Configure Secure Client management VPN tunnel

A Secure Client management VPN tunnel is a VPN connection that

  • automatically connects to the corporate network as soon as the endpoint device powers up

  • ensures that endpoints are up-to-date with software patches and updates, and

  • disconnects once the user establishes their own VPN session.

Management VPN tunnel operation

When the endpoint device starts, Secure Client detects the management VPN feature and initiates a session using the host entry defined in the server list of the Secure Client management VPN profile.

To configure the Secure Client management VPN tunnel on a Firewall Threat Defense device, you need these components:

  • A connection profile with certificate-based authentication and a group URL.

  • A Secure Client management VPN profile file, with a server group URL and backup servers if required.

  • A group policy associated with a remote access VPN policy that includes the management VPN profile, split tunneling with explicitly included networks, client bypass protocol, and no banner.