Last updated: July 24, 2026

How to remotely configure Sonicwall NETExtender VPN for Samsung devices?

This guide explains how to remotely configure SonicWall NetExtender VPN for Samsung Android devices through MDM, since managed app configuration isn't available for this vendor. Admins create an Android profile, select VPN, choose L2TP PSK as the connection type, and provide the server address, username, password, shared secret, and IPSec identifier. Optional settings include Always On VPN and VPN Lockdown (device owner devices only), DNS servers, and forwarding routes, before saving and publishing the profile.

Description

A Virtual Private Network (VPN) ensures only authorized users can access confidential corporate data, from any public network by transmitting all device-web communication on a secure channel. VPN also boosts productivity as it ensures employees can work from anywhere, without worrying about lack of access to specific resource/data. With remote work being adopted extensively, it has become mandatory for IT admins to configure VPN on mobile devices. Since managed app configuration is not available for some of the VPN vendors, MDM provides a workaround to configure them remotely using the native VPN clients.

Steps

Follow the steps given below, to configure VPN plug-ins:

  • On the MDM console, click on Device Mgmt tab and select Profiles.
  • Create an Android profile and click Continue.
  • Select VPN and fill the requisite parameters as explained below:

Policy Description

 

PARAMETERDESCRIPTION
Connection type

Select L2TP PSK as the connection type.

Connection name

Provide a name for the VPN connection to be configured

Server name/IP addressEnter the Fully Qualified Domain Name or IP address of your VPN server
User NameEnter the dynamic variable %username% to get the user name, mapped to the device
PasswordSpecify the password to be used for user authentication
Shared SecretSpecify the pre-shared secret
Secret keyEnable/disable L2TP secret key
L2TP secret keySpecify the L2TP secret key
IPSec IdentifierSpecify the name of the group of the VPN server, to which the user is assigned.
Always on VPNEnable this option to maintain a persistent connection between the managed devices and your organizational network, without the need to manually initiate VPN connection everytime. Applicable only for Device Owner devices.
VPN LockdownWhen the configured VPN is disconnected/unavailable, enabling this restricts access to other networks, including mobile data. VPN Lockdown can be configured only when Always On VPN is enabled.
DNS Server(s)Specify the Fully Qualified Domain Name or IP Address of your internal DNS server to be used, once the VPN connection is established. You can specify several DNS servers, separating them with comma.
Forwarding Route(s)Specify the forwarding route if you want to send the traffic through the VPN interface to the destination addresses. If the route is not specified, all network traffic will pass through the VPN connection.

Frequently asked questions

What connection type is used to configure Sonicwall NETExtender VPN on Samsung devices?

Select L2TP PSK as the connection type, then provide the server address, username, password, shared secret, L2TP secret key, and IPSec identifier.

What does enabling Always On VPN do for Sonicwall NETExtender connections?

Always On VPN maintains a persistent connection between managed devices and your organizational network without requiring users to manually start the VPN each time; it applies only to Device Owner devices.

Is Sonicwall NETExtender VPN configuration limited to Android devices?

Yes, this configuration is documented for Samsung Android devices managed through Mobile Device Manager Plus.