09-03-2025 04:47 AM
09-03-2025 04:55 AM
the S2S VPN will not effect by change clinet service port
MHM
09-03-2025 06:07 AM
If you do not need to download client image and have different way to push to end client, then you can disable.
i dont remember steps on top of my head.
Navigate to VPN settings: Go to Devices > VPN > Remote Access.
Edit the IPSec crypto maps: Under the IPsec tab, find the Crypto Maps section and edit the policy.
09-04-2025 07:59 AM - edited 09-04-2025 08:00 AM
Disabling client services will not affect site-to-site VPNs.
It will affect the ability to push profile and Secure Client updates as those rely on client services over SSL/TLS - even with a remote access VPN that otherwise uses IPsec IKEv2.
See my whitepaper here for more details: https://community.cisco.com/t5/security-knowledge-base/configuring-ipsec-ikev2-remote-access-vpn-with-cisco-secure/ta-p/4485165
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide