Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


Install Juniper Secure Connect on Windows

SUMMARY Learn about how to create rollout packages for Juniper Secure Connect application software and step-by-step procedures to install Juniper Secure Connect on Windows. If you want to install Juniper Secure Connect application, see Manual Installation of Juniper Secure Connect. If you are an administrator, see Create Installation Packages for Juniper Secure Connect Rollout section to prepare the installer for software rollout.

What's Next

For more information on Juniper Secure Connect GUI elements, see Juniper Secure Connect GUI Elements.

For more information on Juniper Secure Connect features and how to configure the options, see Connection Menu, View Menu, and Help Menu.

Manual Installation of Juniper Secure Connect

Following are the steps to install the Juniper Secure Connect on your Windows machine.

  1. Run the Windows installer (.exe) for Juniper Secure Connect . See Figure 1.
    Figure 1: Installer Welcome WindowInstaller Welcome Window
  2. Read the license agreement carefully. If you accept the terms, then select I accept the terms in the license agreement check box to accept the license agreement. See Figure 2.
    Figure 2: License Agreement WindowLicense Agreement Window
  3. Click Next and choose the installation folder for downloading the Juniper Secure Connect software. See Figure 3.
    Figure 3: Choose Installation FolderChoose Installation Folder
  4. Click Next and select Create a shortcut on the desktop to create a shortcut for Juniper Secure Connect on your desktop. See Figure 4.
    Figure 4: Create Juniper Secure Connect Shortcut on DesktopCreate Juniper Secure Connect Shortcut on Desktop
  5. Click Next and the installation page screen appears. Verify that you have enough space on your system. Click Install to begin the installation process. See Figure 5.
    Figure 5: Start Juniper Secure Connect InstallationStart Juniper Secure Connect Installation

    The installation takes several minutes to complete. Please wait till the installation is completed. See Figure 6.

    Figure 6: Juniper Secure Connect Installation Status DisplayJuniper Secure Connect Installation Status Display
  6. Once the installation is complete, click Finish. See Figure 7.
    Figure 7: Juniper Secure Connect Installation CompletedJuniper Secure Connect Installation Completed

    Congratulations! The Juniper Secure Connect application is successfully installed in your Windows machine.

  7. To use the application, you must first restart your system. See Figure 8.
    Figure 8: System Restart NotificationSystem Restart Notification
  8. You can now launch the Juniper Secure Connect and enter the Gateway Address URL to connect with the SRX Series Firewall. Figure 9 shows an example to enter the gateway address to the SRX Series Firewall.

    You can also enter a fully qualified domain name (FQDN) in the Gateway Address URL to connect with the SRX Series Firewall. For example:

    After entering the gateway address, click the connection toggle button to establish connection manually to the destination system. You can also select Connection > Connect from the menu bar to manually establish a VPN connection. When the connection is established successfully, the application window minimizes in the task bar.

    Figure 9: Launch Juniper Secure Connect Launch Juniper Secure Connect

Custom Branding Option

Juniper Secure Connect for windows allows you to add your own logo or branding image. It also allows you to add HTML page for the branding image that would open when you click on the branding area in the Juniper Secure Connect. The HTML page is optional where you can provide any information you want. You should customise the installation package for branding your client. For detailed instructions, see Create Installation Packages for Juniper Secure Connect Rollout (Windows).

Figure 10 is the sample screen, where the customizable branding area is highlighted:

Figure 10: Custom Branding Option (Windows)Custom Branding Option (Windows)

Create Installation Packages for Juniper Secure Connect Rollout

As a system administrator, you can also build your own rollout packages, if required. Building the rollout packages is an optional step. When you create rollout packages for Juniper Secure Connect application, you can install the application across the organization. Read the following steps to learn how you, as a system administrator can prepare the Juniper Secure Connect installer for the software rollout.

You can use an installation package for easy rollout of the Juniper Secure Connect application. You must be assigned the privileges of a system administrator to perform the following steps:

  1. Install the Juniper Secure Connect application manually on one device. After the installation is complete, initiate a connection to the profiles to be saved for the users.

  2. Create a folder with name JuniperSecureConnect including the sub-directories as shown below (all directory are case sensitive):






  3. Copy the ncpphone.cfg file from C:\ProgramData\Juniper\SecureConnect\Data folder to the following folder:


  4. Copy your CA certificates to the following folder:


  5. Copy the Nam_ of_juniper_secure_connect_filename.exe to the following folder:


  6. Open the command prompt using cmd command and navigate to C:\JuniperSecureConnect folder path and execute the following command:

  7. (Optional) To add a custom branding option, follow these steps:

    • Create an .ini file named cbo.ini that contains the following information:

    • Create a logo in .bmp file format and with cbo.bmp file name. The width of the image must be 328 pixels only. The height of the image can be adjusted from 24 pixels and above.

    • You can optionally create an HTML file with cbo.html as a file name that will open if the user clicks on the logo in the application.

    • Now copy these three files (cbo.ini, cbo.bmp, and cbo.html) into the following folder:


  8. Skip this step, if you are using pre-shared key authentication method.

    For EAP-TLS authentication, you must save the user certificates only with name user.p12 in below directory.


    Ensure that user certificate is unique for each installation package.

  9. You can optionally start the installation using the .exe or the .msi installer. Based on your choice you can also remove one of the installers (.exe or .msi) from the folder if you want to reduce the amount of data distributed:


    • exe installer prompts for an interactive installation

    • msi installer can be silent. Following are your options for the msi installer:

      Table 1: msi Installer Options



      msiexec.exe /I

      Install the application

      msiexec.exe /uninstall

      Uninstall the application


      MSI installer package


      Silent installation




      0=No shortcut on desktop, 1=Shortcut on desktop

      /log path

      Path for installation log


      Forces a reboot of the system automatically without any user notification


      Prevents a reboot from happening, a reboot is mandatory to use the application


      Users will be prompted to reboot their device, a reboot is mandatory to use the application

      Following is the example syntax to install the client silently with a forced reboot and save a shortcut to the application on the desktop: