Browse docs

StrongSwan

These policies let you configure the StrongSwan app and its VPN profiles on Android Enterprise devices.

Relution offers two related policies for the StrongSwan app (org.strongswan.android): StrongSwan Restrictions controls the app’s behavior and references a default profile, while StrongSwan VPN Profile defines the actual IKEv2 VPN connection. A StrongSwan profile can additionally be set as the permanently active VPN connection via Always-On VPN →.

StrongSwan Restrictions

  • Allow users to create profiles
  • Allow users to import profiles
  • Allow users to use existing profiles
  • Allow users to import certificates
  • Allow users access to settings
  • Select a default VPN profile – reference to a profile defined via the StrongSwan VPN Profile configuration
  • Do not show a warning if the app is not on the device’s power whitelist

StrongSwan VPN Profile

Multiple VPN profiles can be created and managed in the portal.

VPN Type

  • IKEv2 EAP (username/password)
  • IKEv2 certificate
  • IKEv2 certificate + EAP
  • IKEv2 EAP-TLS (certificate)
  • IKEv2 EAP-TNC (username/password)

Server (Remote)

  • Server address and port, server identity
  • Server certificate plus options for certificate validation (OCSP/CRL, strict validation)

Client (Local)

Connection

  • IKEv2 and ESP encryption proposals
  • MTU and NAT keepalive interval
  • DNS servers, IPv6 transport
  • Proxy (host, port, exclusions)

Split Tunneling and App Assignment

  • Subnets to include or exclude
  • Block IPv4/IPv6 traffic not destined for the VPN
  • Restrict which apps may exclusively use the VPN or are explicitly excluded from it

Support

  • Managed devices (Device Owner)
  • COPE work profile (Personal Profile Enabled)
  • Work profile (Profile Owner/BYOD)
Top