Overview
Use a VPN connection from your computer to Cisco GMM to remotely manage and interact with both the gateways and connected devices.
You can also use the EEM menu for IOS commands, troubleshooting and status information.

Note: Remote access to connected devices only works if the custom subnet is disabled. Go to Gateway > Templates and edit an existing entry. Then select Disabled. If the custom subnet is Enabled, a custom configuration is required.
Remote gateway connection using VPN
Use the AnyConnect client to remotely manage and interact with GMM gateways and devices behind a Cisco GMM gateway.
For example, an elevator technician can use this capability to establish IP connectivity between his PC and an elevator in another city. He can then use a diagnostics application on his PC to troubleshoot an issue, determine a solution, and dispatch a repair technician with the right parts for that issue.
Tip: To see the IP address of the attached devices use Discover Devices. Devices with a static IP address cannot be discovered using the Discover Devices feature.
Prerequisites
Procedure
Create a VPN Connection between your computer and the gateway. Then, use the applications on your computer to communicate with the gateway and connected devices (assets).
Add devices to the gateway.
Request the VPN credentials to access the gateway and the connected device(s).
- Log in to the Cisco GMM Cloud Application.
- Select Gateway > Gateways and select the Monitor tab.
- Select a gateway checkbox.
- Click VPN.
- Select the duration that the credentials will be valid, and click Request.
.
Note: VPN credentials are displayed that are valid only for the current user, the current gateway, and the specified duration. The time remaining is also displayed. The VPN connection will disconnect when the access time expires.

Create a VPN connection between your computer and GMM:
Open the Cisco AnyConnect client on your computer.
Tip: If necessary, click Download to install the AnyConnect VPN client software on your computer.

In the AnyConnect client, enter the "Remote Access Server" address that appears under AnyConnect VPN Profile, and click Connect. This is GMM's VPN address.
Click Connect.
Enter the username and password from the AnyConnectVPNProfile, when prompted, and click OK.
- These are the credentials used to establish a VPN connection, and are valid on the selected gateway for the time requested.
- Click the
icon and enter your GMM credentials to display the VPN password.
Wait for the VPN connection to be established.
Use the applications on your computer to connect and interact with the gateway and connected devices (assets).
- You can connect to:
- The IP addresses are displayed in the Remote VPN Access window under Remote Access Details and Connected Devices.
Audit log entries will be created when either the remote access request is created or has expired.
- Go to Tools > Audit Logs.
- Select:
- Entity Type: Gateway.
- Audit Type: Remote access granted or Remote access revoked.
- Source: All
- Gateways: Select the gateways to include in the audit log.
- Click Run.

Gateway diagnostics menu (EMM)
Use an SSH connection between the gateway and a computer to run predefined IOS commands for troubleshooting and device status. You can use SSH over a VPN connection, from any IP reachable network, or using a physical console cable.
Notes
Procedure
Connect to the gateway using either a USB cable or a SSH connection.
- Option 1: Connect a USB cable from your computer to the gateway console port.
- Option 2: Create a VPN connection between your computer and the gateway as described in Remote management.
- Launch an SSH client on your computer.
- In the SSH client, enter the gateway IP address.
Enter the default username: operator.
Enter the password:
If the gateway is not claimed in the GMM admin console, Enter operator.
If the gateway is claimed, go to Gateway > Gateways, select the gateway and click the Summary tab. Enter the password displayed for the Diagnostics Console.

From the Diagnostics Menu (see below), enter a number for one of the predefined Cisco IOS commands and press Enter.
Follow the onscreen prompts for additional options, if necessary.
For example: