Create Always On VPN Profile

Procedure

1

In the Workspace ONE UEM console, navigate to Resources > Profiles & Baselines > Profiles.

2

Click Add and choose Add Profile from the drop-down list.

3

Select Android as the platform.

4

Choose CUSTOM DPC or ANDROID MANAGEMENT API as the Management Type and click Next.

5

Enter a name for your profile. For example, Always On VPN.

6

Navigate to the VPN section and click Add.

7

In the VPN setting configuration section, complete the fields, including the following:

  • From the Connection Type drop-down list, choose Cisco AnyConnect.
  • In the Server field, enter cisco://local.
  • In the Connection Name, enter the name.
  • Enable the Always on VPN button.
  • Enable the Set Active button.
  • Enable the Per-App VPN Rules button.
8

Click Next.

9

Search or navigate to the Credentials section, and click Add.

10

In the Credential section, do the following:

  • From the Credential Source drop-down list, choose Upload.
  • Click Choose File to browse and select the Cisco_Umbrella_Root_CA Certificate downloaded from Umbrella.

 

In Umbrella, navigate to Deployments > Configuration > Root Certificate, expand Cisco Root Certificate Authority, and download the Cisco Umbrella root certificate, see Push the Umbrella Certificate to Managed Devices

  • Click ATTACH CERTIFICATE.
11

After successful upload of the certificate, the Credential Name would be added automatically and then click Next.

12

In the Assignment and Deployment profile settings screen, complete the fields, including the following:

  • In the Smart Group field, choose the group of devices to which the Always On VPN profile is to be assigned.
  • Select the appropriate deployment values. Choose Auto from the Assignment Type drop-down list, to deploy the profile to all device automatically.
13

Click Save & Publish.