This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Connect Client with OTP

Hi,

I like the new feature of a free IPSEC client introduced with 17.5. As far as In know the CPU load of IPSEC-VPN on the gateway is much lower. I have just tested it and I experienced one issue which somebody else might have discovered.

Sophos connect client without OTP for local user authentication: Working fine, connection establised quickly and network behind XG reachable.

Then I activated OTP for the user on the XG and re-configured the connection with Sophos connect admin, simply activated "Prompt for 2FA": Unfortunately it does not connect, an authentication error occurs. Checking the VPN log I found all entries comperable until an authenication is logged:

[IKE] <IPSEC_VPN | 10> Xauth authetication of 'user' (myself) failed.

Of course without OTP the authenication at that point is successful. Anyone who has successfully used Sophos Connect client with OTP?

BTW: Use of OTP with SSL VPN was succesful, the OTP has to be added directly to the password. So can't be a problem with OTP in general.

Cheers
Dirk



This thread was automatically locked due to age.
Parents Reply Children
  • Hello All,

    Yes it is confirmed that Sophos Connect VPN is compatible with OTP. If you are using OTP with tgb file then you enter passwordOTP with NO comma or space between with password and OTP. The two are entered as a single string.

     

    If you are using Sophos Connect Admin to configure the policy, then you will get separate prompt for OTP.

     

    Please let us know after you give that a try.

    Ramesh

  • I challenge that response. While it maybe listed as supporting OTP, it clearly is not funcitoning correctly. Whether I try via TGB or with OTP prompt it fails. It works great without it and of course on the classic SSLVPN. 

  • Hello Brad,

    I think there is some configuration or user error because I have rechecked user authentication by connecting Sophos Connect with multiple XG gateways and it works. 

    Ramesh

  • Setup of Sophos Connect + OTP on XG330_WP02_SFOS 17.5.3 MR-3 worked out great.  AD user on win7 laptop running the Sophos Connect VPN client + Sophos Authenticator app on an ios device.  No problems here so far.