Prerequisites for Secure Client management VPN tunnel
Review these prerequisites before configuring and establishing a management VPN tunnel connection.
General prerequisites
-
Ensure that Firewall Threat Defense and Cloud-Delivered Firewall Management Center are versions 6.7.0 or later.
-
Download the Secure ClientSecure Client Headend Deployment Package Version 4.7 or later and upload it to Firewall Threat Defense remote access VPN policy.
-
Configure certificate authentication in the connection profile.
-
Do not configure a banner in the group policy.
-
Verify the split tunneling configuration in the management tunnel group policy.
Certificate prerequisites
-
Ensure that the Firewall Threat Defense device has these certificates:
-
A valid identity certificate for remote access VPN.
-
A root certificate from the local Certificate Authority(CA).
-
-
Install a valid identity certificate on the endpoints connecting to the management VPN tunnel.
-
Install the endpoint identity certificate in the Machine Certificate Store (Windows) or System Keychain (macOS).
-
Install the CA certificate for the Firewall Threat Defense device on all endpoints
-
Install the CA certificate for all endpoints on the Firewall Threat Defense device.