Jump to:navigation, search
Wiki





























 als System-Konfigurationen

| }}













Download and installation of the Securepoint VPN Client

Last adaptation to the version: 3.4.0(12.2025)

New:
  • ARM-64 Version des VPN-Clients als Beta
  • Portable x64 und ARM-64 Version des VPN-Clients als Beta
  • Aktualisierung der Kommandozeilen-Befehle
notempty
This article refers to a Beta version

System requirements

  • Windows 10 x64 or higher
  • Windows 10 arm64 or higher notempty
    New as of v3.3.3
  • 1GB RAM
Operating system:
  • Windows 10 x64 or higher
  • Windows 10 arm64 or higher notempty
    New as of v3.3.3
Term requirements:
  • windowsdesktop-runtime-6.0.12-win-x64.exe May be installed automatically
  • VC_redist.x64.exe May be installed automatically
Hardware:
  • Storage space: At least 206 MB (if the runtime requirements are also installed)
  • RAM: At least 1024 MB
  • Processor cores: 2, recommended: 4
  • Processor architecture: 64-bit (x64 or arm64)
Portable Version: notempty
New as of v3.3.3
  • .NET Desktop Runtime (at least Version 8.0.17)
  • VC Redistributables

Installation

Hinweise zur Installation finden sich in einem extra Artikel zur Installation.

Beim ersten Start kann ein Passwort für die gesamte Anwendung festgelegt werden

Portable Version

Eine portable Version des VPN Clients ist verfügbar.

  • Diese speichert den Client als .exe in einem Ordner
  • Es wird keine Installation (Eintrag in Registry etc.) durchgeführt
  • Es werden administrative Rechte benötigt
  • VPN-Tunnel, die in diesem Ordner abgelegt werden, sind auch nach einem Reboot verfügbar


Unterschiede zur normalen Version

  • Keine Cloud-Anbindung
  • Alle Daten werden in einer lokalen Datenbank gespeichert
  • Kein automatischer Start des Clients beim Systemstart
  • Keine Migration vom SSL VPN Client 2 zu Securepoint VPN Client 3




Update

Update dialogue
  • As an administrator, automatic updates can be enabled (see client settings or #Commands_at_runtime with Command Line Interface)
  • If this is not desired, an update icon will be displayed in the header when an update is available
  • If automatic updates are enabled, the system will automatically check for updates every 12 hours
  • A user can decline an automatic update 5 times, after which it will be enforced.
  • The service is restarted after an update.
    The client will use the new version the next time it is started.
    Connections that are set up with ‘’Autostart activated‘’ are restarted.


  • Tray-Icon

    Tray icon of the client in the taskbar

    When the client is started, the client icon appears in the taskbar as a tray icon. The following options are available by right-clicking on this icon:

    • Show the client window
    • Establish or disconnect a connection (is hidden if several connections are configured)
    • Close application


    Importing a VPN configuration

    Caption Description
    Importing a VPN configuration
    Protocol Protocol selection (SSL VPN, WireGuard, or folder
    For importing multiple configurations
    notempty
    : 3.2
    )
    File Use the   button to select the configuration file. button, you can select the configuration file.
    Connection name Change connection names if necessary
    Create system connection If the client was run as an administrator (indicated by the word Admin in the upper right corner of the title bar), the connection can also be created as a system connection, i.e., for all user accounts on the computer.
    Import Import connection

    Create configuration

    Call up the configuration wizard in the menu under Create

    Start the configuration of a new VPN connection with Next.
    Step 1
    • Desired protocol SSLVPNWireGuard
    • Meaningful name for the connection
    • If executed with admin rights: If necessary, UserSystem
      The connection is then available in all user accounts on this computer.

    SSLVPN

    To configure an SSLVPN connection, follow the instructions below:

    Step 2
    • At least one VPN server must be added using the protocol, the IP address or the host name and the port.
    Step 3
  • Select client and server keys or certificates (with )
    Assignment with typical naming:
    Certification Authority (CA)
    …cert.pem
    Private key (RSA)
    …cert.key
    Public Key (CA)
    …ca.pem
  • The option Check server certificates can be used to enable server certificate verification.
  • Step 4
  • Configure the connection with the VPN server accordingly
  • Redirect Gateway
    • If deactivated, only packets to a local destination network are routed through the tunnel
    • If activated, all packets are routed to the tunnel and from there routed further if necessary
  • Step 5
    Summary of all settings for review. If all settings are correct, the configuration wizard can be closed by clicking the Apply button and the connection can be added.

    WireGuard

    Follow the instructions below to configure a WireGuard connection:

    Step 2
    • At least one VPN server must be added using the protocol, the IP address or the host name and the port.
    Step 3
  • Enter client and server key
  • optional Enter preshared key
  • Step 4
  • Client IP address required
  • Other values can be left blank, these options are then either ignored or assigned a default value
  • DNS address(es) can also be entered as a domain notempty
    as of v1.0.9
  • Step 5
    Summary of all settings for verification. If all settings are correct, the configuration wizard can be closed with the Apply button and the connection added.


    Connection settings

    System and user connections

    User connections are saved in the Windows registry under the HKEY_CURRENT_USER context and are therefore only available to the Windows user who imported the connection.

    System connections are stored under HKEY_LOCAL_MACHINE and are therefore available to every user of the machine, but require administration rights for import.

    Establishing a connection

    A connection can be established either via the context menu /  Connect or by clicking on the connection button.

    Connection disconnected
    Connection is being established
    Connection button
    For SSL VPN connections, it may be necessary to enter an OTP



    Connection overview

    Caption Value Description
    Connection overview
    Search
    Search bar to search connections
  • Only displayed after seven connections
  • Status Connected Connection is established
    Connecting Connection is being established
    Failed Connection could not be established
    Disconnected No connection
    Name TTT-Point-1 Name of the connection
    Mehr Opens the context menu for the respective connection.
    / Switches between standard view and compact view of the client


    Extended view

    Connection details in the expanded view

    Additional connection details are displayed via the “Show Details” entry in the context menu:

    • Received data
    • Sent data
    • Connection duration
    • Device name (interface used)
    • Wintun version
    • IPv4 address / IPv6 address

    Compact view

    Description
    Compact view VPN Client
    Switches between standard view and compact view of the client
    - WireGuard

    - SSL-VPN
    - System connection (available to all users)
    - User data is stored
    - Reconnect when connection is lost
    - Connect automatically

    - PIN required for connection
    Connection duration
    Link button
    Upload and download volume and speed

    Context menu

    Call using the button in the connection overview or by right-clicking on a connection.

    Menu item Description WireGuard-Connections Context menu
    SSLVPN-Connections Context menu
     Connect Enable VPN connection
     Edit
    Only possible as Admin with a system connection
    Shows the associated configuration and the certificates that can be edited
     Apply OTP

    Starting with v3.1.0, the system automatically detects whether an OTP is required. No manual configuration is necessary.
     Connect automatically Automatically establishes this connection when the app is started.
     Reconnect when connection is lost If the connection is unexpectedly interrupted, an attempt to reconnect will be made automatically.
     Connect pre-logon
    Only possible as Admin with a system connection
    When the system starts up, a connection to this system connection is initiated
    • For SSLVPN connections, the user login data must be saved
    • As long as OTP is active, pre-logon cannot be activated
     Edit user data
    Only possible as Admin with a system connection
    Not possible with a Wireguard connection
    Opens a window through which you can update the user data
     Delete user data
    Only possible as Admin with a system connection
    Not possible with a Wireguard connection
    Deletes the user data for the current connection
     Add or edit PIN
    Only possible as Admin with a system connection
    Only possible with a Wireguard connection
    Secure connection with PIN, which will then be required for every connection attempt.
     Delete PIN
    Only possible as Admin with a system connection
    Only possible with a Wireguard connection
    Delete connection PIN
     Excluded SSIDs
    Only possible as Admin with a system connection
    Configure networks for which no connection should be established
    Currently only configurable via context menu

    Dialog for excluded SSIDs
     Export
    Only possible as Admin with a system connection
    Opens a dialogue through which you can export the selected connection as a text file notempty
    It is not possible to export ASC connections
    neither as a user nor as an administrator
    .
     Export multiple connections
    Only possible as Admin with a system connection
    Opens a dialog box that allows you to export multiple selected connections at once. notempty
    It is not possible to export ASC connections
    neither as a user nor as an administrator
    .
     Show log Calls up the log for the specific connection
     Show details Opens the connection to the full width and length and displays further helpful information
     Diagnosis
    • Switches to the diagnostic view
    • Testing server connectivity (Can a specified server be reached?)
    • Analyse the log
    • Testing the public IP address (via https://checkip.spdyn.de)
     Delete connection
    Only possible as Admin with a system connection
    Deletes the current connection
     Mehrere Verbindungen löschen
    Only possible as Admin with system connections
    notempty
    New as of v3.4.0
    Öffnet einen Dialog, um mehrere Verbindungen gleichzeitig löschen zu können


    Client settings

    Settings for application start:
    • Run when starting Windows
    • Start application minimised (tray icon)
    • Show migration wizard again
    Settings relating to the connections:
  • Minimise the client after connecting
  • Allow multiple VPN connections at the same time
  • Block shutdown during active connection
  • Attitudes towards appearance:
  • Show pop-up window when application is minimised
  • Display flyout information within the application
  • Activate dark mode
  • Choose language
  • notempty
    These settings are only displayed if the application was started as an administrator, this can be recognised by the "ADMIN" at the top right.

    Advanced settings for administrators:
  • Perform client updates automatically
  • Force DNS, all DNS requests must be made via the VPN


  • Log

    Button Description
    Log overview
    Complete Filters the log by type: Complete log, Client, Connections, Daily, Service
    50 Shows a maximum of the set number of log messages
    Copy Log Copies the entire (also invisible) log
    Copy current Copies the entire currently visible log
    Export Exports the entire currently visible log
    notempty
    New as of v3.4.0
    Verbessertes Logging für ASC-Aktionen, insbesondere beim Anwenden von Profilen und VPN-Konfigurationen

    Command line commands

    Commands at runtime

    The commands are always appended to the installed client call (.\"Securepoint VPN Client.exe")

    Command Description / Example
    /enrollment Performs enrollment for a USC connection
    s.\"Securepoint VPN Client.exe" /enrollment <token>
    /log
    Exports the complete log
    .\Securepoint_VPN_Client.exe /log
    /import <path>
    short form: /i <path>
    Zum importieren aller VPN Konfigurationen aus dem angegebenem Zielordner. Hier werden die Konfigurationen im Benutzer-Kontext angelegt.
    .\Securepoint_VPN_Client.exe /import "C:\Downloads\VPN-Configs"
    /migrate
    short form: /m
    Migrate a connection from the file path of the old Securepoint SSL VPN client.
  • The result per connection is either ALREADY EXISTS (connection with the same name already exists in the registry. It is important that only the name is taken into account, not whether an identical copy of a config has already been imported), SUCCESS or FAILED.
  • All connections are created as USER connections.
  • .\Securepoint_VPN_Client.exe /migrate
    /sys-migrate notempty
    New as of v3.4.0
    Migration vorhandener als System-Konfigurationen
    .\"Securepoint VPN Client.exe" /sys-migrate
    /autoupdate <value> : bool Automatic updates of the client are only possible with admin rights.
    .\Securepoint_VPN_Client.exe /autoupdate true
    /prevent-dns-leaks <value> : bool Enable the “Prevent DNS leaks” option
    Only possible with admin rights
    .\Securepoint_VPN_Client.exe /prevent-dns-leaks true
    /sys-import notempty
    New as of v3.4.0
    Automatischer Import von Konfigurationen aus dem Unterverzeichnis .\data\config als System-Konfigurationen
    .\securepoint-vpn-client-<VERSION>.exe /sys-import /accept-license-agreement=yes