IPsec device management settings for Apple devices

You can configure an IPsec VPN connection for users of an iPhone, iPad, Mac, Apple Vision Pro, or Apple TV that enrolls in a device management service. You can choose the type of machine authentication required. The options are:

  • Shared Secret/Group Name

  • Certificate-based

Tables follow for each type of machine authentication that’s required.

IPsec Machine Authentication Shared Secret/Group Name settings

Setting

Description

Required

Connection name

The display name of the VPN connection.

Yes

Hostname

The IP address or fully qualified domain name (FQDN) of the VPN server.

Yes

Account

The user account for authenticating the VPN connection.

Yes

Group name

The group identifier for the VPN connection.

No

Shared secret

The shared secret for the VPN connection.

No

Hybrid authentication

Allows authentication using the group name, secret, and a server-side certificate.

No

Prompt for password

Users can be prompted for their password on the device.

No

Certificate settings

Setting

Description

Required

Connection name

The display name of the VPN connection.

Yes

Hostname

The IP address or fully qualified domain name (FQDN) of the VPN server.

Yes

Account

The user account for authenticating the VPN connection.

Yes

Certificate payload

The Certificates payload for the VPN connection.

Yes

User PIN

The credential for authorizing the VPN connection.

No

VPN on Demand

Specifies whether to enable VPN on Demand to access specific websites.

The action applies to all matching addresses. Addresses are compared using simple string matching, starting from the end and working backward. The address “.melardclothing.com” matches “support.melardclothing.com” and “sales.melardclothing.com,” but doesn’t match “www.private-melardclothing.com.” However, if you specify the match domain as “melardclothing.com”—notice there isn’t a period at the beginning—it matches “www.private-melardclothing.com” and all the others.

Note: After two minutes of inactivity, the device closes a VPN session initiated by VPN On Demand. If the connection is initiated manually using Settings, only the VPN server’s timeout applies.

No

Match domain or hostname

Domain and hostnames that can establish a VPN connection. When domains or hostnames are added, VPN on Demand can be configured for each entry. These options are:

  • Always: Initiates a VPN connection for any address that matches the specified domain.

  • Never: Doesn’t initiate a VPN connection for addresses that match the specified domain, but if VPN is active, it can be used.

  • Establish if necessary: Initiates a VPN connection for addresses that match the specified domain, after a failed DNS lookup occurs.

No

Note: Each device management service developer implements these settings differently. To learn how IPsec settings are applied to your devices and users, consult your developer’s device management service documentation.

Published Date: October 24, 2022
Morty Proxy This is a proxified and sanitized view of the page, visit original site.
Kasulik?
Tähemärkide piirang: 250
Maksimaalne tähemärkide piirang on 250.
Täname tagasiside eest.
Morty Proxy This is a proxified and sanitized view of the page, visit original site.