Skip to content
Avanet

Set Up Sophos Firewall Remote Access on Linux

The easiest way to use Sophos Firewall Remote Access on Linux is SSL VPN with the standard OpenVPN client. Sophos Connect is not available for Linux. Download the .ovpn file from the VPN Portal and use it either in the terminal or through NetworkManager.

The previously recommended IPsec alternative using NetworkManager-strongSwan is not compatible with the current Sophos Firewall configuration: Under SFOS 22, Remote access VPN > IPsec only accepts IKEv1 profiles, while the NetworkManager-strongSwan plugin supports IKEv2 exclusively.

⚠️ Do not install an unofficial “Sophos Connect for Linux” and do not change the SFOS Remote Access profile to IKEv2 for this guide. The following OpenVPN method is the Linux path documented by Sophos.

Separate guides are available for other devices: Sophos Connect on Windows and Sophos Connect on macOS, as well as SSL VPN on iPhone and iPad and SSL VPN on Android.

Requirements

  • A Remote Access SSL VPN policy is configured under Remote access VPN > SSL VPN on Sophos Firewall.
  • The user or their group is assigned to this policy.
  • A matching firewall rule allows the required traffic from the VPN zone.
  • Under Administration > Device access, VPN portal is allowed for the required zone. For access from the internet, this is the WAN zone; because this adds exposure, only allow it when needed and protect it against repeated sign-in attempts.
  • The user can access the VPN Portal and sign in. Its default port is 443; the port actually configured is shown under Administration > Admin and user settings.
  • The Linux system has local sudo privileges for package installation and starting OpenVPN.
  • If MFA is enabled, sign-in including the verification code works.

Set up Sophos Firewall SSL VPN Remote Access describes the firewall-side configuration. If the .ovpn is later missing from the VPN Portal, is 0 bytes, or contains only an error message, Sophos Firewall: .ovpn missing or 0 bytes guides through policy, user, certificate, and system checks.

Set up SSL VPN with OpenVPN

1. Install OpenVPN

The following package commands apply to a local Debian or Ubuntu terminal. The first read-only query needs no elevated privileges and shows whether the package was already installed. Record this initial state before making a change:

dpkg-query -W -f='${Status}\n' openvpn 2>/dev/null

install ok installed means OpenVPN is already present. No output generally means that the package is absent. apt then installs the client and any required dependencies from the configured repositories; this requires local sudo rights and current package metadata:

sudo apt install openvpn

As a normal user, openvpn --version verifies that the executable is available. Its first line should identify the installed OpenVPN version:

openvpn --version

If the package was absent before, the direct rollback is sudo apt remove openvpn. This removes the package but normally leaves configuration files behind, so disconnect any active tunnel first and check the recorded initial state. If OpenVPN was already installed, there is nothing to roll back. Repeat the read-only dpkg-query check to validate removal.

Other distributions also provide the package through their package manager; check the distribution’s documentation for the package name and syntax. For graphical management under GNOME, you can additionally install the NetworkManager OpenVPN plugin. First record its previous package state with dpkg-query -W -f='${Status}\n' network-manager-openvpn-gnome 2>/dev/null. The following Debian/Ubuntu command requires sudo and installs the plugin and missing dependencies:

sudo apt install network-manager-openvpn-gnome

After installation, dpkg-query -W -f='${Status}\n' network-manager-openvpn-gnome should report install ok installed; you may need to sign out and back in before the graphical interface offers the plugin. If it was absent before, sudo apt remove network-manager-openvpn-gnome removes it again. Disconnect an active VPN managed by NetworkManager before removal, then repeat the read-only query to confirm the previous absent state. Do not confuse this plugin with network-manager-strongswan: it imports the .ovpn file and uses OpenVPN.

2. Download the OpenVPN configuration

  1. Open the Sophos Firewall VPN Portal in a browser.
  2. Sign in with the VPN user.
  3. Under VPN > VPN configuration, click Download configuration for Windows, macOS, Linux.
  4. Download the .ovpn file and store it securely.

