Prerequisites for Secure Client management VPN tunnel

Review these prerequisites before configuring and establishing a management VPN tunnel connection.

General prerequisites

  • Ensure that Firewall Threat Defense and Cloud-Delivered Firewall Management Center are versions 6.7.0 or later.

  • Download the Secure ClientSecure Client Headend Deployment Package Version 4.7 or later and upload it to Firewall Threat Defense remote access VPN policy.

  • Configure certificate authentication in the connection profile.

  • Do not configure a banner in the group policy.

  • Verify the split tunneling configuration in the management tunnel group policy.

Certificate prerequisites

  • Ensure that the Firewall Threat Defense device has these certificates:

    • A valid identity certificate for remote access VPN.

    • A root certificate from the local Certificate Authority(CA).

  • Install a valid identity certificate on the endpoints connecting to the management VPN tunnel.

  • Install the endpoint identity certificate in the Machine Certificate Store (Windows) or System Keychain (macOS).

  • Install the CA certificate for the Firewall Threat Defense device on all endpoints

  • Install the CA certificate for all endpoints on the Firewall Threat Defense device.