Auto-import pfc profile for Cisco VPN clients

Posted on 2011-03-16
Last Modified: 2012-05-11

We have a bunch of users with laptops running cisco VPN clients. We have made chamges to the profile and need to  deploy the new pfc file profile to the users and set it as default. What is the best way to do that with minimum user interaction? Perhaps a script that imports the pfc and sets it as default can be run at startup? IAll I really need is a batch file that the user starts and it installs the new profile and sets it as default.


Question by:rookie_b
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3

Expert Comment

ID: 35148257
Interesting question. First I suppose you mean pcf file. Never mind. There may be an elegant solution. How many clients/VPN users do you have?
Are you concerned about manual import by the users? Or do you wish to control the remote user clients software, configuration, licensing, etc? Just trying to find out the scope of your project.

Author Comment

ID: 35150050
Yes, it is pcf, sorry...The aim is to have as little user involvement as possible, everything elsde is secondary. We have about 50 users and I am not worried about licensing.

Most machines will not be on the domain before the change, so cannot push anything through policy, and after the change they will not be able to connect using the old profiles at all, so cannot use autoupdate or something like that. The only way to send  the new profile to the users would be to email them the files, or perhaps post it online. It would be nice if they just click on a link and it is all done.

At this point we have a not so elegant soloution - a folder that contains the pcf, vpnclient.ini, and a .bat file is zipped and emailed to the user. They unzip it, run the bat file and that imports the new profile and replaces the vpnclient.ini file that has the new default connection setting.

Expert Comment

ID: 35150171
May I suggest the NCP Enterprise Client? This is a managed solution. The way it works is that you have the clients/users install a default generic configuration. So you provide the users with a download link of the client. Once they install the client they will connect to your VPN Cisco gateway. Then the client will contact the Management Server and obtain it's final user-specific configuration. After that you will be able to manage/control the client software, configuration, firewall settings on the clients, etc. A lot of control and functionality. Also they have Friendly Network Detection. Check it out:
This is a great solution!
Moving data to the cloud? Find out if you’re ready

Before moving to the cloud, it is important to carefully define your db needs, plan for the migration & understand prod. environment. This wp explains how to define what you need from a cloud provider, plan for the migration & what putting a cloud solution into practice entails.


Author Comment

ID: 35160390
Thank you for your suggestion, it looks interesting. But we already have the Cisco VPN, which is managed, as long as they can establish connection. However, their existing settings no longer work and cannot connect. We need to deliver the pcf adn vpnclient.ini to their laptops with as little user interaction as possible.

Expert Comment

ID: 35160503
Cisco VPN does not have a Management Solution. I guess you don't quite understand the Management aspect. Cisco DOES NOT have VPN management period. And the NCP Management Server and Clients work with Cisco VPN. So the NCP Management solution sounds right for you. Since you just deploy an Init Profile to all your users and once they connect the client profile is provisioned from the NCP Management Server via the Cisco gateway. This is NCP's competitive edge. Something nobody else can do. It sounded like the right approach for you to me. Other then that your only option is to do what everybody else does handle it manually one client at a time - sort of stupid. If Cisco had a Management solution then you should be able to do what you are asking for as NCP can do it 8)

Author Comment

ID: 35176556
Well, the cisco concentrator provides some management functionality, including updating/upgrading clients when thy connect, however it is too late for that, since clients will not be able to connect using their existing configuration. Thank you for your advice, but we would prefer to avoid the implications of an infrastructure upgrade at this point.

Accepted Solution

Allvirtual earned 500 total points
ID: 35180184
Understood. However you do not need an infrastructure upgrade in terms of the VPN Concentrator. All you need is the NCP Management Server software which will run inside the network and the NCP VPN client. Then you create an Init Profile the users can download from the Internet and Import into the client - 1-click operation, easy. Then they can connect to the Cisco VPN and will get their final profile from the Management Server. Simple and elegant.

Featured Post

2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Suggested Courses
Course of the Month6 days, 18 hours left to enroll

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question