Cisco Secure Client Installation (macOS)
Description
Use this recipe to package and deploy Cisco Secure Client to managed Macs with FileWave. You will import the FileWave templates, replace the example Cisco package and XML with your files, approve the required macOS extensions, and test the result before broad deployment.
Ingredients
-
FileWave Central
-
Cisco Secure Client DMG file, example file name from your Cisco portal:
-
cisco-secure-client-macos-<version>-predeploy-k9.dmg
-
- MDM profile for Cisco security extensions and permissions
- Older macOS versions for Kernel Extension TCC profile:
- Profile - Cisco Secure Client Kernel Extensions.fileset.zip
- macOS 11 (and later) for System Extension TCC profile:
- Profile - Cisco Secure Client System Extensions macOS 11 (and after).fileset.zip
- Template Install Cisco Secure Client Fileset
Directions
-
Download and import the installation template plus the extension profile that matches your target macOS version. Create a Fileset Group named Cisco Secure Client Install or similar.
-
Open the Install CiscoSecureClient Fileset. It contains two scripts and placeholders for your customized DMG and XML files.

-
Follow Cisco's current Customize macOS Installation of Cisco Secure Client instructions to prepare the DMG and choose the modules your organization needs. The DMG and XML in the template are examples and must be replaced with your deployment files.
-
Replace the example DMG in the Fileset with the DMG you prepared.
-
Open the install script and update the DMG name and Cisco Secure Client PKG name to match your files. Escape spaces in the script path, for example
Cisco\ Secure\ Client.pkg.
The script mounts the DMG, locates the PKG, extracts it to the root directory, installs the client, waits 30 seconds, and detaches the DMG. If you use a customizedinstall_choices.xml, replace the example XML in the Fileset as well.
-
Use the System Extension profile for macOS 11 and later; it also includes the Web Content Filter and Managed Login Items settings. Use the Kernel Extension profile only for older macOS versions that still require it.
Update thecheck_profilescript and its Launch Argument to match the profile bundle ID or IDs you deploy. The template checks only the macOS 11-and-later profile bundle ID.



-
Save the changes and assign the Fileset Group to a small pilot. The group deploys the profile and installation Fileset; after the required profile is installed, the Cisco Secure Client installation can proceed.

Notes
On the pilot Macs, confirm the profile is installed, the selected Cisco modules are present, the client opens correctly, and the expected network connection works before expanding the assignment.
No comments to display
No comments to display