Skip to content

Provisioning IPsec and SSL VPN

The provisioning (.pro) file enables the Sophos Connect client on your endpoint to automatically fetch the remote access IPsec and SSL VPN configurations. The .pro file automatically imports any configuration changes your administrator makes later.

You must download the Sophos Connect client and import the provisioning file your administrator provides if they aren't automatically installed on your endpoint.

Supported endpoints

You can use the Sophos Connect client and the provisioning file to configure the connection on the following endpoints:

  • Windows 10 and 11 devices

Download the Sophos Connect client

  1. Sign in to the VPN portal.
  2. Go to VPN.
  3. Under Sophos Connect client (IPsec and SSL VPN), click Download client for Windows.

    Download Sophos Connect client for Windows.

  4. Click the downloaded file to install the Sophos Connect client on your device.

    You can see the client on your desktop.

  5. Double-click the client.

    You can then see it in the tray in the lower-right corner for Windows.

    Sophos Connect client in Windows tray.

Import the provisioning file

  1. Click the .pro file your administrator provides.

    If a text file is provided, change the extension to .pro.

    The file is then automatically imported into the Sophos Connect client.

  2. Click Connect to sign in.

    Click connect.

  3. Enter your VPN portal username and password.

    Sign in to connect.

  4. If multi-factor authentication is configured, do as follows based on the option configured:

    • OTP token (Sophos Firewall or third-party tokens): Enter the passcode.

      If it's a token generated by Sophos Firewall, see OTP token for more information.

    • Duo Push: Enter push and approve the notification on your mobile device.

    • Duo Phone: Enter phone. You'll receive a call for authentication.
    • Duo SMS: Enter sms. In the next sign-in screen, enter your username, password, and the OTP token.

    Sign-in using MFA.


    If you're using the provisioning file the first time, the sign-in screen is shown twice. The first sign-in downloads the configuration file, and the second establishes the connection.

  5. Click Sign in.

This establishes the remote access connection.