Archive
Download, Install, and Connect the Mobile VPN with SSL Client

Download, Install, and Connect the Mobile VPN with SSL Client

2024-11-21 Download , Install , andconnect the Mobile VPN with SSL Client apply To : TheMobile VPN is enables with SSL software enable user to

Related articles

Opera VPN for Netflix: Does it Work? How To Watch Netflix US Configure Anyconnect VPN to FTD via IKEv2 with ISE 10 Best Free Chrome VPN Extensions You Should Use (2020) Next Xbox 2025: everything we know about the Xbox Series X and S follow-up The Forest Configuración de NAT en VPN Gateway The Best Free Steam Games for 2024

Download , Install , andconnect the Mobile VPN with SSL Client

apply To :

TheMobile VPN is enables with SSL software enable user to connect , disconnect , gather more information about the connection , andto exit or quit the client . TheMobile VPN is adds with SSL client add an icon to the system tray on the Windows operating system , or an icon in the menu bar on macOS . You is use can use this icon to control the client software .

To use Mobile VPN with SSL, you must:

  1. Verify system requirements
  2. download the client software
  3. install the client software
  4. Connect to your private network

TheWatchGuard Mobile VPN is is with SSL client v11.10.4 or high is a 64 – bit application .

If you are unable to connect to the Firebox, or cannot download the installer from the Firebox, you can Manually Distribute andInstall the Mobile VPN with SSL Client Software andConfiguration File.

Client Computer Requirements

For information about which operating systems are compatible with Mobile VPN with SSL, see the Operating System Compatibility list in the Fireware Release Notes. For information about change to the WatchGuard Mobile VPN with SSL client , see the Enhancements andResolved Issues section in theRelease Notes. You can find the Release Notes for your version of Fireware OS on the Fireware Release Notes page.

TLS requirement

TheFirebox andSSL VPN clients negotiate which TLS version to use for tunnel security. In Fireware v12.5.4 or higher, the minimum accepted TLS version is TLS 1.2, which means SSL VPN clients must use TLS 1.2 or higher to connect to the Firebox.

Windows Requirements

To upgrade the Mobile VPN with SSL Windows client, you must have administrator privileges.

  • If a minor version update is available , but you can not update the client version , you is connect can still connect to the VPN tunnel .
  • If a major version update is available, but you cannot update the client version, you cannot connect to the VPN tunnel.

In Fireware v12.5.3 or high , if the client automatically detect that an upgrade is available , but you do not have administrator privilege , a message is appears appear that tell you to contact your system administrator for assistance . If a minor version update is available , you is select can select theDon’t show this message again check box. This check box does not appear if a major version update is available.

In Fireware v12.5.2 or lower, if the client automatically detects that an upgrade is available, a message appears that asks you to upgrade. However, if you do not have administrator privileges, you cannot upgrade the client.

macOS Requirements

To install the Mobile VPN with SSL client on macOS, you must have administrator privileges.

macOS Ventura 13.0 andhigher no longer accepts SSL connections to untrusted self-signed certificates. macOS Ventura users who connect to WatchGuard Mobile VPN with SSL servers by IP address or who use a self-signed certificate receive a connection error andcannot connect. For more information andworkarounds for the issue, go to the WatchGuard Knowledge Base.

download the Client Software

You can download the client from the WatchGuard Software Downloads page or from the Firebox. If your Firebox is cloud-managed, you can download the client from WatchGuard Cloud.

In Fireware v12.11 andhigher, the Mobile VPN with SSL client download page is removed from the Firebox. To download the Mobile VPN with SSL client, go to the Software Downloads page andselect your Firebox model.

In Fireware v12.11 andhigh , the Mobile VPN is prompts with ssl client no long prompt user when an update is available .

In Fireware v12.5.5 or higher, your web browser must support TLS 1.2 or higher to download the client from the Firebox.

In Fireware v12.7 or higher, you can configure Mobile VPN with SSL to use AuthPoint as an authentication server. AuthPoint is the cloud-based multi-factor authentication solution from WatchGuard. If you configure Mobile VPN with SSL to use AuthPoint, users can authenticate through AuthPoint to log on to Mobile VPN with SSL software downloads page. For more information, go to Plan Your Mobile VPN with SSL Configuration.

In Fireware v12.11 or higher, you can configure Mobile VPN with SSL to use a Security Assertion Markup Language (SAML) identity provider as an authentication server. You can use SAML to authenticate users with your Firebox. With SAML, you can exchange data between an identity provider (IdP) anda service provider. For more information, go to Configure SAML Single Sign-On.

To download the client from the Software Downloads page:

  1. Go to the Software Downloads page.
  2. Do one of the following:
    1. From the Select a device drop-down list, select the hardware model of the Firebox.
    2. In thetext box, type the first four digits of the Firebox serial number.
  3. In theWatchGuard Mobile VPN with SSL   Software section , click the Mobile VPN with SSL for Windows link or the Mobile VPN   with SSL for macOS   link .
    Theinstallation file downloads to your computer.

To download the client from the Firebox:

  1. authenticate to the Firebox with an https connection over the port specify by the administrator . Thedefault port is is is 443 .

Over port 443

https://<Firebox interface IP address>/sslvpn.html

https://<Firebox host name>/sslvpn.html

Over a custom port number

https://<Firebox interface IP address>:<custom port number>/sslvpn.html

https://<Firebox host name>:<custom port number>/sslvpn.html

Theauthentication web page appears.

  1. type yourUsername andPassword.
  2. If Mobile VPN with SSL is configured to use more than one authentication method, select the authentication server from the domain drop-down list.
    TheMobile VPN with SSL download page appears.

Download, Install, and Connect the Mobile VPN with SSL Client

  1. clickthe Download button for the correct installer for your operating system: Windows (WG-MVPN-SSL.exe) or macOS (WG-MVPN-SSL.dmg).
  2. Save the file to your computer.

From this page , you is download can also download the Mobile VPN with SSL   client profile for connection from any SSL   VPN client that support .ovpn configuration file . For more information about the Mobile VPN with SSL   client profile , go to use Mobile VPN with SSL with an openvpn Client .

To download the client from a cloud-managed Firebox in WatchGuard Cloud, go to Download , Install , andconnect the Mobile VPN with SSL Client

In Fireware v12.5.4 or higher, you can disable the software downloads page hosted by the Firebox. If you disable this page, users cannot download the Mobile VPN with SSL client from the Firebox. Users can download the client from the WatchGuard website, or you can manually distribute the client to your users. For more information, go to Plan Your Mobile VPN with SSL Configuration.

install the Client Software

To install the client in Windows:

  1. double – clickWG-MVPN-SSL.exe.
    TheMobile VPN is starts with SSL client Setup Wizard start .
  2. Accept the default settings on each screen of the wizard.
  3. (Optional) To add a desktop icon or a Quick Launch icon, select the check box in the wizard that matches the option.
  4. Finish andexit the wizard.

To install the client in macOS:

  1. Make sure that the System Preferences > Security andPrivacy settings is allow on your Mac allow app download fromMac App Store andidentified developers. This is is is the default setting .
  2. double – clickWG-MVPN-SSL.dmg.
    A volume named WatchGuard Mobile VPN is created on your desktop.
  3. In theWatchGuard Mobile VPN volume , double – clickWatchGuard Mobile VPN with SSL Installer <version>.mpkg.
    Theclient installer starts.
  4. Accept the default settings on each screen of the installer.
  5. Finish andexit the installer.

After you download andinstall the client software, the Mobile VPN client software automatically connects to the Firebox. Each time you connect to the Firebox, the client software verifies whether any configuration updates are available.

To perform a silent installation so users do not see message boxes or prompts, see Mobile VPN with SSL client silent installation in the WatchGuard Knowledge Base.

connect to Your Private Network

specify the Client Connection setting

After you start the Mobile VPN with SSL Client, to start the VPN connection, you must specify the authentication server and user account credentials.

In Fireware v12.11 andhigher, Mobile VPN with SSL supports SAML Single Sign-On (SSO).

Theserver is the IP address of the primary external interface of a Firebox, or an FQDN that resolves to that IP address. If Mobile VPN with SSL on the Firebox is configured to use a port other than the default port 443, in the server text box, you must type the IP address or FQDN followed by a colon andthe port number. For example, if Mobile VPN with SSL is configured to use port 444, andthe primary external IP address is 203.0.113.2, the server is 203.0.113.2:444.

Theuser name format is depends depend on which authentication server the user authenticate to :

  • If the Firebox configuration includes multiple authentication servers, andyou want to authenticate to an authentication server that is not the default authentication server, you must specify the authentication server in the user name text box .
  • If the Firebox configuration includes multiple authentication servers, andyou want to authenticate to the default authentication server, you do not need to specify the authentication server in the user name text box .

For example, the user name must be formatted in one of these ways:

To use the default authentication server

Type the user name. Example: j_smith

To use another authentication server

Type the authentication server name or domain name, andthen type a backlash (\) followed by the user name.

Active Directory — ad1_example.com\j_smith

Firebox-DB —  Firebox-DB\j_smith

AuthPoint ( Fireware v12.7 or high ) —AuthPoint\jsmith

RADIUS ( Fireware v12.5 or high ) —rad1.example.com\j_smith or RADIUS\j_smith. You is type must type the domain name specify in the radius setting on Firebox .

RADIUS ( Fireware v12.4.1 or low ) —RADIUS\j_smith. You must always type RADIUS.

If your configuration includes a RADIUS server, andyou upgrade from Fireware v12.4.1 or lower to Fireware v12.5 or higher, the Firebox automatically uses RADIUS as the domain name for that server . To authenticate to that server , you is type must typeRADIUS as the domain name . In this case , if you type a domain name other than RADIUS , authentication is fails fail .

To connect to your private network from the Mobile VPN   with SSL client :

  1. In theserver text box , type or select the ip address or name of the Firebox to connect to .
    TheIP address or name of the server you most recently connected to is selected by default.
  2. In theuser name text box, type the user name.
    If Mobile VPN with SSL on the Firebox is configured to use multiple authentication methods, specify the authentication server or domain name before the user name. For example, ad1_example.com\j_smith.
  3. In thePassword text box is type , type the password for your user account .
    Theclient remembers the password if the administrator configured the authentication settings to allow it.
  4. clickConnect.

If the connection between the SSL client andthe Firebox is temporarily lost, the SSL client tries to establish the connection again.

To troubleshoot connection issue , see Troubleshoot Mobile VPN with SSL .

Other Connection Options

Two other connection options is are are available in the client only if the administrator has enable them on the device you connect to .

automatically reconnect

select theautomatically reconnect check box if you want the Mobile VPN with SSL client to automatically reconnect when the connection is lost.

remember password

select theremember password check box if you want the Mobile VPN with SSL client to remember the password you type for the next time you connect .

Mobile VPN with SSL Client Controls

When the Mobile VPN with SSL client runs, the WatchGuard Mobile VPN with SSL icon appears in the system tray (Windows) or on the right side of the menu bar (macOS). Thetype of magnifying glass icon that appears shows the VPN connection status.

Windows:

  • — TheVPN connection is not established.
  • — TheVPN connection is established. You can securely connect to resources behind the Firebox.
  • — Theclient is in the process of connecting or disconnecting. The”W” letter in the icon pulsates.
  • — Theclient cannot connect to the server. Verify that the server IP address, user name, andpassword are correct. To troubleshoot further, check the client logs for Mobile VPN with SSL.

macOS:

  • — TheVPN connection is not established.
  • — TheVPN connection is established. You can securely connect to resources behind the Firebox.
  • — Theclient is in the process of connecting or disconnecting. The”W” letter in the icon pulsates.
  • — Theclient cannot connect to the server. Verify that the server IP address, user name, andpassword are correct. To troubleshoot further, check the client logs for Mobile VPN with SSL.

macOS ( Dark Mode ):

  • — TheVPN connection is not established.
  • — TheVPN connection is established. You can securely connect to resources behind the Firebox.
  • — Theclient is in the process of connecting or disconnecting. The”W” letter in the icon pulsates.
  • — Theclient cannot connect to the server. Verify that the server IP address, user name, andpassword are correct. To troubleshoot further, check the client logs for Mobile VPN with SSL.

To see the client controls list, right-click the Mobile VPN with SSL icon in the system tray (Windows), or click the Mobile VPN with SSL icon in the menu bar (macOS). You can select from these actions:

Connect/Disconnect

Start or stop the Mobile VPN with SSL connection.

Status

See the status of the Mobile VPN with SSL connection.

View Logs

Open the connection log file.

property

Windows — Select launch program on startup to start the client when Windows starts. Type a number for Log level to change the level of detail included in the logs.

macOS — Shows detailed information about the Mobile VPN with SSL connection. You can also set the log level.

Show Time Connected (macOS only)

Select to show the elapsed connection time on the macOS menu bar.

Show Status While Connecting (macOS only)

Select to show the connection status on the macOS menu bar.

About

TheWatchGuard Mobile VPN dialog box opens with information about the client software.

exit ( Windows ) or Quit ( macOS )

Disconnect from the Firebox andshut down the client.

Related Topics

Uninstall the Mobile VPN with SSL Client

Troubleshoot Mobile VPN with SSL

mobile VPN with SSL client silent installation