The MSI package is designed for silent deployment via Group Policy Object (GPO) or software distribution systems (e.g., SCCM, Intune). The workflow differs from a standard user-driven .exe installation.
The .msi supports public properties to pre-configure both tunnels. A standard deployment command that makes sophosconnect250gaipsecandsslvpnmsi work seamlessly is:
If the MSI installation or client fails to work, consider these solutions:
Disclaimer: Always test new installers on a pilot group of machines before mass deployment. sophosconnect250gaipsecandsslvpnmsi work
The ipsecandsslvpn capability is powerful, but you must configure the firewall correctly:
After creating this file, you can push it out using a PowerShell script. The script below can be used to silently install the MSI and then copy the provisioning file to the correct directory for all users.
The file designation SophosConnect_2.5_GA_(IPsec_and_SSLVPN).msi represents the General Availability (GA) branch of Sophos's unified endpoint client. Historically, IT administrators had to manage separate client software depending on whether a user required an SSL-based or an IPsec-based virtual private network. The MSI package is designed for silent deployment
For further reading, consult Sophos Knowledge Base article KB-000042415 (Sophos Connect MSI deployment with dual profiles) or contact Sophos support with the reference “Connect 2.5.0 IPsec+SSL MSI” for advanced tuning parameters.
msiexec /x OLD-PRODUCT-GUID /quiet /norestart
For non-domain devices (BYOD or roaming), deploy via an RMM (Remote Monitoring and Management) script using the same msiexec command. The file designation SophosConnect_2
This article provides a comprehensive guide on ensuring the SophosConnect_2.5.0_IPsec_and_SSLVPN.msi works seamlessly within your network infrastructure.
: Supports enhanced security via 2FA/OTP.