# Add a new VPN payload configuration to an existing profile Create Android VPN Policy Payload ## Endpoint `POST /api/v1/mdm/profiles/{profile_id}/payloads/androidvpnpolicy` ## Request ### Request URL `https://`[{serverurl}](https://www.manageengine.com/mobile-device-management/help/api/cloud/oauth-authentication-endpoint-domain.html)`/api/v1/mdm/profiles/{profile_id}/payloads/androidvpnpolicy` ### Scope `MDMOnDemand.MDMDeviceMgmt.CREATE` ### Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ### Request Parameters #### Request Headers | Parameter | Type | Required | Value | |---|---|---|---| | Content-Type | string | Mandatory | `application/json` | | Accept | string | Mandatory | `application/json` | #### Path Parameters | Parameter | Type | Required | Description | |---|---|---|---| | profile_id | string | Mandatory | Unique identifier of the profile. Obtain from the [Create Profile](https://www.manageengine.com/mobile-device-management/help/api/cloud/profiles-create-profile.html) or [Get Profiles](https://www.manageengine.com/mobile-device-management/help/api/cloud/profiles-get-profile.html) response | #### Request Body `application/json` | Parameter | Type | Required | Description | |---|---|---|---| | connection_name | string | Mandatory | VPN connection display name (required) | | connection_type | integer | Mandatory | VPN connection protocol type. 1 = L2TP/IPSec PSK, 2 = L2TP/IPSec RSA, 3 = IPSec Xauth PSK, 4 = IPSec Xauth RSA, 5 = IPSec IKEv2 PSK, 6 = IPSec IKEv2 RSA, 7 = IPSec Hybrid RSA, 8 = PPTP, 19 = Cisco AnyConnect, 20 = Pulse Secure, 21 = F5 SSL, 22 = Palo Alto (required) | | vpn_app_id | JSON object | Optional | App identifier for the VPN client application | | vpn_lockdown_excluded_apps | JSON array | Optional | List of apps excluded from VPN lockdown | | always_on | boolean | Optional | Whether VPN is always on. Default: false | | lockdown_enabled | boolean | Optional | Whether VPN lockdown is enabled (blocks traffic without VPN). Default: false | | l2tp_psk | JSON object | Optional | L2TP/IPSec PSK connection configuration | | l2tp_rsa | JSON object | Optional | L2TP/IPSec RSA connection configuration | | pptp | JSON object | Optional | PPTP connection configuration | | ipsec_xauth_psk | JSON object | Optional | IPSec Xauth PSK connection configuration | | ipsec_xauth_rsa | JSON object | Optional | IPSec Xauth RSA connection configuration | | ipsec_ikev2_psk | JSON object | Optional | IPSec IKEv2 PSK connection configuration | | ipsec_ikev2_rsa | JSON object | Optional | IPSec IKEv2 RSA connection configuration | | ipsec_hybrid_rda | JSON object | Optional | IPSec Hybrid RSA connection configuration | | pulsesecure | JSON object | Optional | Pulse Secure VPN connection configuration | | f5ssl | JSON object | Optional | F5 SSL VPN connection configuration | | ciscoanyconnect | JSON object | Optional | Cisco AnyConnect VPN connection configuration | | paloalto | JSON object | Optional | Palo Alto Networks GlobalProtect VPN connection configuration | ## Sample Request ```curl curl --request POST \ --url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/androidvpnpolicy \ --header 'Accept: application/json' \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' \ --header 'Content-Type: application/json' \ --data '{"connection_name":"VPN Configuration","connection_type":19}' ``` ### Sample Request Body Add VPN payload to the profile ```json { "connection_name": "VPN Configuration", "lockdown_enabled": false, "connection_type": 19, "vpn_app_id": {}, "l2tp_psk": {}, "vpn_lockdown_excluded_apps": [], "ipsec_xauth_psk": {}, "always_on": false, "pptp": {}, "l2tp_rsa": {} } ``` ## Response Parameters ### HTTP Code 200 #### Response Body `application/json` | Parameter | Type | Description | |---|---|---| | payload_id | long | Unique identifier for the created payload item | | connection_name | string | VPN connection display name (required) | | connection_type | integer | VPN connection protocol type. 1 = L2TP/IPSec PSK, 2 = L2TP/IPSec RSA, 3 = IPSec Xauth PSK, 4 = IPSec Xauth RSA, 5 = IPSec IKEv2 PSK, 6 = IPSec IKEv2 RSA, 7 = IPSec Hybrid RSA, 8 = PPTP, 19 = Cisco AnyConnect, 20 = Pulse Secure, 21 = F5 SSL, 22 = Palo Alto (required) | | vpn_app_id | JSON object | App identifier for the VPN client application | | vpn_lockdown_excluded_apps | JSON array | List of apps excluded from VPN lockdown | | always_on | boolean | Whether VPN is always on. Default: false | | lockdown_enabled | boolean | Whether VPN lockdown is enabled (blocks traffic without VPN). Default: false | | l2tp_psk | JSON object | L2TP/IPSec PSK connection configuration | | l2tp_rsa | JSON object | L2TP/IPSec RSA connection configuration | | pptp | JSON object | PPTP connection configuration | | ipsec_xauth_psk | JSON object | IPSec Xauth PSK connection configuration | | ipsec_xauth_rsa | JSON object | IPSec Xauth RSA connection configuration | | ipsec_ikev2_psk | JSON object | IPSec IKEv2 PSK connection configuration | | ipsec_ikev2_rsa | JSON object | IPSec IKEv2 RSA connection configuration | | ipsec_hybrid_rda | JSON object | IPSec Hybrid RSA connection configuration | | pulsesecure | JSON object | Pulse Secure VPN connection configuration | | f5ssl | JSON object | F5 SSL VPN connection configuration | | ciscoanyconnect | JSON object | Cisco AnyConnect VPN connection configuration | | paloalto | JSON object | Palo Alto Networks GlobalProtect VPN connection configuration | ### Possible Response Codes | HTTP Code | |---| | 200 | ### Sample Response: HTTP 200 VPN payload successfully added ```json { "connection_name": "VPN Configuration", "payload_id": 9007199254741000, "lockdown_enabled": false, "connection_type": 19, "vpn_app_id": {}, "l2tp_psk": {}, "vpn_lockdown_excluded_apps": [], "ipsec_xauth_psk": {}, "always_on": false, "pptp": {}, "l2tp_rsa": {} } ``` ## API Rate Limit ![](https://www.zohowebstatic.com/sites/zweb/images/people/ico-help.png) **Duration:** 1 minute | **Threshold:** 30 | **Lock period:** 5 minutes Duration - Time window for the threshold. Threshold - Number of API calls allowed within the specified duration. Lock Period - Wait time before consecutive API requests.