Using the VPN Client Configuration Utility

If you use this tool to create an MSI for SmartEndpoint-managed deployments, you must distribute it with an exported package, and not with Automatic Software Deployment.

To edit an MSI client package with the VPN Client Configuration Utility:

  1. Get the MSI file:

    • SmartEndpoint-managed - Export a package that includes Remote Access VPN from the SmartEndpoint.

    • SmartConsole-managed - Download the MSI from the Support Center.

  2. Run VPNConfig.exe.

    The VPN Client Configuration Utility opens on the General tab.

  3. Click Browse to select the location of the MSI.

  4. Select the options and their values to include in the MSI:

    • Secure Domain Logon - To control whether the authentication credentials sent to the Domain Controller are sent through an encrypted channel.

    • Fixed MAC - To control whether to use fixed MAC address for Office Mode IP address allocation.

    • No Office Mode - To control Office Mode support.

    • Replace trac.defaults file - This file includes the default values for configuration attributes.

    • Replace trac.config file - This file includes VPN Site configuration.

      Optional: Select Overwrite user's configuration when upgrading. When selected, if a user has an earlier version of Remote Access Clients and installs the new MSI, the old trac.config file is overwritten by the new trac.config file.

  5. If you selected to replace a trac.* file, browse to the path of the trac.* file that you want to include.

    Important:

    • If you selected to replace the trac.config file, then you have to provide the path for both trac.config and trac.defaults files.

    • If you selected to replace the trac.config and trac.defaults files, then you have to use the configuration files from the same version as the customized MSI package. For example, if you need to customize the MSI of E87.10, then use the trac.config and trac.defaults from E87.10.

  6. Optional: Create a CAB file for Standalone VPN Client only.

    Select the Save CAB as well (Standalone VPN Client only) check box to create a TRAC.cab file to use for an upgrade with SmartEndpoint-managed client.

    • Create a ver.ini file with the correct build number. Make sure the build number is higher than the build number in the current ver.ini file (located in the Endpoint Client installation directory).

    • To upgrade using a customized TRAC.cab file, users need to use it together with Upgrading with a Customized Package.

  7. Optional: Open the Edit Files tab.

    Add the desired files to the installation directory. For example, a script to use with Configuring Post Connect Scripts.

  8. Optional: Open the Advanced tab.

    • For SmartConsole-managed clients, select a VPN Client sub type:

      • Endpoint Security VPN - To force this VPN Client sub type.

      • Check Point Mobile for Windows - To force this VPN Client sub type.

      • SecuRemote - To force this VPN Client sub type.

      • User defined (default) - To let user select the VPN Client sub type.

      • Click Add to add SCV Plugins - To make sure that Remote Access client computer is configured in accordance with the enterprise Security Policy.

  9. Click Save.

  10. Select the location where the new MSI will be saved.