# Virtual Private Network (VPN) Last updated: August 14, 2026 This page explains how to configure Virtual Private Network (VPN) profiles on managed iOS devices using Mobile Device Manager Plus. It covers built-in VPN types such as L2TP, PPTP, IPSec, and IKEv2, as well as plug-in VPNs including Cisco AnyConnect, Pulse Secure, and OpenVPN. Administrators can learn about VPN On-Demand to automate connectivity for specific domains, certificate-based authentication for enhanced security, and a detailed profile specification table covering all configurable parameters for each supported VPN connection type. A Virtual Private Network (VPN) ensures all data is transmitted via a secured tunnel, which means it strictly requires authentication or a special certificate to establish connectivity. Every enterprise prefers to configure VPN to ensure all corporate data is secured from hackers or unauthentic users. VPN is a necessity without which users cannot reach the corporate network away from work. Since mobile devices have become a part of productivity, corporate data should be reachable for employees from anywhere. As an administrator, you need to configure VPN for all managed mobile devices. You can create and associate VPN profiles to devices. ## VPN and VPN On-Demand When a VPN profile is configured on a device, users have to turn on the VPN settings on the mobile device every time before accessing secured corporate data. Since VPN runs over Wi-Fi or cellular data, VPN connectivity turns off automatically every time the device loses connectivity with the internet. Users have to manually turn it on to reach corporate data. To overcome this, you can choose VPN On-Demand. As the name signifies, VPN connectivity is established only when specific domains require it, and the user need not turn VPN on manually. You have to specify the domain for which VPN should be turned on. You can comma-separate multiple domains to be added. The following built-in VPN connection types are supported by MDM: - L2TP - PPTP - IPSec - IKEv2 In addition to the above-mentioned built-in VPNs, Mobile Device Manager Plus also supports configuring the following plug-in VPNs. These VPNs require an additional app to be installed on the devices. - [Cisco AnyConnect Legacy](https://www.manageengine.com/mobile-device-management/help/app_management/ios_app_management.html#iOS_app_config) (Device OS is less than iOS 10.3) - [Cisco AnyConnect New](https://itunes.apple.com/us/app/apple-store/id1135064690) (Device OS is iOS 10.3 or later versions) - Juniper SSL - [F5 Access Legacy](https://itunes.apple.com/us/app/f5-big-ip-edge-client/id411062210?mt=8) - [Pulse Secure](https://itunes.apple.com/us/app/pulse-secure/id945832041?mt=8) - [SonicWALL Mobile Connect](https://itunes.apple.com/us/app/sonicwall-mobile-connect/id822514576?mt=12) - Aruba VIA - [Check Point Mobile VPN](https://itunes.apple.com/us/app/check-point-capsule-connect/id506669652?mt=8) - [F5 Access](https://itunes.apple.com/us/app/f5-access/id1354638393?mt=8&ign-mpt=uo%3D4) - [Global Protect Legacy](https://itunes.apple.com/us/app/globalprotect-legacy/id592489989?mt=8) - [Global Protect](https://itunes.apple.com/us/app/globalprotect/id1400555706?mt=8&ign-mpt=uo%3D4) - [Open VPN](https://itunes.apple.com/us/app/openvpn-connect/id590379981?mt=8&ign-mpt=uo%3D4) - [Citrix SSO](https://itunes.apple.com/us/app/citrix-sso/id1333396910?mt=8) - Wireguard VPN - Citrix VPN - Custom SSL **Note:** These apps can also be configured over the air using the [App Configurations](https://www.manageengine.com/mobile-device-management/help/app_management/ios_app_management.html#iOS_app_config) feature. Juniper SSL app is not available in the App Store. This VPN type can only be configured for devices that already have the app present. To configure Custom SSL VPN, the admin must manually enter the app details. All other plug-in apps can be added using ABM and silently distributed to devices. Click [here](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_creating_app_repository.html) to learn more about App Distribution and click [here](https://www.manageengine.com/mobile-device-management/how-to/silent-installation-ios-apps.html) to learn how to install apps silently on iOS devices. Mobile Device Manager Plus also lets you configure the following plug-in VPNs that are not supported by default. - [Barracuda/CudaLaunch VPN](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-barracuda-cudalaunch-vpn.html) - [iBoss Per-app VPN](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-iboss-vpn.html) - [KerioControl VPN](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-keriocontrol-vpn.html) - [Netmotion VPN](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-netmotion-vpn.html) - [Sophos VPN](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-sophos-vpn.html) - [WatchGuard VPN](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-watchguard-vpn.html) **Note:** If you need support for other VPNs, you can raise your request [here](https://www.manageengine.com/mobile-device-management/product-roadmap-add-details.html?id=26). ## Using Certificate for Authentication In addition to configuring VPN on managed devices, MDM also provides the option of provisioning VPN on devices using a certificate as the means of authentication. Authentication plays a major role in the establishment of a VPN connection, and a certificate