Category Filter

Last updated: August 14, 2026

Virtual Private Network(VPN)

This page guides IT administrators through configuring VPN profiles on Android devices using MDM. It explains how VPN establishes a secure private tunnel for authorized access to organizational resources from any network. Administrators will find a comprehensive list of supported VPN types—including PPTP, L2TP PSK, IPSec, Cisco AnyConnect, F5 SSL, Pulse Secure, Palo Alto, and additional plug-in VPNs—along with device compatibility details and step-by-step profile configuration parameters for each type.

A Virtual Private Network(VPN) as the name suggests establishes a logical private tunnel on the Internet, to ensure only authorized users can access confidential web resources of the organization, from any network. VPN ensures all the device-web resource communication happens on a secure channel preventing any kind of unauthorized access. VPN also boosts productivity as it ensures employees can work from anywhere, without worrying about lack of access to specific resource/data. With mobile devices extensively becoming a part of corporate productivity, it has become mandatory for IT admins to configure on VPN on mobile devices, which can be easily and efficiently done using MDM.

VPN profiles applied to devices provisioned as Personally-Owned Work Profile (BYOD, or previously Profile Owner) will ensure only the traffic from the apps distributed using MDM is routed through the VPN. VPN will not be applied to the apps outside the container.

Supported VPN types

The following VPN types are supported by MDM:

VPN TYPEKNOX-ENABLED SAMSUNGNON-SAMSUNGADDITIONAL REQUIREMENT(S), IF ANY
LEGACYPersonally-Owned Work Profile (BYOD, or previously Profile Owner)Fully Managed (COSU and COBO, or previously Device Owner)
PPTPSupported from Android 4.3Not supportedFailured - ManageEngine MDMFailured - ManageEngine MDMNone
L2TP PSKSupported from Android 4.3Failured - ManageEngine MDMFailured - ManageEngine MDMFailured - ManageEngine MDMNone
IPSec XAuth PSKSupported from Android 4.3Failured - ManageEngine MDMFailured - ManageEngine MDMFailured - ManageEngine MDMNone
IPSec IKEv2 PSKSupported from Android 4.3Failured - ManageEngine MDMFailured - ManageEngine MDMFailured - ManageEngine MDMNone
Cisco AnyConnectSupported from Android 6.0/Knox version 5.7 or moreFailured - ManageEngine MDMSupportedSuccess - ManageEngine MDMCisco AnyConnect app must be installed on the device. Automate installation of this app
F5 SSLSupported from Android 6.0/Knox version 5.7 or moreFailured - ManageEngine MDMSuccess - ManageEngine MDMSuccess - ManageEngine MDMF5 Access app must be installed on the device. Automate installation of this app
Pulse SecureSupported from Android 6.0/Knox version 5.7 or moreFailured - ManageEngine MDMSuccess - ManageEngine MDMSuccess - ManageEngine MDMPulse Secure app must be installed on the device. Automate installation of this app
Palo AltoSupported from Android 6.0/Knox version 5.7 or moreFailured - ManageEngine MDMSuccess - ManageEngine MDMSuccess - ManageEngine MDMPalo Alto app must be installed on the device. Automate installation of this app

In addition to the plug in VPNs supported by default, you can also configure the following plug in VPNs

VPN TYPEKNOX-ENABLED SAMSUNGNON-SAMSUNG
FortiClient IPSECSuccess - ManageEngine MDMFailured - ManageEngine MDM
Barracuda/ CudaLaunch VPNSuccess - ManageEngine MDMFailured - ManageEngine MDM
KerioControl VPNSuccess - ManageEngine MDMFailured - ManageEngine MDM
Sonicwall NETExtenderSuccess - ManageEngine MDMFailured - ManageEngine MDM

Note: If you need support for other VPNs, you can raise your request here.

Profile Details

To configure a VPN policy, you need to configure certain common parameters and parameters specific to a VPN type. To know the parameters to be configured for a particular VPN type, click on the VPN type name from the tabs given

PPTP
Profile SpecificationDescription
COMMON PARAMETERS
Connection NameSpecify the name, which needs to be displayed as the VPN name on the end user's mobile device
Connection TypeThe VPN type, to be provisioned on the device
Server Name / IP AddressHost name or IP address of the VPN server
PPTP-SPECIFIC PARAMETERS
User NameThe user to whom this VPN configuration is to be applied. Using the dynamic variable %username% fetches the user name from the enrollment details
PasswordSpecify the password to be used for authentication
Allow new addition of VPNsSpecify the additional VPNs can be configiured or not
Allow modification of configured VPNsSpecify whether the configured VPNs can be modified by device users or not
L2TP
Profile Specification

