VPN

The VPN policy configuration distributes VPN profiles to managed Windows devices centrally. Besides the connection itself, the configuration covers authentication, name resolution, split tunnelling and proxy settings.


Connection

  • Profile name
  • VPN type
  • Server names
  • Connect automatically
  • Remember credentials
  • Use Windows logon credentials

Authentication

  • Authentication type
  • Machine certificate
  • Secured password (EAP)
  • Identity Certificate
  • Certificate type
  • Pre Shared Key
  • Use strong cipher keys

EAP settings

With the Protected password (EAP) authentication type, the following fields are additionally available:

  • Extensible Authentication Protocol (EAP)
  • Inner authentication
  • Inner authentication type
  • Trusted Certificates
  • Trusted Server Names
  • Enable fast reauthentication
  • Enable usage of Realms
  • Specify a realm
  • Anonymous username
  • Don’t reveal real identity to the server when pseudonym identity is available
  • Ignore mismatched network names
  • Notify user when server identity cannot be verified
  • Don’t prompt user if unable to authorise the server

Name resolution and routes

  • Name Resolution Policy table (NRPT) rules
  • Name Resolution Policy table (NRPT) rules define how the DNS resolves names when connected to the VPN. Each row in the table specifies a domain and the DNS suffixes or web proxy server to use to resolve that domain.
  • Automatically connect to the VPN when the device connects to this domain
  • Keep this rule active even when the VPN is not connected.
  • Specify DNS suffixes to add to the DNS search list to properly route short names. The first in the list is also used as the primary connection specific DNS suffix for the VPN Interface.
  • Split tunneling routes for this VPN connection
  • The IPv4/v6 CIDR address, which will be used to determine the destination prefix to send via the VPN Interface.

Proxy

  • Proxy configuration
  • Proxy type
  • Automatic
  • Manual
  • Proxy server
  • Proxy server port
  • Proxy configuration URL

App triggers

  • Apps added here will automatically connect to the VPN when started. For desktop apps, add the file path to the app. For universal (UWP) apps, add the package family name
  • Restrict VPN connection to these apps

Top