Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1131
  • Last Modified:

Auto-import pfc profile for Cisco VPN clients

Hello,

We have a bunch of users with laptops running cisco VPN clients. We have made chamges to the profile and need to  deploy the new pfc file profile to the users and set it as default. What is the best way to do that with minimum user interaction? Perhaps a script that imports the pfc and sets it as default can be run at startup? IAll I really need is a batch file that the user starts and it installs the new profile and sets it as default.

Cheers!

0
rookie_b
Asked:
rookie_b
  • 4
  • 3
1 Solution
 
AllvirtualCommented:
Interesting question. First I suppose you mean pcf file. Never mind. There may be an elegant solution. How many clients/VPN users do you have?
Are you concerned about manual import by the users? Or do you wish to control the remote user clients software, configuration, licensing, etc? Just trying to find out the scope of your project.
0
 
rookie_bAuthor Commented:
Yes, it is pcf, sorry...The aim is to have as little user involvement as possible, everything elsde is secondary. We have about 50 users and I am not worried about licensing.

Most machines will not be on the domain before the change, so cannot push anything through policy, and after the change they will not be able to connect using the old profiles at all, so cannot use autoupdate or something like that. The only way to send  the new profile to the users would be to email them the files, or perhaps post it online. It would be nice if they just click on a link and it is all done.

At this point we have a not so elegant soloution - a folder that contains the pcf, vpnclient.ini, and a .bat file is zipped and emailed to the user. They unzip it, run the bat file and that imports the new profile and replaces the vpnclient.ini file that has the new default connection setting.
0
 
AllvirtualCommented:
May I suggest the NCP Enterprise Client? This is a managed solution. The way it works is that you have the clients/users install a default generic configuration. So you provide the users with a download link of the client. Once they install the client they will connect to your VPN Cisco gateway. Then the client will contact the Management Server and obtain it's final user-specific configuration. After that you will be able to manage/control the client software, configuration, firewall settings on the clients, etc. A lot of control and functionality. Also they have Friendly Network Detection. Check it out:
http://www.ncp-e.com/en/products/central-managed-vpn-solution.html
This is a great solution!
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
rookie_bAuthor Commented:
Thank you for your suggestion, it looks interesting. But we already have the Cisco VPN, which is managed, as long as they can establish connection. However, their existing settings no longer work and cannot connect. We need to deliver the pcf adn vpnclient.ini to their laptops with as little user interaction as possible.
0
 
AllvirtualCommented:
Cisco VPN does not have a Management Solution. I guess you don't quite understand the Management aspect. Cisco DOES NOT have VPN management period. And the NCP Management Server and Clients work with Cisco VPN. So the NCP Management solution sounds right for you. Since you just deploy an Init Profile to all your users and once they connect the client profile is provisioned from the NCP Management Server via the Cisco gateway. This is NCP's competitive edge. Something nobody else can do. It sounded like the right approach for you to me. Other then that your only option is to do what everybody else does handle it manually one client at a time - sort of stupid. If Cisco had a Management solution then you should be able to do what you are asking for as NCP can do it 8)
0
 
rookie_bAuthor Commented:
Well, the cisco concentrator provides some management functionality, including updating/upgrading clients when thy connect, however it is too late for that, since clients will not be able to connect using their existing configuration. Thank you for your advice, but we would prefer to avoid the implications of an infrastructure upgrade at this point.
0
 
AllvirtualCommented:
Understood. However you do not need an infrastructure upgrade in terms of the VPN Concentrator. All you need is the NCP Management Server software which will run inside the network and the NCP VPN client. Then you create an Init Profile the users can download from the Internet and Import into the client - 1-click operation, easy. Then they can connect to the Cisco VPN and will get their final profile from the Management Server. Simple and elegant.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now