Skip to main content

Configure VPN Policy Profile (Android Enterprise)

The VPN Policy allows administrators to centrally configure secure access to corporate networks using the SureAccess VPN solution. This policy defines connection parameters, network routing rules, web filtering, and application access controls to ensure secure communication between the managed device and the enterprise network.

To remotely configure the VPN Configuration profile on the enrolled device(s), follow these steps:

  1. Navigate to SureMDM Web Console > Profiles > Android > Add > Primary Profile > VPN > Configure.

  2. Enter a Profile Name.

  3. In the VPN Configuration screen, enter the following details and click Save.

SettingDescription
Enable SureAccessCheck this option to activate the SureAccess VPN configuration on the device.
Connection NameEnter a unique name for the VPN connection that will be displayed on the device.
Always OnCheck this option to keep the VPN connection persistent at all times. This ensures that all device traffic routes through the VPN automatically, providing continuous security.
Tunnelled CIDR ListSelect from the pre-configured CIDR ranges (e.g., 192.168.1.0/24) that are permitted to be accessed via the secure VPN tunnel.
Tunnelled FQDN ListSelect from the pre-configured Fully Qualified Domain Names (FQDNs) (e.g., erp.company.com) that should be routed through the secure VPN tunnel.
Blocked FQDN ListSelect from the pre-configured FQDNs to explicitly deny access through the secure tunnel.
Enable Web FilteringCheck this option to block user access to websites based on selected content categories.
Blocked Category ListChoose the categories of websites (e.g., Social Media, Gaming) that will be blocked when Enable Web Filtering is active.
App Access ModeSelect either Allow Specific Apps or Block Specific Apps to control which applications can use the VPN tunnel.
Allowed Applications List(App Access Mode: Allow Specific Apps) Select the applications allowed to operate within the SureAccess VPN. Applications other than the specified ones will be blocked.
Blocked Applications List(App Access Mode: Block Specific Apps) Select the applications blocked from operating within the SureAccess VPN. Applications other than the specified ones will be allowed.
Enable AuthenticationCheck this option to enforce user authentication during the initial SureAccess setup process on the device. Uncheck to bypass authentication.

The newly created profile will be listed in the Profiles section.

  1. Go back to the Home tab and select the device(s).

  2. Click Apply to launch the Apply Job/Profile To Device prompt.

  3. In the Apply Job/Profile To Device prompt, select the created profile and click Apply.