After ensuring that your servers meets all the proper requirements, configuring VMware Tunnel settings in the Workspace ONE UEM console, and downloading the installer to your Linux server, you can run the installer to enable the service.

Note: If you are installing the Proxy component either alone or in combination with the Per-App Tunnel component, the installer refers to the front-end server as the relay server. Proxy uses the relay-endpoint mode for communication. The relay-endpoint deploys alongside the cascade mode services on the same server. Consider using just the Per-App Tunnel component for your VMware Tunnel solution as it has additional features and functionality that the Proxy component does not.


  • Download the installer and transfer to the server. The link in the Workspace ONE UEM console directs you to Workspace ONE UEM Resources to download the installer.
  • If you are using the API method, the installer prompts for the necessary configuration information. You do not need to download the vpn_config.xml file.
  • If you are using the configuration file method, download the vpn_config.xml (per-app config) file and config.xml (proxy config) file from the Workspace ONE UEM console and transfer to the server.


  1. Create a dedicated install directory for the installer on the front-end server (for example, /tmp/Install/) and copy the BIN file to this location.
    You can use file transfer software such as FileZilla or WinSCP to perform the action.
  2. Once on the Linux server, navigate to the folder you copied the file to and then run the BIN file by using the required command.
    $ sudo ./VMwareTunnel.bin
    If you are installing for the first time, the following screen displays:

  3. Press Enter.
  4. Read and accept the licensing agreement by entering 'y'.
  5. After accepting the licensing agreement, you must choose your installation method.
    • Option 1: Provide API Server Information
      1. Enter the following information. After entering each value, the system dialog asks you to confirm the entry.
        • Workspace ONE UEM API URL
        • Organization Group Code
        • Console Server Username
        • Console Server Password
      2. Enter the hostname of the Tunnel server.

        The installer chooses the components to install based on the Workspace ONE UEM console configuration.

      3. Press Enter.
      4. Continue to Step 5.
    • Option 2:
      1. Download and copy the Tunnel Proxy and Per-app VPN configuration files to a single directory on the server.
      2. Confirm that the Proxy and Per-app VPN configuration file names are not modified from their original config.xml and vpn_config.xml names, respectively.
        1. If they have been modified, rename the files to match these names when copied into the common directory on the Linux server.
        2. If you are installing one of the Tunnel services, copy the respective configuration file.
      3. Enter the directory path that contains both configuration files.
      4. Enter the certificate password for both configuration files when prompted.
  6. Enter the hostname of the Tunnel server.
    The hostname must match the hostname that is used to configure VMware Tunnel in Workspace UEM.
    For example, if your VMware Tunnel Front end server is configured to use, enter the same address.
  7. Enter Y to grant the installer firewall permissions needed for VMware Tunnel.
    Note: Note: The ports you see may differ from the ones shown because the installer shows the values you set during VMware Tunnel configuration.
  8. Review and verify the summary information.
  9. When the installer finishes, press Enter to exit the installer.


The product begins installation. If there were any errors, the installer displays an error message with details and logs the error in the installation log file. The log file is saved in the directory that you installed the VMware Tunnel in.

What to do next

To complete your installation, see Install the VMware Tunnel Back-End Server (Linux).