is generally considered a much more secure form of authentication than a pre-shared key. Further, in the case of large VPN networks, managing a large quantity of pre-shared keys can be cumbersome. Certificates are a much more scalable alternative. Additionally, pre-shared keys are bound to an IP address, but certificates are not bound to an IP address, ensuring remote users with a dynamically assigned IP address can authenticate using identification information contained in the certificate. You can configure certificates as [explained here](https://www.manageengine.com/mobile-device-management/help/profile_management/ios/mdm_certificate.html) and distribute them on a large scale as [explained here](https://www.manageengine.com/mobile-device-management/help/profile_management/ios/mdm_scep.html). The following documents will help you configure Cisco AnyConnect on your mobile devices: - [Cisco AnyConnect User Guide](https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect40/user/guide/b_Apple_iOS_AnyConnect_User_Guide_4-0-x.html) - [Cisco AnyConnect Administrator Guide](https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect40/administration/guide/b_AnyConnect_Administrator_Guide_4-0/anyconnect-mobile-devices.html#task_hc5_3yt_z1b) ## Profile Description | Profile Specification | Description | |---|---| | VPN | | | Connection Name | Specify the name that needs to be displayed as the VPN name on the end user's mobile device. | | Connection Type | Connection type to be enabled. | | Server Name / IP Address | Host name or IP address of the server. | | Local Identifier **(Can be configured only if the Connection Type is configured as IKEv2)** | Specify the certificate identity of the user/device. | | Remote Identifier **(Can be configured only if the Connection Type is configured as IKEv2)** | Specify the certificate identity of the server. | | Account | User authentication to access the VPN. `%username%` will get the appropriate user name mapped to the device. | | Realm **(Can be configured only if Connection Type is set as Juniper SSL/Pulse VPN)** | Specify the authentication realm. An authentication realm specifies the criteria users must comply with to use the VPN service. It is a grouping of authentication resources, including authentication server and authentication policy. This is usually done by network administrators. | | Role **(Can be configured only if Connection Type is set as Juniper SSL/Pulse VPN)** | Specify the user role. A user role is an entity defining user session parameters, such as session settings, personalization settings, such as bookmarks, and other enabled access features. For example, a user role may define whether a user can perform web browsing. | | Disconnect when the connection is idle | Specify whether you want to disconnect when the VPN connection is idle. You can choose when to disconnect the VPN: **Never** or **After interval**. | | Specify the idle time | VPN connection will be automatically disconnected after the specified time of inactivity. | | User Authentication | Specify user authentication type as password or RSA SecurID. | | Machine Authentication **(Can be configured only if Connection Type is set as IPSec(Cisco))** | Specify the password to be used for machine authentication. | | Password **(Can be configured only if User authentication is set as Password)** | Specify the password to be used for user authentication. | | Identity Certificate **(Can be configured only if Machine Authentication is set as Certificate)** | Specify the identity certificate to be used for certificate-based authentication. You can also use [SCEP](https://www.manageengine.com/mobile-device-management/help/profile_management/ios/mdm_scep.html) for this. | | Include User PIN **(Can be configured only if Machine Authentication is set as Certificate)** | Specify whether the User PIN must be included. | | Group Name **(Can be configured only if User authentication is set as Password)** | Specify the group name to be used for identifying the group. The group must end with **[hybrid]** if Hybrid Authentication is enabled. | | Shared secret | Specify the pre-shared secret. | | Use Hybrid Authentication **(Can be configured only if Machine Authentication is set as Shared Secret)** | Enable Hybrid Authentication, a secure alternative to the regular authentication used. | | Prompt for password **(Can be configured only if Machine Authentication is set as Shared Secret)** | Enable or disable prompting for a password from the user. | | Encryption level **(Can be configured only if Connection Type is set as PPTP)** | Specify the password to be used for user authentication. | | Send All traffic | Routes all network traffic through the VPN connection. | | Custom Data **(Can be configured only for Connection Type that support additional configurations)** | Specify the custom data to include additional configurations to the VPN connection. | | Plug-in identifier **(Can be configured only if Connection Type is set as Custom SSL)** | It is the VPN extension identifier provided by third-party vendors used to identify the apps and apply VPN on the device. | | Provider Bundle identifier **(Can be configured only if Connection Type is set as Custom SSL)** | It is the bundle identifier of apps. Whenever the same VPN extension is used by many apps, the bundle identifier of the app needs to be specified to use VPN. | | App