Setting the AnyConnect VPN Server URL during deployment?

Elliot-12345
New here

Setting the AnyConnect VPN Server URL during deployment?

Hi,

 

We deploy the Cisco Secure Client and AnyConnect VPN via Intune, is there an easy way to set the VPN Server URL as part of the deployment? i.e. When a user connects to the VPN, they don't have to enter it manually, it is already populated as per below.

Elliot12345_0-1754464330042.png

 

5 Replies 5
dmbooth
Here to help

You need to populate your endpoints with a client profile. On the Client VPN > Cisco Secure Client Settings page there's a link to download the Secure Client Profile Editor which you can use to create a profile (which is just an xml file). This page in docs walks you through creating a profile - AnyConnect Client Download and Deployment - Cisco Meraki Documentation

Elliot-12345
New here

Thanks @dmbooth, I've set this up. Is there a way to have it apply to the client without them having to connect first? We want to deploy this to the wider team and it would be a bit counter-intuitive if they have to manually enter the VPN server URL themselves before it pulls down the profile.

dmbooth
Here to help

You'd have to push the xml profile file to the correct location on the user's endpoint which you should be able to do with Intune.

alemabrahao
Kind of a big deal
Kind of a big deal

You can also achieve this using a Windows GPO.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

I have an online AnyConnect profile editor you can use.

https://ifm.net.nz/cookbooks/online-anyconnect-profile-editor.html

 

For Windows, this needs to go into this directory:

%ProgramData%\Cisco\Cisco Secure Client\VPN\Profile

 

If you are deploying AnyConnect using IntuneWin, you can also place the profile in this directory, and it will be deployed automatically at install time.

PhilipDAth_0-1754513132969.png

 

If you are prepared to do a bit of setup work, you can also use the Cisco SecureClient cloud management portal.  The client pulls all of its configs from that (it also lets you push client updates easily).

https://secure-client.apjc.security.cisco.com/

 

Get notified when there are additional replies to this discussion.