After ensuring that your servers meets all the proper requirements, configuring VMware Tunnel settings in the AirWatch Console, and downloading the installer to your Linux server, you can run the installer to enable the service.


If you are installing the Proxy component either alone or in combination with the Per-App Tunnel component, the installer refers to the front-end server as the relay server. Proxy uses the relay-endpoint mode for communication. The relay-endpoint deploys alongside the cascade mode services on the same server. Consider using just the Per-App Tunnel component for your VMware Tunnel solution as it has additional features and functionality that the Proxy component does not.


  • Download the installer and transfer to the server. The link in the AirWatch Console directs you to AirWatch Resources to download the installer.
  • If you are using the API method, the installer prompts for the necessary configuration information. You do not need to download the vpn_config.xml file.
  • If you are using the configuration file method, download the vpn_config.xml file from the AirWatch Console and transfer to the server.


Perform the following steps on the front-end server:

  1. Create a dedicated install directory for the installer on the front-end server (for example, /tmp/Install/) and copy the BIN file to this location. You can use file transfer software such as FileZilla or WinSCP to perform the action.

  2. Once on the Linux server, navigate to the folder you copied the file to and then run the BIN file by using the following command:

    $ sudo ./VMwareTunnel.bin

    If you are installing for the first time, the following screen displays:


    Press Enter.

  3. Read and accept the licensing agreement by entering ' y'.

  4. After accepting the licensing agreement, you must choose your installation method.


    • Option 1: Provide API Server Information
      1. Enter the following information. After entering each value, the system dialog asks you to confirm the entry.
        • VMware API URL
        • Organization Group Code
        • Console Server Username
        • Console Server Password
      2. Enter the hostname of the Tunnel server.
      3. The installer chooses the components to install based on the AirWatch Console configuration.


        Press Enter.

      Continue to Step 5.

    • Option 2: Import Config.xml file
      1. Select the components you want to install.
      2. Enter the file path of the configuration file.
      3. Enter the VMware Tunnel certificate password as entered in the AirWatch Console.

      Continue to Step 5.

  5. Enter Relay or Front as the configuration type for VMware Tunnel Setup.
  6. Enter Y to grant the installer firewall permissions needed for VMware Tunnel.


    Note: The ports you see may differ from the ones shown because the installer shows the values you set during VMware Tunnel configuration.

  7. Review and verify the summary information.


    When the installer finishes, press Enter to exit the installer.

The product begins installation. If there were any errors, the installer displays an error message with details and logs the error in the installation log file. The log file is saved in the directory that you installed the VMware Tunnel in.

To complete your installation, see Install the VMware Tunnel Endpoint Server.