Cisco Secure Access Help

PDF

Cisco Secure Access Help

Download and Install Cisco Secure Client

Want to summarize with AI?

Log in

Explains how to obtain the installer and the specific configuration files required to activate the VPN, Zero Trust Access, Internet Security, and ThousandEyes modules in your Secure Access organization.


This section describes how to download and install the Cisco Secure Client on endpoint devices. It also covers downloading the configuration files required to connect the Secure Client VPN module, Zero Trust Access, Internet Security, and ThousandEyes modules to your Secure Access organization.

For more information on Cisco Secure Client deployment, see Deploy Cisco Secure Client in the Cisco Secure Client (including AnyConnect) Administrator Guide, Release 5.

Procedure

  1. Navigate to Connect > End User Connectivity.

  2. On the End User Connectivity page, click Cisco Secure Client.


    End user connectivity page with option to select Cisco Secure Client

    The Download Cisco Secure Client window appears.


    Download Cisco Secure Client window displayed
  3. In the Download Cisco Secure Client window, choose one of the following options to obtain the installer:

    • Download the latest version of Secure Client from Secure Access: Click the Download icon next to your specific operating system. To see version details, hover over the Information (i) icon beside the client name.

    • Download the cloud-managed version of Secure Client:To manage your deployment through the cloud, click Secure Client Management at the bottom of the Download Cisco Secure Client menu and choose one of the following options:

      Option 1: For Cisco XDR Customers

      Option 2:For Non-XDR Customers

      Use Secure Client Management to download and manage your clients. This is a free cloud-based application available upon registration. For more information, see About Cisco Secure Client Cloud Management.

    • Download a previous version of Secure Client from Cisco Secure Central: Click the Cisco Software link.
      Note
      You must have a valid service contract associated with your Cisco.com profile to access these files.

      In Cisco Secure Central, download the desired Secure Client pre-deployment package and the version for the OS on the end-user device.

      • Examples:

        • macOS — cisco-secure-client-macos-5.1.8.105-predeploy-k9.pkg

        • Windows — cisco-secure-client-win-5.1.8.105-predeploy-k9.msi

  4. In the Download configuration files section, download the configuration files (also known as profiles) for your deployment:


    Download configuration files section with options to download profiles for deployment
    1. VPN Module: Choose the applicable VPN profiles. The VPN profile tells Secure Access which VPN profiles to enforce. For more information, see Manage VPN Profiles.

    2. Zero Trust Access: No configuration file is required for ZTNA enrollment.

    3. Internet Security module: Download the orginfo.json file. This file configures policies in the Internet Security module (also known as the Umbrella roaming module).

    4. ThousandEyes module: Download the ThousandEyes Endpoint Agent Configuration.json file.

      Note
      To register the ThousandEyes module, you must first onboard Experience Insights in Cisco Secure Access. For more information, see Onboard Experience Insights.
  5. Install the Cisco Secure Client by running the installer (for example, Setup.exe for Windows) and following the prompts in the installation wizard. For more information, see Deploy Cisco Secure Client in the Cisco Secure Client (including AnyConnect) Administrator Guide, Release 5.


ThousandEyes Endpoint Agent Module

ThousandEyes Endpoint Agent is included as part of Cisco Secure Client. To learn how to download and manage your endpoint agents with your other Cisco Secure Client Modules, see Cisco Secure Client ThousandEyes Endpoint Agent Module.

Automatic Registration

After completing the Secure Client installation, the ThousandEyes endpoint agent will register the endpoint with your Secure Access organization automatically once the endpoint establishes a connection to VPN, ZTA, or the roaming module. For more information, see Automatic Registration of ThousandEyes Endpoint Agents.

Manual Registration

If an endpoint will not connect via VPN, ZTA, or the roaming module, you can manually register it with Secure Access by running the registration script on the endpoint command line. For more information, see Manual Registration of ThousandEyes Endpoint Agent.

MDM Registration

For an example of how to use an MDM to install Secure Client and register the ThousandEyes endpoint agent, see Deploy Cisco ThousandEyes Module via Microsoft Intune.