The instructions found here were for a Sophos UTM. For the XG model you should be able to follow these instructions:
https://community.sophos.com/kb/en-us/131471
I have done it. It's been quite awhile since I did it though, and don't remember if I had to make any changes in the process.
I highly recommend moving to a TLS H323 connection instead now.
Richard
I have completed this and found that if you do not have access to the phone, the best way to enable VPN on the phone, is to amend the 46xxsettings.txt file this is store on the Avaya, and when the phone initially configures it self from the Avaya, this file will provide the defaults for the phone when connecting to the Avaya PBX.
XG & UTM Architect (Systems: XG v18 & UTM 9.7 - Virtual, HW & SW)
Curious enough to take it apart, skilled enough to put it back together, Clever enough to hide the extra parts when I'm Done!