11-17-2025 08:55 AM
Hello Cisco Community:VPN and AnyConnect, VPN
We're working on pushing out the latest releases of Cisco Secure Client. Recently, we migrated our environment's VPN head-end concentrators from legacy ASA5555X's, to FirePower 4110's. Previously, in ASA's there was no option for targeted module upgrades for our clients. You uploaded the head-end package to the VPN concentrator, and then clients connecting would pull down the latest VPN modules.
In Firewall Management Center, is there any additional options for targeted upgrades? Meaning, for test groups of clients, is there a way to upgrade just a subset of clients connecting to our concentrator, or is it still an all or nothing approach? For on-prem we already use ISE client provisioning to push out the latest Secure Client, but we have some remote users that we need to upgrade, and are concerned if they run into any issues with modules updating properly.
Thanks in advance for any support!
Solved! Go to Solution.
11-17-2025 09:00 AM
@Inq_J no unfortunately you cannot do that with FTD/FMC, when you upload the new client software all clients when they connect will upgrade their software (unless the local configuration bypasses updates). You'd have to use your software management solution, such as SCCM to target users or computer to upgrade their Secure Client software.
11-17-2025 09:00 AM
@Inq_J no unfortunately you cannot do that with FTD/FMC, when you upload the new client software all clients when they connect will upgrade their software (unless the local configuration bypasses updates). You'd have to use your software management solution, such as SCCM to target users or computer to upgrade their Secure Client software.
11-17-2025 09:03 AM
Thanks for the quick response, much appreciated.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide