Create an RA VPN Configuration

Security Cloud Control allows you to add one or more FDM-managed devices to the RA VPN configuration wizard and configure the VPN interfaces, access control, and NAT exemption settings associated with the devices. Therefore, each RA VPN configuration can have connection profiles and group policies shared across multiple FDM-managed devices that are associated with the RA VPN configuration. Further, you can enhance the configuration by creating connection profiles and group policies.

You can either onboard an FDM-managed device that has already been configured with RA VPN settings or a new device without RA VPN settings. When you onboard an FDM-managed device that already has RA VPN settings, Security Cloud Control automatically creates a "Default RA VPN Configuration" and associates the FDM-managed device with this configuration. Also, this default configuration can contain all the connection profile objects that are defined on the device.

Important
  • You are not allowed to add ASA and FDM-managed device in the same Remote Access VPN Configuration.

  • An FDM-managed device can't have more than one RA VPN Configuration.

Prerequisites

Before adding the FDM-managed devices to RA VPN configuration, the following prerequisites must be met:

  • Make sure that the FDM-managed devices have the following:

  • FDM changes are synchronized to Security Cloud Control.

    1. In the left pane, click Security Devices and search for one or more FDM-managed devices to be synchronized.

    2. Select one or more devices and then click Check for changes. Security Cloud Control communicates with one or more FDM-managed devices to synchronize the changes.

  • RA VPN configuration group policy objects are consistent.

  • RA VPN group policies of the FDM-managed device match RA VPN configuration group policies.