Skip to content
Last update: 2022-03-11

Remote access IPsec and SSL VPN

Using the Sophos Connect client, you can establish remote access IPsec and SSL VPN connections.

You don't need the Sophos Connect client for iOS devices.

You can download the Sophos Connect client and SSL VPN configuration to establish a remote access SSL VPN connection between your endpoint and your organization's network.

Supported endpoints

You can use the Sophos Connect client to configure the connection on the following endpoints:

  • Windows 10 and 11 devices

You can't use the Sophos Connect client to configure the connection on the following endpoints:

  • macOS devices
  • Linux devices
  • Mobile devices

You can use the legacy SSL VPN client or the OpenVPN client for these endpoints.

Download the Sophos Connect client

  1. Sign in to the user portal.
  2. Go to VPN.
  3. Under Sophos Connect client (IPsec and SSL VPN), click Download client for Windows.

    Download Sophos Connect client for Windows

  4. Click the downloaded file to install the Sophos Connect client on your device.
    You can see the client on your desktop.

  5. Double-click the client.
    You can then see it in the tray in the lower-right corner for Windows and the upper-right corner for macOS devices.

    Sophos Connect client in Windows tray

Download the configuration file

  1. On the user portal, scroll down to SSL VPN client and click Download configuration for other OSs.
    This downloads a .ovpn file.

    Download configuration file

    Note

    You can see the SSL VPN client section only if your administrator has configured a remote access SSL VPN policy for you.

Import the configuration file to the client

  1. Click the Sophos Connect client in the Windows tray on your endpoint and click Import connection.

    Import the connection

  2. Select the .ovpn configuration file you've downloaded.

    Here's an example of a connection:

    VPN connection

  3. Click Connect to sign in.

    Click connect

  4. Enter your user portal credentials.

    Sign in to connect

  5. Enter the verification code if you're prompted for two-factor authentication.

  6. Click Sign in.

This establishes the remote access SSL VPN connection. Future connections are established automatically.

Tip

If tunnels that had connected earlier don't connect later, download the .ovpn configuration file again from the user portal, and import it to the Sophos Connect client.

You must do this if your administrator has made configuration changes.

You can download the Sophos Connect client and import the IPsec configuration to it. You can then establish a remote access IPsec VPN connection between your endpoint and your organization's network.

Supported endpoints

You can use the Sophos Connect client to configure the connection on the following endpoints:

  • Windows 10 and 11 devices
  • macOS 10.13 and later

You can't use the Sophos Connect client to configure the connection on the following endpoints:

  • Linux devices
  • Mobile devices

You can use a third-party IPsec VPN client for these endpoints.

Download the Sophos Connect client

  1. Sign in to the user portal.
  2. Go to VPN.
  3. Under Sophos Connect client (IPsec and SSL VPN), do as follows:

    • Windows devices: Click Download client for Windows.
    • macOS devices: Click Download client for macOS.

    Download Sophos Connect client for Windows

  4. Click the downloaded file to install the Sophos Connect client on your device.
    You can see the client on your desktop.

  5. Double-click the client.
    You can then see it in the tray in the lower-right corner for Windows and the upper-right corner for macOS devices.

    Sophos Connect client in tray

Note

You can see the IPsec VPN client section only if your administrator has configured remote access IPsec VPN.

Import the configuration file to the client

Your administrator will share the `.scx' configuration file with you.

  1. Click the Sophos Connect client in the tray on your endpoint and click Import connection.

    Import the connection

  2. Select the .scx configuration file your administrator has shared with you.

    Here's an example of a connection:

    VPN connection

  3. Click Connect to sign in.

    Click connect

  4. Enter your user portal credentials.

    Sign in to connect

  5. Enter the verification code if you're prompted for two-factor authentication.

  6. Click Sign in.

This establishes the remote access IPsec VPN connection. Future connections are established automatically.

Tip

If tunnels that had connected earlier don't connect later, your administrator may have made changes to the configuration file. Ask for the new file, and import it to the Sophos Connect client.

You can establish remote access IPsec VPN connections between your iOS device and your organization's network.

How to establish the connection

  1. On your iOS device, open the Safari browser, and sign in to the user portal.
  2. Go to VPN.
  3. Under Apple iOS IPsec VPN client configuration, click Install.

    Install IPsec VPN configuration on iOS devices

The IPsec VPN is automatically established.

Note

You can only see the iOS IPsec section if your administrator has configured remote access IPsec VPN.

Tip

Install the configuration again if tunnels that had connected earlier don't connect later.

You must do this if your administrator has made configuration changes.

Closing the VPN connection

To close the VPN connection, do as follows:

  1. On the iOS device, tap Settings.
  2. Tap General > VPN.
  3. Tap the Status button for your connection.

Your VPN connection will close.

Back to top