StrongSwan
These policies let you configure the StrongSwan app and its VPN profiles on Android Enterprise devices.
Relution offers two related policies for the StrongSwan app (org.strongswan.android): StrongSwan Restrictions controls the app’s behavior and references a default profile, while StrongSwan VPN Profile defines the actual IKEv2 VPN connection. A StrongSwan profile can additionally be set as the permanently active VPN connection via Always-On VPN →.
StrongSwan Restrictions
- Allow users to create profiles
- Allow users to import profiles
- Allow users to use existing profiles
- Allow users to import certificates
- Allow users access to settings
- Select a default VPN profile – reference to a profile defined via the StrongSwan VPN Profile configuration
- Do not show a warning if the app is not on the device’s power whitelist
StrongSwan VPN Profile
Multiple VPN profiles can be created and managed in the portal.
VPN Type
- IKEv2 EAP (username/password)
- IKEv2 certificate
- IKEv2 certificate + EAP
- IKEv2 EAP-TLS (certificate)
- IKEv2 EAP-TNC (username/password)
Server (Remote)
- Server address and port, server identity
- Server certificate plus options for certificate validation (OCSP/CRL, strict validation)
Client (Local)
- Username, client identity
- User certificate (see Certificate Management →)
- RSA/PSS signatures
Connection
- IKEv2 and ESP encryption proposals
- MTU and NAT keepalive interval
- DNS servers, IPv6 transport
- Proxy (host, port, exclusions)
Split Tunneling and App Assignment
- Subnets to include or exclude
- Block IPv4/IPv6 traffic not destined for the VPN
- Restrict which apps may exclusively use the VPN or are explicitly excluded from it
Support
- Managed devices (Device Owner)
- COPE work profile (Personal Profile Enabled)
- Work profile (Profile Owner/BYOD)