The file can contain embedded certificates, a private key, and user-specific connection data. Do not distribute it through unencrypted email or public storage. If it is compromised, an administrator must revoke it or replace the relevant credentials; deleting the local copy is not sufficient.

3. Start the connection in the terminal

The next commands run in a local Linux terminal. Replace <linux-user> with the local username, and make sure the example path points to the downloaded file. First, stat reads the current numeric file mode without elevated privileges. Record this value in case you need to undo the permission change:

stat -c '%a %n' "/home/<linux-user>/Downloads/sophos-vpn.ovpn"
chmod 600 "/home/<linux-user>/Downloads/sophos-vpn.ovpn"
stat -c '%a %n' "/home/<linux-user>/Downloads/sophos-vpn.ovpn"

chmod 600 grants read and write access only to the file owner; the second query must show mode 600. It needs no sudo if the signed-in user owns the file. To roll back, run chmod <previous-mode> "/home/<linux-user>/Downloads/sophos-vpn.ovpn", replacing <previous-mode> with the recorded value, and verify it with stat. Only restore broader permissions if they are deliberately required.

The following command then starts OpenVPN with elevated privileges because the client creates a tunnel interface and temporary routes. On Linux, the direct OpenVPN process does not apply offered DNS servers by itself; the profile needs a suitable up/down script or system integration. NetworkManager can provide this DNS integration:

sudo openvpn --config "/home/<linux-user>/Downloads/sophos-vpn.ovpn"

OpenVPN first prompts for the local sudo password and then for the VPN credentials. With MFA, use the input format specified by the administrator; depending on the authentication setup, the one-time code is combined with the password or requested separately. Initialization Sequence Completed and a present tunnel interface are the success criteria. The connection runs in the foreground. Ctrl+C stops OpenVPN and is also the rollback: the client removes the temporary tunnel interface and routes it installed; any DNS integration that was actually configured must also restore its temporary DNS values. Use the checks below afterward to confirm that the tunnel interface and VPN route have disappeared and normal name resolution applies again.

4. Import the connection into NetworkManager

  1. Open the network settings.
  2. Add a new VPN connection and select Import from file.
  3. Select the downloaded .ovpn file.
  4. Save the username if this is appropriate for the operating model.
  5. Start the connection and enter the VPN credentials in the MFA format specified by the administrator.

Importing creates a separate NetworkManager connection profile and can copy embedded keys or certificates from the file. Deleting the downloaded .ovpn therefore does not remove the imported profile. Do not save the password in the profile unless the operating model explicitly provides protected credential storage. To roll back, disconnect the VPN, delete the imported profile in the network settings, and confirm that it no longer appears in the connection list.

NetworkManager is more convenient for daily use than keeping a terminal open. However, unattended autostart is not automatically possible with interactive sign-in or MFA. Credentials should not be stored in an unprotected file solely to enable autostart.

Why NetworkManager-strongSwan is not suitable here

Under SFOS 22, Sophos only allows IKEv1 profiles for Remote access VPN > IPsec where Dead Peer Detection is disabled or set to Disconnect. The NetworkManager-strongSwan plugin, by contrast, only establishes IKEv2 connections. The two endpoints therefore cannot negotiate a tunnel with the previously described workflow.

The strongSwan software itself still supports IKEv1, but this is not the same GUI path as the NetworkManager plugin. A manual IKEv1 configuration requires matching parameters, authentication, traffic selectors, and a tested client setup. Without a reliable target configuration, do not copy a generic example from the internet.

Sophos lists a compatible third-party client as an option for IPsec on Linux. However, the exported .tgb file does not contain all advanced settings from the Sophos Connect configuration and cannot simply be imported into NetworkManager as an IKEv2 profile. If IPsec is mandatory, the selected client must explicitly support the firewall’s IKEv1 setup and must be tested in the relevant environment. Sophos Connect or SSL VPN: Which Remote Access Solution Fits? helps with the general choice.

