# Virtual Private Network(VPN) Last updated: August 14, 2026 This page guides IT administrators through configuring VPN profiles on Android devices using MDM. It explains how VPN establishes a secure private tunnel for authorized access to organizational resources from any network. Administrators will find a comprehensive list of supported VPN types—including PPTP, L2TP PSK, IPSec, Cisco AnyConnect, F5 SSL, Pulse Secure, Palo Alto, and additional plug-in VPNs—along with device compatibility details and step-by-step profile configuration parameters for each type. A Virtual Private Network(VPN) as the name suggests establishes a logical private tunnel on the Internet, to ensure only authorized users can access confidential web resources of the organization, from any network. VPN ensures all the device-web resource communication happens on a secure channel preventing any kind of unauthorized access. VPN also boosts productivity as it ensures employees can work from anywhere, without worrying about lack of access to specific resource/data. With mobile devices extensively becoming a part of corporate productivity, it has become mandatory for IT admins to configure on VPN on mobile devices, which can be easily and efficiently done using MDM. VPN profiles applied to devices provisioned as [Personally-Owned Work Profile (BYOD, or previously Profile Owner)](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Profile_Owner) will ensure only the traffic from the apps distributed using MDM is routed through the VPN. VPN will not be applied to the apps outside the container. ## Supported VPN types The following VPN types are supported by MDM: | VPN TYPE | KNOX-ENABLED SAMSUNG | LEGACY | Personally-Owned Work Profile (BYOD, or previously Profile Owner) | Fully Managed (COSU and COBO, or previously Device Owner) | ADDITIONAL REQUIREMENT(S), IF ANY | |---|---|---|---|---|---| | PPTP | Supported from Android 4.3 | ![Not supported](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | None | | L2TP PSK | Supported from Android 4.3 | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | None | | IPSec XAuth PSK | Supported from Android 4.3 | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | None | | IPSec IKEv2 PSK | Supported from Android 4.3 | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | None | | Cisco AnyConnect | Supported from Android 6.0/Knox version 5.7 or more | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Supported](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![Success - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/success.png) | [Cisco AnyConnect](https://play.google.com/store/apps/details?id=com.cisco.anyconnect.vpn.android.avf) app must be installed on the device. [Automate installation of this app](https://www.manageengine.com/mobile-device-management/how-to/mdm-silent-installation-android-apps.html) | | F5 SSL | Supported from Android 6.0/Knox version 5.7 or more | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Success - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![Success - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/success.png) | [F5 Access](https://play.google.com/store/apps/details?id=com.f5.edge.client_ics) app must be installed on the device. [Automate installation of this app](https://www.manageengine.com/mobile-device-management/how-to/mdm-silent-installation-android-apps.html) | | Pulse Secure | Supported from Android 6.0/Knox version 5.7 or more | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Success - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![Success - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/success.png) | [Pulse Secure](https://play.google.com/store/apps/details?id=net.pulsesecure.pulsesecure) app must be installed on the device. [Automate installation of this app](https://www.manageengine.com/mobile-device-management/how-to/mdm-silent-installation-android-apps.html) | | Palo Alto | Supported from Android 6.0/Knox version 5.7 or more | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | ![Success - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![Success - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/success.png) | [Palo Alto](https://play.google.com/store/apps/details?id=com.paloaltonetworks.globalprotect) app must be installed on the device. [Automate installation of this app](https://www.manageengine.com/mobile-device-management/how-to/mdm-silent-installation-android-apps.html) | In addition to the plug in VPNs supported by default, you can also configure the following plug in VPNs | VPN TYPE | KNOX-ENABLED SAMSUNG | NON-SAMSUNG | |---|---|---| | [FortiClient IPSEC](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-forticlient-vpn.html) | ![Success - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | [Barracuda/ CudaLaunch VPN](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-barracuda-cudalaunch-vpn.html) | ![Success - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | [KerioControl VPN](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-keriocontrol-vpn.html) | ![Success - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | | [Sonicwall NETExtender](https://www.manageengine.com/mobile-device-management/how-to/mdm-configure-sonicwall-vpn.html) | ![Success - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/success.png) | ![Failured - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/failured.gif) | **Note:** If you need support for other VPNs, you can raise your request [here](https://www.manageengine.com/mobile-device-management/product-roadmap-add-details.html?id=26). ### Profile Details To configure a VPN policy, you need to configure certain common parameters and parameters specific to a VPN type. To know the parameters to be configured for a particular VPN type, click on the VPN type name from the tabs given #### Always On VPN: Enabling **Always On VPN** helps maintain a persistent connection between the managed devices and their organizational network, without the need for the users to manually connect to the VPN every time. Always On VPN can be configured only for devices provisioned as Fully Managed (COSU and COBO, or previously Device Owner). **Identity certificate** An Identity certificate can be uploaded to secure VPN. The device must be password protected for this to function. The following VPN vendors allow securing VPN using a certificate: - Cisco Any Connect - F5SSL - Pulse Secure #### To configure certificate, 1. Create a **VPN profile.** 2. Select the **Connection type.** 3. Under Authentication settings, select **'certificate based authentication'** and upload the required certificate. 4. If your organization needs support for any other VPN vendors, please add it [here](https://www.manageengine.com/mobile-device-management/product-roadmap.html) ## Frequently Asked Questions - **What VPN connection types are supported for Android devices in ManageEngine MDM?** ManageEngine MDM supports PPTP, L2TP PSK, IPSec, Cisco AnyConnect, F5 SSL, Pulse Secure, Palo Alto, and additional plug-in VPN types for Android devices across Knox-enabled Samsung and non-Samsung devices. - **Can Android VPN profiles be applied to both Samsung and non-Samsung devices?** Yes, VPN profiles in ManageEngine MDM can be configured for Knox-enabled Samsung devices and non-Samsung Android devices, though the supported VPN types and configuration parameters may differ by device type. - **Does ManageEngine MDM support Always-On VPN for Android?** Yes, ManageEngine MDM supports Always-On VPN for supported Android device types, ensuring devices maintain a persistent VPN connection to corporate resources at all times.