Description

COMMON PARAMETERS
Connection NameSpecify the name, which needs to be displayed as the VPN name on the end user's mobile device
Connection TypeThe VPN type, to be provisioned on the device
Server Name / IP AddressHost name or IP address of the VPN server
L2TP-SPECIFIC PARAMETERS
User NameThe user to whom this VPN configuration is to be applied. Using the dynamic variable %username% fetches the user name from the enrollment details
PasswordSpecify the password to be used for authentication
Shared secretSpecify the pre-shared secret
Secret KeySpecify whether L2TP secret key is to be enabled or not.
L2TP Secret KeySpecify the L2TP secret key.
Allow new addition of VPNsSpecify the additional VPNs can be configiured or not
Allow modification of configured VPNsSpecify whether the configured VPNs can be modified by device users or not
IPSec XAuth
Profile SpecificationDescription
COMMON PARAMETERS
Connection NameSpecify the name, which needs to be displayed as the VPN name on the end user's mobile device
Connection TypeThe VPN type, to be provisioned on the device
Server Name / IP AddressHost name or IP address of the VPN server
IPSec XAuth-SPECIFIC PARAMETERS
User NameThe user to whom this VPN configuration is to be applied. Using the dynamic variable %username% fetches the user name from the enrollment details
PasswordSpecify the password to be used for authentication
Shared secretSpecify the pre-shared secret
Allow new addition of VPNsSpecify the additional VPNs can be configiured or not
Allow modification of configured VPNsSpecify whether the configured VPNs can be modified by device users or not
IPSec IdentifierName of the group on the VPN server, to which the user is assigned.
IPSec IKEv2
Profile SpecificationDescription
COMMON PARAMETERS
Connection NameSpecify the name, which needs to be displayed as the VPN name on the end user's mobile device
Connection TypeThe VPN type, to be provisioned on the device
Server Name / IP AddressHost name or IP address of the VPN server
IPSec IKEv2-SPECIFIC PARAMETERS
User NameThe user to whom this VPN configuration is to be applied. Using the dynamic variable %username% fetches the user name from the enrollment details
PasswordSpecify the password to be used for authentication
Shared secretSpecify the pre-shared secret
Allow new addition of VPNsSpecify the additional VPNs can be configiured or not
Allow modification of configured VPNsSpecify whether the configured VPNs can be modified by device users or not
IPSec IdentifierName of the group on the VPN server, to which the user is assigned.
CISCO ANYCONNECT
Profile SpecificationDescription
COMMON PARAMETERS
Connection NameSpecify the name, which needs to be displayed as the VPN name on the end user's mobile device
Connection TypeThe VPN type, to be provisioned on the device
Server Name / IP AddressHost name or IP address of the VPN server
CISCO ANYCONNECT-SPECIFIC PARAMETERS
Connection ProtocolSpecify the protocol type to be used for establishing and/or maintaining the connection
Authentication TypeSpecify the proctocol to govern the authentication during connection establishment
IKE IdentitySpecify the infromation used to uniquely identify a user connection
FIPS modeSpecify whether the VPN connection/communication is governed by FIPS-compliant protocols.
Strict ModeSpecify whether Strict mode is to be enabled, for secure establishment of VPN connection
Allowed AppsList of apps which can utilize this VPN connection
Identity CertificateSpecify the identity certificate to be used for certificate-based authentication.
Always OnBy enabling this, force the configured VPN connection to always be on without the user having to start the configuration on every device restart. Always On can be configured only for devices provisioned as Fully Managed (COSU and COBO, or previously Device Owner).
VPN LockdownWhen the configured VPN is disconnected/unavailable, enable this to restrict access to other networks, including mobile data.VPN Lockdown can be configured only when Always On is enabled.
F5 SSL
Profile SpecificationDescription
COMMON PARAMETERS
Connection NameSpecify the name, which needs to be displayed as the VPN name on the end user's mobile device
Connection TypeThe VPN type, to be provisioned on the device
Server Name / IP AddressHost name or IP address of the VPN server
F5 SSL-SPECIFIC PARAMETERS
User NameThe user to whom this VPN configuration is to be applied. Using the dynamic variable %username% fetches the user name from the enrollment details
PasswordSpecify the password to be used for authentication
FIPS modeSpecify whether the VPN connection/communication is governed by FIPS-compliant protocols.
Allowed AppsList of apps permitted to utilize this VPN connection
Identity CertificateSpecify the identity certificate to be used for certificate-based authentication.
Web logon modeIf enabled, it lets the device user connect to VPN through a web browser.
Client certificate passwordPassword for the client certificate, which is used for authentication.
Bypass AppsList of apps which can bypass the VPN connection
Allow users to configure VPNEnable/Disable configuring of VPN by users
Modify configured VPNEnable/Disable modification of previously configured VPN by users
Restriction Message to be displayedSpecify the message shown to the users, on restriction
Always OnBy enabling this, force the configured VPN connection to always be on without the user having to start the configuration on every device restart. Always On can be configured only for devices provisioned as Fully Managed (COSU and COBO, or previously Device Owner).
VPN LockdownWhen the configured VPN is disconnected/unavailable, enable this to restrict access to other networks, including mobile data.VPN Lockdown can be configured only when Always On is enabled.
PULSE SECURE
Profile SpecificationDescription
COMMON PARAMETERS
Connection NameSpecify the name, which needs to be displayed as the VPN name on the end user's mobile device
Connection TypeThe VPN type, to be provisioned on the device
Server Name / IP AddressHost name or IP address of the VPN server
PULSE SECURE-SPECIFIC PARAMETERS
User NameThe user to whom this VPN configuration is to be applied. Using the dynamic variable %username% fetches the user name from the enrollment details
PasswordSpecify the password to be used for authentication
Alternate user nameSpecify the alternate user name, associated with the device user
RealmSpecify the authentication realm. An authentication realm specifies the criteria users must comply with, to use the VPN service. It is a grouping of authentication resources, including authentication server, authentication policy etc., This is usually done by the network administrators.
RoleSpecify the user role. A user role is an entity defining user session parameters(such as session settings), personalization settings(such as bookmarks) and other enabled access features. For example, a user role may define whether or not a user can perform Web browsing.
Allowed AppsList of apps permitted to utilize this VPN connection
Authentication TypeSpecify the proctocol to govern the authentication during connection establishment
Action on ProfileSpecify the whether the profile is to be created/deleted
Make this configuration defaultSpecify whether this profile is to be made default or not.
Route TypeSpecify whether the VPN is to be applied to the device or to applications.
Machine AuthenticationEnabling this automatically establishes connection on user login and the connection is maintained till the user logs off.
Identity CertificateSpecify the identity certificate to be used for certificate-based authentication.
Always OnBy enabling this, force the configured VPN connection to always be on without the user having to start the configuration on every device restart. Always On can be configured only for devices provisioned as Fully Managed (COSU and COBO, or previously Device Owner).
VPN LockdownWhen the configured VPN is disconnected/unavailable, enable this to restrict access to other networks, including mobile data.VPN Lockdown can be configured only when Always On is enabled.
PALO ALTO
Profile SpecificationDescription
COMMON PARAMETERS
Connection NameSpecify the name, which needs to be displayed as the VPN name on the end user's mobile device
Connection TypeThe VPN type, to be provisioned on the device
Server Name / IP AddressHost name or IP address of the VPN server
PALO ALTO-SPECIFIC PARAMETERS
User NameThe user to whom this VPN configuration is to be applied. Using the dynamic variable %username% fetches the user name from the enrollment details
PasswordSpecify the password to be used for authentication
Allowed AppsList of apps permitted to utilize this VPN connection
Identity CertificateSpecify the identity certificate to be used for certificate-based authentication.
Client certificate passwordPassword for the client certificate, which is used for authentication.
Route TypeSpecify whether the VPN is to be applied to the device or to applications.
Remove VPN profile, via restrictionsEnable/Disable restrictions removing the distributed VPN profile.
Always OnBy enabling this, force the configured VPN connection to always be on without the user having to start the configuration on every device restart. Always On can be configured only for devices provisioned as Fully Managed (COSU and COBO, or previously Device Owner).
VPN LockdownWhen the configured VPN is disconnected/unavailable, enable this to restrict access to other networks, including mobile data.VPN Lockdown can be configured only when Always On is enabled.