Verify the connection

After the connection is established, do not check only the client status. What matters is whether the route, DNS, and firewall rule match the intended destination.

These commands run as a normal user in a local Linux terminal and are read-only, so they need neither sudo nor a rollback. Replace the private example address 10.20.30.40 with an allowed internal destination. Replace the reserved example name intranet.example.net with an internal FQDN that the VPN DNS should resolve:

ip addr show
ip route get 10.20.30.40
getent hosts intranet.example.net

Expected results:

  • OpenVPN reports a successful connection and a tunnel interface is present.
  • The route check shows the VPN path for the internal destination instead of the normal internet gateway.
  • The DNS check returns the internal address if internal DNS servers were distributed and integrated by the selected Linux client.
  • An allowed internal service is reachable; a deliberately disallowed destination remains blocked.
  • The firewall’s Log Viewer shows the test traffic from the VPN zone with the expected rule.
  • After signing in again, authentication requires the intended MFA proof again.

If the tunnel is established but no traffic flows, see Test a firewall rule with Log Viewer, Policy Test, and Packet Capture.

Common errors

  • No Linux configuration in the VPN Portal: The user or group is not assigned to a Remote Access SSL VPN policy. Check the policy and Portal sign-in.
  • OpenVPN reports an authentication error: Check the username, password, MFA process, group membership, and selected authentication method.
  • The tunnel is established, but internal destinations remain unreachable: Check the permitted networks in the SSL VPN policy, the firewall rule from VPN to the destination zone, and the route to the internal network.
  • The VPN route is missing or points to local Wi-Fi: The SSL VPN lease network and internal destinations must not overlap local networks or common home subnets. Check the address ranges in SSL VPN global settings; after correcting them, disconnect and reconnect the tunnel.
  • IP addresses work, but internal names do not: Check the distributed DNS servers, search domain, and reachability of the internal DNS server.
  • Full tunnel connects, but internet access stops: With Use as default gateway, also check the firewall rule from VPN to the internet, the required protection policies, and an SNAT/masquerading rule for ##ALL_SSLVPN_RW or ##ALL_SSLVPN_RW6.
  • The terminal was closed and the connection was lost: This is normal when running openvpn --config directly. For graphical management, import the .ovpn file into NetworkManager.
  • NetworkManager does not offer file import: The NetworkManager OpenVPN plugin is missing or the NetworkManager service has not yet loaded the newly installed plugin.
  • An old .ovpn file no longer works: Download the file again after changes to the SSL VPN protocol, SSL server certificate or CA, Override hostname, or SSL VPN port.
  • NetworkManager-strongSwan does not connect: Do not switch to IKEv2. The plugin is not compatible with the Sophos Firewall IKEv1 Remote Access profile.
  • An alleged Sophos Connect client for Linux was found: Do not install it without verification. Sophos does not provide an official Linux client.

FAQ

Is there an official Sophos Connect client for Linux?

No. Sophos Connect is available for Windows and macOS. On Linux, SSL VPN with an OpenVPN client is the path documented by Sophos.

Which file must be downloaded from the VPN Portal for Linux?

Under VPN > VPN configuration, use Download configuration for Windows, macOS, Linux. The .ovpn file only appears if the user is assigned to a Remote Access SSL VPN policy.

Why does the VPN connection disconnect when the terminal is closed?

The direct sudo openvpn --config command runs in the foreground of the terminal. For a graphically managed connection, import the .ovpn file into NetworkManager.

Can NetworkManager be used for Sophos Firewall Remote Access?

Yes, with the NetworkManager OpenVPN plugin and the .ovpn file. The NetworkManager-strongSwan plugin, however, is IKEv2-only and is not compatible with the SFOS 22 IKEv1 Remote Access IPsec profile.

Must the .ovpn file be downloaded again after a firewall change?

Yes, if the SSL VPN protocol, SSL server certificate or CA, Override hostname, or SSL VPN port has changed. An old file may still contain outdated connection parameters.