Learn how to configure and monitor Remote Access VPN for FDM-managed devices in Security Cloud Control, including AnyConnect packages, identity sources, RADIUS and Duo authentication, group policies, connection profiles, traffic access, licensing, verification, session reporting, and session management.
Security Cloud Control Firewall Management provides an intuitive user interface for configuring a new Remote Access Virtual Private Network (RA VPN). It also allows you to quickly and easily configure RA VPN connection for multiple FDM-managed devices that are on board in Security Cloud Control Firewall Management. AnyConnect is the only client that is supported on endpoint devices for an RA VPN connectivity to FDM-managed devices.
When the AnyConnect client negotiates an SSL VPN connection with the FDM-managed device, it connects using Transport Layer Security (TLS) or Datagram Transport Layer Security (DTLS). DTLS avoids latency and bandwidth problems associated with some SSL connections and improves the performance of real-time applications that are sensitive to packet delays. The client and the FDM-managed device negotiate the TLS/DTLS version to use. DTLS is used if the client supports it.
Security Cloud Control supports the following aspects of RA VPN functionality on FDM-managed devices:
SSL client-based remote access
IPv4 and IPv6 addressing
Shared RA VPN configuration across multiple FDM-managed devices
If an onboarded FDM-managed device (running on software version 6.7 or later) contains RA VPN configuration with SAML server as the authentication source, Security Cloud Control doesn't populate the AAA details in the connection profile as it doesn't manage SAML server objects in the current release. Thus you can't manage such RA VPN configuration from Security Cloud Control. However, Security Cloud Control reads the RA VPN connection profile and associated trusted CA certificate and SAML server objects.

>



to upload the package. If the checksum doesn't match, the AnyConnect package upload fails. You can see the device's workflow tab for more details about the failure.
to upload the package.
icon appearing beside the existing AnyConnect package. If there are multiple versions of AnyConnect package for an operating system, select the package you want to replace from the list and click
icon appearing beside the AnyConnect package that you want to delete. If there are multiple versions of AnyConnect package for an operating system, select the package you want to delete from the list. The existing package disappears from the corresponding field. 
to perform the following on the
to copy the instructions to the clipboard, and then distribute them to your users.
) button (

) to open a summary of the connection profile and connection instructions. Under