Sophos UTM 9.7
Tested Version: 9.711-5
Open the web interface of the firewall and move to Site-to-site VPN | Amazon VPC | Setup:

Set in Local Networks the network you want be reachable from the Cloud and click Apply.
Upload the ready-to-use configuration file in “VPN config file” upload form and click Apply.
After few minutes you should be able to see in Status tab all up and running:

Two tunnels are created for high availability: only one of the two is active, the one with the CIDR of the remote network at the end of the BGP line.
If something is not working fine please check to have set correctly the packet filtering section, for example:
