# Add a new VPN payload configuration to an existing profile To create VPN policy ## Endpoints **POST** `/api/v1/mdm/profiles/{profile_id}/payloads/vpnpolicy` ## Request URL `https://{serverurl}/api/v1/mdm/profiles/{profile_id}/payloads/vpnpolicy` ## Scope `MDMOnDemand.MDMDeviceMgmt.CREATE` ## Header `Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52` ## Request Parameters ### Path Parameters - **profile_id** (string, Mandatory) Unique identifier of the profile. Obtain from the [Create Profile](https://www.manageengine.com/mobile-device-management/help/api/cloud/profiles-create-profile.html) or [Get Profiles](https://www.manageengine.com/mobile-device-management/help/api/cloud/profiles-get-profile.html) response. ### Query Parameters - **t** (long, Optional) - **ignoreHeader** (boolean, Optional) - **qlt** (long, Optional) - **previousTab** (string, Optional) - **service** (string, Optional) - **search** (string, Optional) Free-text search string applied to the default searchable fields of the resource. - **all** (boolean, Optional) - **dc_customerid** (long, Optional) - **mdm_instance** (string, Optional) - **signupsrc** (string, Optional) - **zaaid** (string, Optional) - **command** (string, Optional) - **orderby** (string, Optional) - **sortorder** (string, Optional) - **select_all** (boolean, Optional) When true, applies the operation to every record matching the current filter rather than to specific IDs. Default: false. - **zoho-internal** (boolean, Optional) - **dc_instance** (string, Optional) - **SUBREQUEST** (string, Optional) - **source** (string, Optional) - **nocache** (long, Optional) Param to avoid being served from cache. - **wms_csrparam** (string, Optional) CSRF Token. ## Request Body **Content-Type:** `application/json` ### JSON Object - **sub_config** (string, Optional) Sub Config. Default: L2TP. - **connection_name** (string, Mandatory) Connection Name. Default: VPN Configuration. - **connection_type** (integer, Mandatory) VPN connection type. Allowed values: `0=L2TP, 1=PPTP, 2=IPSec, 3=Cisco Legacy AnyConnect, 4=Juniper SSL, 5=F5 SSL, 6=Custom SSL, 7=Pulse Secure, 8=IKEv2, 9=Cisco AnyConnect, 10=SonicWall, 11=Aruba VIA, 12=CheckPoint Mobile` - **send_all_nw_traffic** (boolean, Optional) Send all network traffic. Default: false. - **certificate_uuid** (string, Optional) Certificate UUID. - **enable_vpn_on_demand** (boolean, Optional) Enable VPN on demand. Default: false. - **disconnect_on_idle_timeout** (integer, Optional) Disconnect on idle timeout in seconds. Default: 0. - **l2tp** (JSON object, Optional) - **pptp** (JSON object, Optional) - **ipsec** (JSON object, Optional) - **cisco** (JSON object, Optional) - **juniperssl** (JSON object, Optional) - **pulsesecure** (JSON object, Optional) - **f5ssl** (JSON object, Optional) - **customssl** (JSON object, Optional) - **ikev2** (JSON object, Optional) - **ciscoanyconnect** (JSON object, Optional) - **sonicwall** (JSON object, Optional) - **arubavia** (JSON object, Optional) - **checkpoint** (JSON object, Optional) - **proxy_type** (integer, Optional) Proxy configuration type. Allowed values: `0=None, 1=Manual, 2=Automatic (PAC URL)` - **proxy_server** (string, Optional) - **proxy_server_port** (integer, Optional) Default: 0. - **proxy_user_name** (string, Optional) - **proxy_password** (string, Optional) Sensitive (write-only). - **proxy_password_id** (long, Optional) - **proxy_pac_url** (string, Optional) - **ondemand_user_override_disabled** (boolean, Optional) Default: false. - **ondemandrules** (JSON array, Optional) List of VPN On Demand rules controlling when the VPN connects/disconnects. - **rule_order** (integer, Optional) Order in which the rule is evaluated. - **action** (integer, Optional) Allowed values: `0=Disconnect, 1=Connect, 2=Ignore, 3=Evaluate Connection` - **type** (integer, Optional) Allowed values: `0=Always, 1=DNS Domain Match, 2=DNS Server Address Match, 3=Interface Type Match, 4=SSID Match, 5=URL String Probe` - **value** (array, Optional) List of match values (domains, addresses, SSIDs, etc.). - **vpn_type** (integer, Mandatory) VPN scope type. Allowed values: `1=Device-level VPN, 2=Per-App VPN` - **provider_type** (integer, Optional) VPN provider type. Allowed values: `0=Packet Tunnel (default), 1=App Proxy` - **vpnuuid** (string, Optional) - **ondemand_match_app_enabled** (boolean, Optional) Default: true. - **custom_data** (JSON array, Optional) List of custom key-value pairs for vendor-specific VPN configuration. - **custom_key** (string, Optional) Custom configuration key name. - **custom_value** (string, Optional) Custom configuration key value. ## Sample Request ### Curl ```bash curl --request POST \ --url https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/vpnpolicy \ --header 'Authorization: Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52' \ --header 'content-type: application/json' \ --data '{"connection_name":"VPN Configuration","connection_type":0,"vpn_type":1}' ``` ### Java ```java import java.net.URI; import java.net.http.HttpClient; import java.net.http.HttpRequest; import java.net.http.HttpResponse; import java.io.IOException; import java.net.http.HttpTimeoutException; public class Main { public static void main(String[] args) { HttpRequest request = HttpRequest.newBuilder() .uri(URI.create("https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/vpnpolicy")) .header("content-type", "application/json") .header("Authorization", "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52") .method("POST", HttpRequest.BodyPublishers.ofString("{\"connection_name\":\"VPN Configuration\",\"connection_type\":0,\"vpn_type\":1}")) .build(); HttpResponse response = HttpClient.newHttpClient().send(request, HttpResponse.BodyHandlers.ofString()); System.out.println(response.body()); } } ``` ### Python ```python import http.client conn = http.client.HTTPSConnection("appdomain") payload = "{\"connection_name\":\"VPN Configuration\",\"connection_type\":0,\"vpn_type\":1}" headers = { 'content-type': "application/json", 'Authorization': "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52" } conn.request("POST", "/api/v1/mdm/profiles/{profile_id}/payloads/vpnpolicy", payload, headers) res = conn.getresponse() data = res.read() print(data.decode("utf-8")) ``` ### Deluge ```javascript headersMap = Map(); headersMap.put("Content-Type", "application/json"); headersMap.put("Accept", "application/json"); data=Map(); data.put("connection_name","value"); data.put("connection_type","1"); data.put("vpn_type","1"); response = invokeUrl [ url: "https://appDomain/api/v1/mdm/profiles/{profile_id}/payloads/vpnpolicy" type: POST headers: headersMap body: data connection: connection_name ] info response; ``` ### PowerShell ```powershell $headers=@{} $headers.Add("content-type", "application/json") $headers.Add("Authorization", "Zoho-oauthtoken d92d4xxxxxxxxxxxxx15f52") $response = Invoke-WebRequest -Uri 'https://appdomain/api/v1/mdm/profiles/{profile_id}/payloads/vpnpolicy' -Method POST -Headers $headers -ContentType 'application/json' -Body '{"connection_name":"VPN Configuration","connection_type":0,"vpn_type":1}' ``` ## Sample Request Body ```json { "connection_name": "VPN Configuration", "send_all_nw_traffic": false, "l2tp": {}, "connection_type": 0, "sub_config": "L2TP", "ipsec": {}, "pptp": {}, "enable_vpn_on_demand": false, "certificate_uuid": "value", "disconnect_on_idle_timeout": 0, "vpn_type": 1 } ``` ## Response Parameters ### HTTP 200 **Response Body:** `application/json` - **payload_id** (long) Unique identifier for the created payload item. - **sub_config** (string) Sub Config. Default: L2TP. - **connection_name** (string) Connection Name. Default: VPN Configuration. - **connection_type** (integer) VPN connection type. Allowed values: `0=L2TP, 1=PPTP, 2=IPSec, 3=Cisco Legacy AnyConnect, 4=Juniper SSL, 5=F5 SSL, 6=Custom SSL, 7=Pulse Secure, 8=IKEv2, 9=Cisco AnyConnect, 10=SonicWall, 11=Aruba VIA, 12=CheckPoint Mobile` - **send_all_nw_traffic** (boolean) Default: false. - **certificate_uuid** (string) - **enable_vpn_on_demand** (boolean) Default: false. - **disconnect_on_idle_timeout** (integer) 0 means disabled. Default: 0. - **l2tp** (JSON object) - **pptp** (JSON object) - **ipsec** (JSON object) - **cisco** (JSON object) - **juniperssl** (JSON object) - **pulsesecure** (JSON object) - **f5ssl** (JSON object) - **customssl** (JSON object) - **ikev2** (JSON object) - **ciscoanyconnect** (JSON object) - **sonicwall** (JSON object) - **arubavia** (JSON object) - **checkpoint** (JSON object) - **proxy_type** (integer) Allowed values: `0=None, 1=Manual, 2=Automatic (PAC URL)` - **proxy_server** (string) - **proxy_server_port** (integer) Default: 0. - **proxy_user_name** (string) - **proxy_password** (string) Sensitive (write-only). - **proxy_password_id** (long) - **proxy_pac_url** (string) - **ondemand_user_override_disabled** (boolean) Default: false. - **ondemandrules** (JSON array) - **rule_order** (integer) - **action** (integer) `0=Disconnect, 1=Connect, 2=Ignore, 3=Evaluate Connection` - **type** (integer) `0=Always, 1=DNS Domain Match, 2=DNS Server Address Match, 3=Interface Type Match, 4=SSID Match, 5=URL String Probe` - **value** (array) - **vpn_type** (integer) `1=Device-level VPN, 2=Per-App VPN` - **provider_type** (integer) `0=Packet Tunnel (default), 1=App Proxy` - **vpnuuid** (string) - **ondemand_match_app_enabled** (boolean) Default: true. - **custom_data** (JSON array) - **custom_key** (string) - **custom_value** (string) ## Sample Response: HTTP 200 ```json { "connection_name": "VPN Configuration", "send_all_nw_traffic": false, "payload_id": 9007199254741000, "l2tp": {}, "connection_type": 0, "sub_config": "L2TP", "ipsec": {}, "pptp": {}, "enable_vpn_on_demand": false, "certificate_uuid": "value", "disconnect_on_idle_timeout": 0, "vpn_type": 1 } ``` ## Possible Response Codes - **200** HTTP code