name **(Can be configured only if Connection Type is set as Custom SSL)** | Specify the app name. | | Advanced Settings **(Can be configured only if Connection Type is set as IKEv2)** | | | Dead Peer Detection (DPD) Rate | DPD is used for identifying whether the connection between the managed device and the VPN has been established. If DPD is set as high, the time interval for verifying the connection establishment is miniscule. If set as medium or low, the time interval increases. | | Enable Perfect Forward Secrecy (PFS) | Perfect Forward Secrecy (PFS) is a property that ensures security of past communication if secret keys or passwords get compromised in the future. For example, even if someone gets access to the secret key or password now, it cannot be used for accessing previous communication. | | Enable Certificate Revocation Check | This can be used to verify that the CA has revoked the certificate provisioned for the particular device. | | Disable MOBIKE | MOBIKE ensures the connection with the VPN gateway is active while moving from one address to another. Additionally, if the host is connected to multiple networks, MOBIKE can be used to move traffic to a different interface if the one currently being used stops working. | | Use internal IPv4 subnet | Allow or restrict usage of internal IPv4 subnet attributes distributed. | | Disable Redirect | Allow or restrict redirection of connection from one VPN gateway to another. | | IKE SA Parameters **(Can be configured only if Connection Type is set as IKEv2)** | | | The Internet Key Exchange Security Association (IKE SA) is used for establishing communication between the VPN and the devices for the first time, either using certificate, pre-shared key, or user name. | | | Encryption Algorithm | The encryption technique to be used for sharing data to establish a connection. Common encryption techniques such as DES, AES, and POLY are supported. | | Integrity Algorithm | The integrity technique to be used for sharing data to establish a connection. Common integrity techniques such as SHA and MD5 are supported. | | Diffie-Hellman Group | Specify the group of Diffie-Hellman algorithm to be used for key exchange. | | Lifetime (in minutes) | Specify the maximum possible duration for the connection to be established. | | Child SA Parameters **(Can be configured only if Connection Type is set as IKEv2)** | | | The Child Security Association (IKE SA) is used to secure the communication occurring between the endpoints after the VPN connection has been established during IKE SA. | | | Encryption Algorithm | The encryption technique to be used for encrypting the data being shared. Common encryption techniques such as DES, AES, and POLY are supported. | | Integrity Algorithm | The type of integrity algorithm to be used on the data being shared. Common integrity techniques such as SHA and MD5 are supported. | | Diffie-Hellman Group | Specify the group of Diffie-Hellman algorithm to be used for key exchange. | | Lifetime (in minutes) | Specify the maximum possible duration for the connection to be active. | | VPN On-Demand | | | The device will automatically connect to the configured VPN only if the specified URL is not accessible without VPN. | | | Enable VPN On Demand | Enabling this switches on VPN when VPN connectivity is required to reach the specific server or domain and the device is not in the corporate network. | | Specify the Domains | Specify the list of domains for which VPN should be enabled on demand. You can enter multiple domain names using comma separation. | | Configure Proxy | | | Proxy settings | Configure proxy settings for VPN. | | Server URL **(Can be configured only if Proxy is set as Automatic)** | Specify the URL containing the Proxy PAC. | | Server **(Can be configured only if Proxy is set as Manual)** | Proxy server name. | | Port **(Can be configured only if Proxy is set as Manual)** | Port number to be used. | | User Name **(Can be configured only if Proxy is set as Manual)** | User name for authentication. | | Password **(Can be configured only if Proxy is set as Manual)** | Specify the password to be used. | ### Dynamic Variables The following dynamic variables are retrieved from the data provided while enrolling the device: - `%username%` - Gets the appropriate user name mapped to the device. ## Frequently Asked Questions **1. Which built-in VPN connection types does MDM support on iOS?** MDM supports the built-in connection types L2TP, PPTP, IPSec, and IKEv2, in addition to several plug-in VPN apps such as Cisco AnyConnect, Pulse Secure, and SonicWALL Mobile Connect. **2. What is VPN On-Demand and when should it be used?** VPN On-Demand automatically establishes a VPN connection only when a user tries to reach a domain you've specified, so users do not have to manually turn on VPN every time connectivity drops. **3. Can VPN be configured using a certificate instead of a pre-shared key?** Yes. MDM lets you provision VPN using certificate-based authentication, which is generally more secure and scalable than managing pre-shared keys, especially for large VPN networks. **4. Are third-party VPN apps like Cisco AnyConnect distributed automatically to devices?** Most plug-in VPN apps can be added using ABM and silently distributed to devices, except Juniper SSL, which must already be present on the device since it is not available on the App Store.