. A compatible SFOS setup and a current client configuration are required. Check authentication methods and the Redirect URI; MFA remains a separate checkpoint. This does not imply an identical browser flow or that Windows GPO deployment applies to macOS. Entra ID SSO for Sophos Connect and VPN Portal
Update to the dated observation: Sophos release notes list Sophos Connect 2.1 for macOS, released on October 6, 2026, with .pro provisioning, Entra ID SSO and native ARM support. The September 24, 2026 observation describes the situation at that time. Check the version of the installer actually available; publication does not prove that your firewall portal already serves that package or that it has been tested on a specific device.
Android: IPsec is documented with a third-party client and .tgb; SSL VPN uses a compatible client with .ovpn. iOS: download the IPsec configuration from VPN > VPN configuration > IPsec VPN profile in the VPN Portal; no additional client is required for that path. SSL VPN uses a third-party client with .ovpn. These are file paths and selection boundaries, not a tested mobile setup.
Choose IPsec or SSL VPN
Sophos Connect with IPsec
IPsec fits managed corporate endpoints when it works reliably across users’ typical networks. It provides good performance in many environments. The actual path and load still need testing; there is no universal performance guarantee.
Its limits include blocked or poorly handled IPsec on external networks and the need to control profile distribution. Current Remote access VPN > IPsec must not be confused with IPsec (legacy). See Configure Sophos Connect on Sophos Firewall for the firewall setup.
Sophos Connect with SSL VPN
SSL VPN fits when OpenVPN-based processes already exist, Linux or mobile devices are in scope, or IPsec repeatedly fails on external networks during the pilot. Windows and macOS can use Sophos Connect; Linux and mobile devices use an OpenVPN-compatible client.
Performance and scale depend on the appliance, encryption, load, and access pattern. See Set up Sophos Firewall SSL VPN remote access for the firewall side. Separate client guides cover Windows, macOS, Linux, iPhone and iPad, and Android.
Migrate from the old Sophos SSL VPN Client
The old Sophos SSL VPN Client and Sophos Connect with SSL VPN both use OpenVPN configuration, but they aren’t the same client generation. Current Sophos Connect installation guidance requires you to uninstall an existing SSL VPN Client before installing Sophos Connect, so side-by-side operation isn’t an appropriate migration path.
Use a controlled migration:
- Inventory users, operating systems, current
.ovpnprofiles, MFA, and required targets. - Test the current SSL VPN policy, certificate, gateway, and firewall rules with a pilot user.
- Prepare the approved Sophos Connect version and a fresh
.ovpnfile from the VPN portal. On Windows, a tested.proprovisioning file is an alternative. For provisioning on Windows and on macOS from Sophos Connect 2.1. - Disconnect the active tunnel, uninstall the old SSL VPN Client on the pilot endpoint, and install Sophos Connect.
- Import the current profile and test sign-in, MFA, VPN address, DNS, allowed targets, and firewall rule hits.
- Roll out only after a successful pilot, then remove old installers and profiles from distribution in a controlled way.
Define the rollback before the pilot: retain the approved old installer and profile securely until acceptance is complete. If the pilot fails, uninstall Sophos Connect before restoring the old client and profile; don’t install both clients side by side. Treat this only as a short-term return to the documented starting state while you correct the migration.
For a Sophos Connect upgrade, uninstall the existing version before installing the new version. Check and safely update the Sophos Connect Client version covers version choice, known issues, piloting, and rollback.
Operate profiles and updates
The file extension identifies the delivery path, not tunnel quality:
.scxis the preferred Sophos Connect profile for current IPsec and includes advanced settings..tgbis an IPsec export for compatible third-party clients and doesn’t include the advanced Sophos Connect settings..ovpnis the user-specific SSL VPN configuration..proretrieves IPsec (.scx) and the user’s authorised SSL VPN configurations (.ovpn) through the VPN Portal and fetches later changes; it is not itself a tunnel profile. Supported clients include compatible Windows clients and Sophos Connect for macOS from 2.1, not macOS client 2.0 or earlier. IPsec provisioning requires Sophos Connect 2.1 or later. On macOS client 2.0, direct imports and controlled manual refresh remain required.
Track approved client versions centrally, give profiles unique names, and avoid distributing .scx, .tgb, .ovpn, and .pro files in parallel without a documented purpose. For mobile devices, define the approved app, profile source, MFA flow, and support owner rather than leaving those choices to each user.
Provisioning still requires VPN Portal reachability, a trusted certificate, MFA, suitable Local Service ACLs and protection against repeated sign-in attempts. Test Windows and macOS from 2.1 separately. Sophos Connect provisioning with .pro
Manually delivered profiles must be exported and imported again in a controlled manner after relevant changes. With provisioning, the client fetches most changes; after changing the SSL VPN port or protocol, users must select gear icon > Update policy for the profile. Gateway, certificate, port, or protocol changes can require another sign-in. Test Windows, macOS, and mobile OpenVPN clients separately.
Security and acceptance testing
The same minimum controls apply to either tunnel type:
- Test MFA with the actual client and reconnect flow.
- With
.proprovisioning, MFA must also succeed before the client can download the configuration. If an OTP or verification code is required, the first connection can show sign-in twice: once to download the configuration and once to establish the tunnel. - Limit users and groups to those who need access.
- Permit only required networks and services in logged rules from the
VPNzone. - Review the VPN portal and other WAN-facing services under Device access and Local Service ACL.
- Renew or revoke profiles when a user leaves, a device is lost, or authentication changes.
A pilot succeeds only when the client receives the expected VPN address, resolves internal names, reaches allowed targets, can’t reach a deliberately forbidden target, and its traffic hits the intended firewall rule in Log Viewer. Also test split- or full-tunnel behavior, MFA, and reconnect after changing networks. See Set up Sophos Firewall MFA; for a connected tunnel without traffic, continue with IPsec VPN troubleshooting, MTU and MSS checks, and firewall rule testing.
SFOS 22: Legacy IPsec blocks upgrades
SFOS 22.0 MR1 and later don’t support Legacy Remote Access IPsec. Merely having a legacy configuration blocks the upgrade. A restore or configuration import can bring it back, and Sophos doesn’t migrate it automatically.
Before upgrading, check Remote access VPN > IPsec (legacy), provide a tested replacement, delete the legacy configuration, and confirm that the upgrade blocker has disappeared. See Migrate Legacy Remote Access IPsec before SFOS 22 MR1 for the complete process. Set up L2TP remote access covers L2TP with an operating-system client; site links belong in Set up site-to-site IPsec VPN.
FAQ
Is Sophos Connect the successor to the old SSL VPN Client?
Is Sophos Connect the same as IPsec?
Does Sophos Connect support SSL VPN on macOS?
.scx for IPsec, while SSL VPN requires a third-party client with .ovpn. With 2.0, IPsec (.scx) and SSL VPN (.ovpn) are imported directly; macOS 13+ is supported, and Apple Silicon uses Rosetta 2. From 2.1, the baseline is macOS 14+; Intel and Apple Silicon are supported, with native ARM on Apple Silicon. .pro provisioning is now documented for both VPN types. Manual profiles remain an option. Before rollout, check the package version, architecture and files actually available from the portal, and validate each combination in a pilot. Microsoft Entra ID SSO is documented for Windows from Sophos Connect 2.4 and macOS from 2.1, not macOS client 2.0. A compatible SFOS setup and a current client configuration are required. Check authentication methods and the Redirect URI; MFA remains a separate checkpoint. This does not imply an identical browser flow or that Windows GPO deployment applies to macOS.