Setup VPN Configuration Profile
The VPN Configuration profile enables administrators to effectively set up enrolled devices, allowing them to establish a secure connection to a wireless network using a VPN. By configuring a VPN profile, administrators gain the ability to remotely manage the network connectivity of enrolled devices.
- Supported OS Version: macOS 10.7 or later
- Supported Enrollment Type: Device Enrollment and Automated Device Enrollment
To configure VPN remotely on the enrolled devices, follow these steps:
Navigate to SureMDM Web Console > Profiles > macOS > Add > Select Enrollment Type > Network & Connectivity > VPN Configuration > Configure.
Enter a Profile Name.
Configure VPN settings and click Save.
| Settings | Description |
|---|---|
| Connection Type | Choose the network connection method from the drop-down menu. - IPSec - L2TP - PPTP - Cisco AnyConnect - Cisco AnyConnect(New) - Juniper SSL - F5 SSL - SonicWALL Mobile Connect - Aruba VIA - Pulse Secure - Open VPN - Checkpoint Mobile VPN - Custom VPN |
| SureAccess Configuration | |
| Enable SureAccess | Check this option to enable SureAccess |
| Install SureAccess using PKG | If enabled, SureAccess will be installed using the PKG deployment method instead of VPP. Once enabled and saved, this setting cannot be reverted. |
| Connection Name | Name of the connection to be displayed on the device. |
| Auto Update | If enabled, the SureAccess Agent will automatically update to the latest available version whenever a newer version becomes available. |
| Tunnelled CIDR List | Specify the Classless Inter-Domain Routing (CIDR) ranges allowed to access the VPN. |
| Tunnelled FQDN List | List the Fully Qualified Domain Names (FQDNs) allowed to access the VPN. |
| Blocked FQDN List | Select from the pre-configured FQDNs to explicitly deny access through the secure tunnel. |
| Enable Web Filtering | Check this option to block user access to websites based on selected content categories. |
| Blocked Category List | Choose the categories of websites (e.g., Social Media, Gaming) that will be blocked when Enable Web Filtering is active. |
| Enable Authentication | Check this option to enforce user authentication during the initial SureAccess setup process on the device. Uncheck to bypass authentication. |
| Note | SureAccess now installs automatically as a PKG application as soon as the VPN Configuration payload is deployed. Separate VPP configuration or Application Policies are no longer required. SureAccess auto-updates are now controlled through the VPN Configuration payload. VPP-based Auto Update settings configured in Application Policy are not applicable. |
| Other VPN Configuration | |
| Server | Enter the hostname or IP address of the server. |
| Account | Enter the VPN account name. |
| Password | Enter the password for authentication. |
| User Authentication | Choose a method for end-user authentication: Password RSA Secure ID |
| Shared Secret | Enter the key to authorize the end-users for VPN access. |
| Send All Traffic | Select to send all traffic through the specified network. |
The above settings vary depending on the Connection Type chosen.
The newly created profile will be listed in the Profiles section.
Go back to the Home tab and select the macOS device(s) or group(s).
Click Apply to launch the Apply Job/Profile To Device prompt.
Select the profile under All Jobs/Profiles.
Click Apply in the Apply/Profile To Device prompt.