Deploy scripts on endpoint devices using Secure Client
Secure Client lets you download scripts and run them when these events occur:
-
Establishment of a new client VPN session with a Firewall Threat Defense device. This event triggers an OnConnect script. Reconnection of the VPN session does not trigger this script.
-
Disconnection of a client VPN session with a Firewall Threat Defense device. This event triggers an OnDisconnect script.
Secure Client identifies the OnConnect and OnDisconnect scripts by the filename. It looks for a file whose name begins with OnConnect or OnDisconnect regardless of the file extension.
Use cases
You can use this feature to perform these automated actions:
-
Refresh the group policy upon VPN connection.
-
Mount a network drive upon a VPN connection.
-
Unmount a network drive upon a VPN disconnection.
Scripting behavior and requirements
-
Secure Client launches scripts only after the user logs in and establishes a VPN session.
-
The scripts run asynchronously and do not delay the connection establishment or disconnection.
-
The scripts can have any file extension and must be executable in the endpoint.
-
To enable scripts, select Enable Scripting in the VPN profile. By default, scripts do not launch automatically. They can be in any language. The endpoint must have an application that runs them from the command line.
-
To trigger scripts after login, select Enable Post SBL On Connect Script in the VPN profile.
-
You cannot launch the OnConnect script from the Start Before Logon (SBL) user interface.
-
On 64-bit Windows systems, scripts run using the 32-bit version of cmd.exe, because Secure Client is a 32-bit application.