Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Remote Access SSL Change - does this type of change require a new profile for end users?

I am not an expert on the Sophos UTM but I know enough to be dangerous.

Recently, under Remote Access > SSL > Settings, we made a change to the port being used which required every employee using the VPN to download a new config/profile on every device they use. On Windows, it's an easy installation, but not so straightforward on iOS devices (and sometimes MacBooks if the end-user isn't really familiar with VPN's)

I didn't realize that a change to that port number would cause a new config (because I'm ignorant and in a hurry), but I understand now why it would.

The Problem:

I need to allow multiple user connections concurrently. For example, our Software Dev team (most of whom work remotely) runs a Macbook, with a Windows VM on it.   Both "devices" need to connect to the VPN.

If I change that one setting that allows multiple concurrent sessions under Remote Access > SSL > Settings Tab (there is a check box at the bottom) will that also require that all users download/install a new profile?

I was hoping that a global setting like that would NOT affect individual profiles.

But I've been wrong before (obviously).

Any help would be greatly appreciated.



This thread was automatically locked due to age.
Parents
  • Hello Ron,

    Thank you for contacting the Sophos Community!

    When enabling or disabling Duplicate CN is NOT necessary for users to re-download the Config File.

    When modifying something in the Settings >> Server Settings as well as under Advanced >> Cryptographic Settings ((then users will need to re-download the config).

    Regards,

Reply
  • Hello Ron,

    Thank you for contacting the Sophos Community!

    When enabling or disabling Duplicate CN is NOT necessary for users to re-download the Config File.

    When modifying something in the Settings >> Server Settings as well as under Advanced >> Cryptographic Settings ((then users will need to re-download the config).

    Regards,

Children
No Data