iOS VPN Configuration


MobiControl's iOS VPN configuration enables you to set up the VPN settings for devices. You can set up VPN for L2TP, PPTP, IPSec, Cisco AnyConnect, Juniper SSL, F5 SSL, SonicWALL Mobile Connection, Aruba VIA, or a Custom SSL connection.

To access the VPN configuration dialog box, click the Add button in the Add Profile dialog box, then click VPN under the Connectivity heading and select a VPN type.

 

Important:

VPN settings are only available for devices with iOS 5 or higher.

 

To create a new VPN connection click and select the desired connection type.

Below we will go through each of the configurations for iOS VPN Configuration. Click the titles to reveal the information:

L2TP

The tables below lists and give an explanation of each of the fields for configuring a L2TP VPN connection.

General

FieldDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection

Proxy and Authentication

Field Description
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection
AuthenticationWe can select the type of authentication used here. The options available are Password or RSA SecurID
L2TP SecretEnter the L2TP shared secret

 

PPTP

The tables below lists and give an explanation of each of the fields for configuring a PPTP VPN connection.

General

FieldDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection
Send all TrafficRoutes all network traffic through the VPN connection

Proxy and Authentication

Field Description
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection
AuthenticationWe can select the type of authentication used here. The options available are Password or RSA SecurID
Encryption LevelSet the level of encryption. We can choose Automatic, Maximum (128 bit) or none.

 

IPSec (Cisco)

The tables below lists and give an explanation of each of the fields for configuring a IPSec (Cisco) VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Shared Secret / Group Name or Certification
Group NameIf Shared Secret / Group is selected, we can enter the Group name used for authentication
Shared SecretIf Shared Secret / Group is selected, we can enter the shared secret used for the group
Prompt for PasswordIf selected, the user will be prompted for their password
Enable Hybrid Authentication Authenticate using secret, name, and a server-side certificate
Identity CertificateIf Certification is used, we can select the certificate used for identity here
User Pin RequestRequest PIN during connection and send with authentication
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

Cisco AnyConnect

The tables below lists and give an explanation of each of the fields for configuring a Cisco AnyConnect VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection
Group NameThe group name used for authentication

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

Juniper SSL

The tables below lists and give an explanation of each of the fields for configuring a Juniper SSL VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection
Realm for authenticating the connection Enter the realm used to authenticate the connection
Role for authenticating the connection Enter the role used to authenticate the connection

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

F5 SSL

The tables below lists and give an explanation of each of the fields for configuring a F5 SSL VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

SonicWALL Mobile Connect

The tables below lists and give an explanation of each of the fields for configuring a SonicWALL Mobile Connect VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection
Group NameThe group name used for authentication

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

Aruba VIA

The tables below lists and give an explanation of each of the fields for configuring a Aruba VIA VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

Custom SSL

The tables below lists and give an explanation of each of the fields for configuring a Custom SSL VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
Identifier for the custom SSLEnter the custom SSL VPN (reverse DNS format)
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection
Group NameThe group name used for authentication

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

NetMotion

The tables below provide a description of the configuration's settings.

General

Field Name Description
VPN Name Enter a name for this VPN connection. The name cannot contain spaces or special characters.
VPN Server Hostname/IP Address Enter the hostname or IP address for your VPN server.
Domain Enter the domain that authenticates your VPN connection
Username Enter a username.

You can use the following macros to specify usernames: %ENROLLEDUSER_UPN%, %ENROLLEDUSER_DOMAIN%, %ENROLLEDUSER_USERNAME%.

Target Domain Enter the target domain.
Port Enter the port number of your mobility server port, if changed from the default (5008).

This option is only available when the Target Domain field has been completed.

Profile Name Enter a unique name for this profile. Necessary if you plan to create several VPN profiles with the same server address.

Proxy

Field Name Description
Proxy Select a proxy to be used with this VPN configuration.

None: Do not use a proxy. Do not fill out any of the fields in this section.

Manual: Manually fill in the fields with the settings for your proxy.

Automatic: Enter a URL that contains information for this proxy.

URL Enter a URL with the settings for your Proxy

Only applicable on Automatic proxy setups.

Proxy Server Enter the hostname or IP address of your proxy server.

Only applicable on Manual proxy setups.

Username Enter a username that authenticates the proxy connection.

Only applicable when setting up a Manual proxy connection.

Password Enter a password that authenticates the proxy connection.

Only applicable when setting up a Manual proxy connection.

Authentication

Field Description
Authentication Select the authentication method that this VPN connection will use:

Password: a static password is used for authentication.

Certificate:

Password used to authenticate the connection Enter a secure password that will be used to authenticate the connection.

This option only applicable when Password is selected as the authentication type.

Identity Certificate Select an identity certificate from the dropdown. This certificate will be used to authenticate the VPN server.

This option only applicable when Certificate is selected as the authentication type.

Validate Server When enabled, the connection is only established once the authentication's server certificate is validated by the client.

This option only applicable when Certificate is selected as the authentication type.

Server Suffix Enter a suffix for the server. A connection will only be established if the server name ends with this value.

This option only applicable when Password is selected as the authentication type.

Enable VPN on Demand When enabled, the VPN automatically connects to or blocks certain domains or hostnames specified in the VPN on Demand Actions below.

VPN On Demand Actions

To add multiple VPN On Demand Actions, enter the settings for your first action and a new empty row appears.

Field Description
Integrated Parameter Name Create a name for the integrated parameter.
Action Set an action for the integrated parameter name:

Always Establish: a VPN connection is always established for this domain or hostname.

Never Establish: a VPN connection is never established for this domain or hostname.

Establish if needed: a VPN connection is established for this domain or hostname if a VPN connection is required.

© SOTI Inc.
Contact us