Always On VPN:

Enabling Always On VPN helps maintain a persistent connection between the managed devices and their organizational network, without the need for the users to manually connect to the VPN every time. Always On VPN can be configured only for devices provisioned as Fully Managed (COSU and COBO, or previously Device Owner).

Identity certificate
An Identity certificate can be uploaded to secure VPN. The device must be password protected for this to function. The following VPN vendors allow securing VPN using a certificate:

  • Cisco Any Connect
  • F5SSL
  • Pulse Secure

To configure certificate,

  1. Create a VPN profile.
  2. Select the Connection type.
  3. Under Authentication settings, select 'certificate based authentication' and upload the required certificate.
  4. If your organization needs support for any other VPN vendors, please add it here

 

Frequently Asked Questions

  • What VPN connection types are supported for Android devices in ManageEngine MDM? ManageEngine MDM supports PPTP, L2TP PSK, IPSec, Cisco AnyConnect, F5 SSL, Pulse Secure, Palo Alto, and additional plug-in VPN types for Android devices across Knox-enabled Samsung and non-Samsung devices.
  • Can Android VPN profiles be applied to both Samsung and non-Samsung devices? Yes, VPN profiles in ManageEngine MDM can be configured for Knox-enabled Samsung devices and non-Samsung Android devices, though the supported VPN types and configuration parameters may differ by device type.
  • Does ManageEngine MDM support Always-On VPN for Android? Yes, ManageEngine MDM supports Always-On VPN for supported Android device types, ensuring devices maintain a persistent VPN connection to corporate resources at all times.
Jump To