Troubleshoot remote access SSL VPN
Make sure you've completed the configurations. If you can't establish tunnels after that, follow the basic and advanced troubleshooting steps.
Complete the configurations
-
Web admin console: You can use the remote access SSL VPN assistant to configure the following settings:
- Remote access VPN > SSL VPN: Add an SSL VPN policy.
- Administration > Device access: Allow access from zones to services.
- Authentication > Services: Check the SSL VPN authentication method.
-
VPN portal
- Download the Sophos Connect client and install it on your endpoint.
- Download and import the
.ovpn
file to the client.
-
Sophos Connect client: Enter your credentials to establish the connection.
Example configurations:
- Configure remote access SSL VPN as a split tunnel.
- Configure remote access SSL VPN as a full tunnel.
Basic troubleshooting
Users can't access VPN portal from WAN zone
- Go to Administration > Device access and select WAN and the required zones under VPN portal.
- Make sure you added an SSL VPN policy.
-
In the browser, enter
https://<IP address or hostname of Sophos Firewall>:<VPN portal's port>
.Note
The default port for VPN portal is 443. To check the port, go to Administration > Admin and user settings and see under Admin console and end-user interaction.
Other VPN portal issues
-
Scenario
- Can't sign in to VPN portal.
- SSL VPN configuration files don't appear.
- Go to Remote access VPN > SSL VPN and make sure you added the users to an SSL VPN policy.
-
We recommend that usernames and certificate and CA fields don't contain special characters for the following reasons:
- The VPN portal doesn't support some special characters in usernames.
- The Sophos Connect client only supports ASCII characters in usernames. It doesn't support certain sequences of special characters. See Sophos Connect: Supported characters.
- Usernames are used in the
.ovpn
filenames and the certificates the firewall generates for each remote user. Third-party VPN clients may not support special characters in these.
Advanced troubleshooting
To resolve advanced issues, see the following checklists: