09-16-2025 04:09 AM
Hi
Its my understanding from previous machine tunnel configurations on ASAs/FTDs, that the machine tunnel XML profile name needs to be 'VpnMgmtTunProfile'. However, when I download the machine tunnel XML from Secure Access the file name is 'machine-tunnel-[Org ID]-27'.
I assume it still needs to be 'VpnMgmtTunProfile' when installed on the end clients? but I need to confirm this before deploying as the solution is already in production. Please could someone confirm?
Kind regards
Terry
09-16-2025 04:19 AM
There is no restrictions of profile name for mgmt tunnel as I know
MHM
09-16-2025 04:35 AM
Hi MHM
Thanks for your reply.
In the 'Cisco Secure Client Administrator Guide' is shows an example of the machine tunnel configuration on an ASA and states the following:
You can deploy only one management VPN profile to a given client device. The management VPN profile is stored in a dedicated directory (%ProgramData%\Cisco\Cisco Secure Client\VPN\Profile\MgmtTun in Windows, /opt/cisco/secureclient/VPN/profile/mgmttun in macOS) with a fixed name (VpnMgmtTunProfile.xml).
09-16-2025 04:38 AM
Let me check
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide