iOS VPN Per App Configuration


MobiControl's iOS Per App VPN feature enables you to specify apps which must communicate over a per-app VPN connection. You are able to set up VPN for Cisco AnyConnect, Juniper SSL, F5 SSL, SonicWALL Mobile Connection, Aruba VIA, or a Custom SSL connection. You can also specify whether the per-app VPN will automatically start when the app initiates network communications.

To access the VPN configuration dialog box, click the Add button in the Add Profile dialog box, then click Per App VPN under the Connectivity heading and select a VPN type.

 

Important:

VPN settings are only available for devices with iOS 5 or higher.

 

To associate an app with the current VPN connection enter the App Id and App Name. To remove an associated app from the current VPN connection click on the button. An app cannot be associated with more than one VPN connection.

Cisco AnyConnect

The tables below lists and give an explanation of each of the fields for configuring a Cisco AnyConnect VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection
Group NameThe group name used for authentication

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

Juniper SSL

The tables below lists and give an explanation of each of the fields for configuring a Juniper SSL VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection
Realm for authenticating the connection Enter the realm used to authenticate the connection
Role for authenticating the connection Enter the role used to authenticate the connection

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

F5 SSL

The tables below lists and give an explanation of each of the fields for configuring a F5 SSL VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

SonicWALL Mobile Connect

The tables below lists and give an explanation of each of the fields for configuring a SonicWALL Mobile Connect VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection
Group NameThe group name used for authentication

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

Aruba VIA

The tables below lists and give an explanation of each of the fields for configuring an Aruba VIA VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

Custom SSL

The tables below lists and give an explanation of each of the fields for configuring a Custom SSL VPN connection.

General

Field NameDescription
VPN NameThe name of the VPN connection
Identifier for the custom SSLEnter the custom SSL VPN (reverse DNS format)
VPN Server / IP AddressThe server or IP address of the VPN connection
DomainThe domain of the VPN connection
Username FormatThe format of the user name which is used for connecting. We can choose UPN, Domain\Username, Username, Prompt User, or static
UsernameThe username for authenticating the connection
Group NameThe group name used for authentication

Proxy

Field NameDescription
ProxyConfigures the proxy used with this configuration. We can select None, Automatic or manual
URLIf automatic is selected, then enter the address of the proxy here
Proxy ServerIf manual is selected, then enter the host name or IP address of proxy server
UsernameUsername for authenticating the connection
PasswordPassword for authenticating the connection

Authentication

Field NameDescription
Authentication Select the type of authentication used for this VPN connection. We can select Password or Certificate
Password used for AuthenticationIf Password is selected, we can enter the password used for authentication
Identity CertificateIf Certification is used, we can select the certificate used for identity here
Prompt for PasswordIf selected, the user will be prompted for their password
Enable VPN on DemandWhen enabled, VPN on demand will establish a VPN connection for specified domains and host names.
VPN On Demand ActionsWe can select Always Established, Never established, or Establish if needed

 

NetMotion

The tables below provide a description of the configuration's settings.

General

Field Name Description
VPN Name Enter a name for this VPN connection. The name cannot contain spaces or special characters.
VPN Server Hostname/IP Address Enter the hostname or IP address for your VPN server.
Domain Enter the domain that will authenticate your VPN connection
Username Enter a username.

You can use the following macros to specify usernames: %ENROLLEDUSER_UPN%, %ENROLLEDUSER_DOMAIN%, %ENROLLEDUSER_USERNAME%.

Target Domain Enter the target domain.
Port Enter the port number of your mobility server port, if changed from the default (5008).

This option is only available when the Target Domain field has been completed.

Profile Name Enter a unique name for this profile. Necessary if you plan to create several VPN profiles with the same server address.
Auto Start VPN When enabled, the VPN connects automatically, even before any of the managed applications are initiated.

Proxy

Field Name Description
Proxy Select a proxy to be used with this VPN configuration.

None: Do not use a proxy. Do not fill out any of the fields in this section.

Manual: Manually fill in the fields with the settings for your proxy.

Automatic: Enter a URL that contains information for this proxy.

URL Enter a URL with the settings for your Proxy

Only applicable when setting up an Automatic proxy connection.

Proxy Server Enter the hostname or IP address of your proxy server.

Only applicable when setting up a Manual proxy connection.

Username Enter a username that authenticates the proxy connection.

Only applicable when setting up a Manual proxy connection.

Password Enter a password that authenticates the proxy connection.

Only applicable when setting up a Manual proxy connection.

Authentication

Field Description
Authentication Select the authentication method that this VPN connection uses:

Password: a static password is used for authentication.

Certificate:

Password used to authenticate the connection Enter a secure password that will be used to authenticate the connection on the devices.

This option only applicable when Password is selected as the authentication type.

Identity Certificate Select an identity certificate from the dropdown. This certificate will be used to authenticate the VPN server.

This option only applicable when Certificate is selected as the authentication type.

Validate Server When enabled, the connection is only established once the authentication's server certificate is validated by the client.

This option only applicable when Certificate is selected as the authentication type.

Server Suffix Enter a suffix for the server. A connection will only be established if the server name ends with this value.

This option only applicable when Certificate is selected as the authentication type.

Enable VPN on Demand When enabled, the VPN automatically connects to or blocks certain domains or hostnames specified in the VPN on Demand Actions below.

VPN On Demand Actions

To add multiple VPN On Demand Actions, enter the settings for your first action and a new empty row will appear.

Field Description
Integrated Parameter Name Create a name for the integrated parameter.
Action Set an action for the integrated parameter name:

Always Establish: a VPN connection is always established for this domain or hostname.

Never Establish: a VPN connection is never established for this domain or hostname.

Establish if needed: a VPN connection is established for this domain or hostname if a VPN connection is required.

Managed Applications

Click Search application to enter an app name and search the App Store for the applications you want this VPN to apply to. If you have several apps that you would like to use the VPN, you can upload a .csv file by clicking Import file. Each row in the .csv file must contain the following information: <App ID>, <App Name>

© SOTI Inc.
Contact us