Last updated: July 24, 2026

How to remotely configure WatchGuard VPN for iOS/iPadOS devices?

This guide explains how to remotely configure WatchGuard VPN for iOS/iPadOS devices through MDM. Admins create an iOS/iPadOS profile, select VPN, choose OpenVPN as the connection type, and upload the .ovpn file provided by WatchGuard along with the account and authentication method (password or certificate). Optional settings include enabling On-Demand VPN for specified domains and configuring proxy settings, before saving and publishing the profile to target devices.

Description

A Virtual Private Network (VPN) ensures only authorized users can access confidential corporate data, from any public network by transmitting all device-web communication on a secure channel. VPN also boosts productivity as it ensures employees can work from anywhere, without worrying about lack of access to specific resource/data. With remote work being adopted extensively, it has become mandatory for IT admins to configure VPN on mobile devices. Configuring VPN can be easily and efficiently done using MDM.

Steps

Follow the steps given below, to configure VPN plug-ins:

  • On the MDM console, click on Device Mgmt tab and select Profiles.
  • Choose iOS/iPadOS and click Continue.
  • Select the VPN tab and fill the requisite parameters as explained below:

Policy Description

PARAMETERDESCRIPTION
Connection type

Select OpenVPN as the connection type.

Connection name

Provide a name for the VPN connection to be configured

AccountSpecify the account that needs access to this VPN. Type %username% to get the appropriate user name, mapped to the device
Custom DataUpload the .opvn file downloaded from your VPN vendor
User authenticationSpecify the authentication type as Password or Certificate or Both
PasswordSpecify the password to be used for user authentication
Identity Certificate (If Certificate is selected for authentication)Specify the identity certificate to be used for certificate-based authentication. You can also use SCEP for this.
Enable On-Demand VPNEnabling On-Demand VPN ensures that a device not present in the corporate network, will be automatically connected to VPN whenever the specified list of server/domains are accessed. If you specify multiple domain names, they should be comma separated.
Proxy Configure the proxy settings to be used for this VPN connection

For more information, refer here

Frequently asked questions

What connection type does WatchGuard VPN use on iOS/iPadOS profiles?

Select OpenVPN as the connection type, then specify the account and upload the .opvn file downloaded from WatchGuard as the Custom Data.

What authentication methods are supported for WatchGuard VPN?

You can use Password or Certificate authentication, or both; certificate-based authentication can rely on an identity certificate or SCEP.

Is WatchGuard VPN configuration in MDM limited to iOS and iPadOS?

Yes, this configuration is documented for iOS and iPadOS devices managed through Mobile Device Manager Plus.