# How to configure VPN Settings on Android Devices

A Virtual Private Network (VPN) lets the users access the organization network remotely. It enhances security by allowing the users to send data through a private network. A private network is created virtually across the public network, and the interaction is done via this virtual network. To start a connection with a VPN server, devices use a VPN connection profile. Hexnode UEM allows you to configure VPN profiles for Android devices. Once configured, the VPN connection will be listed among the available networks.

Configure VPN Settings
----------------------

1. Login to your Hexnode UEM Portal.
2. Go to **Policies**.
3. Select an existing policy or create a new one by clicking on **New Policy**.
4. From **Android > Networks**, select **VPN** and click on **Configure**.

You will have the following options to be configured.

[![Configure VPN for Android devices using mdm](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/11/Configure-VPN-for-Android-devices.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/11/Configure-VPN-for-Android-devices.png) Note: 
PPTP, L2TP/IPSec PSK, IPSec Xauth PSK, IPSec IKEv2 PSK, L2TP/IPSec RSA, IPSec Xauth RSA, IPSec Hybrid RSA, and IPSec IKEv2 RSA connection types are supported only on Knox devices.

 

Connection types supported on Knox devices
------------------------------------------

SettingsDescriptionProfile Name Provide a name to identify VPN on the device. Among the list of available connections, this will be the displayed name for the VPN.Server Provide the domain name of the server or the IP address of the server to which the devices get connected.Connection Type Select the connection type to be used. The remaining settings changes in accordance with the selected connection type.Username Provide the username for authenticating the VPN Server. This field supports the use of wildcards. The supported wildcard is %name%.Password Provide the password of the account used for authenticating the VPN Server.
 Note: 
Username and password is required to sign into the VPN server. The credentials provided here authenticates the user’s device to get connected with the VPN.

 

 The following options will be enabled when **Show advanced** options is clicked.

SettingsDescriptionDNS search domainsProvide the internal DNS domain to be used, once the connection is established.DNS serversProvide the internal DNS server to be used, once the connection is established.Forwarding routesProvide the forwarding route to send the traffic through the VPN interface to the destination. Forwarding routing is required to tell the devices to send traffic to the destination through the VPN interface.Based on the **Connection Type** selected, you will have the following options to be configured.

### Configuring PPTP Connection Type

PPTP Connection

 PPTP SettingsDescriptionPPP encryption (MPPE)Check this option to enable PPP (Point-to-Point Protocol) encryption on the android devices.

 

 

### Configuring L2TP/IPSec PSK Connection Type

L2TP/IPSec PSK Connection

 L2TP/IPSec PSK SettingsDescriptionL2TP secretA second password required to establish a connection. Also known as pre-shared key, the shared secret is previously known to the device and the VPN server, and no one else. This key is used just to establish a connection and not used for encryption.IPSec pre-shared keyProvide the pre-shared key for IPSec connection type. This key is used only for authentication and not for encryption.IPSec IdentifierProvide the IPSec Identifier to establish the VPN authentication.

 

 

### Configuring IPSec Xauth PSK Connection Type

IPSec Xauth PSK Connection

 IPSec Xauth PSK SettingsDescriptionIPSec pre-shared keyInput the pre-shared key required for IPSec connection type. It is used only for authenticating the connection and not for encryption.IPSec IdentifierProvide the IPSec Identifier to establish the VPN authentication.

 

 

### Configuring IPSec IKEv2 PSK Connection Type

IPSec IKEv2 PSK Connection

 IPSec IKEv2 PSK SettingsDescriptionIPSec pre-shared keyIPSec connection type requires the pre-shared key to authenticate the connection. Note that this key is not used for encryption.IPSec IdentifierProvide the IPSec Identifier to establish the VPN authentication.

 

 

### Configuring L2TP/IPSec RSA Connection Type

L2TP/IPSec RSA Connection

 L2TP/IPSec RSA SettingsDescriptionL2TP secretL2TP secret, also known as the pre-shared key, is the alternate password for establishing the connection. It is a shared secret previously known only to the VPN server and the device. This pre-shared key can be used only for establishing the connection and not for encryption.Ca CertificateSelect the Certificate Authority (Ca) trusted certificate for establishing L2TP/IPSec RSA connection. The assigned trusted certificate authenticates the device to establish a connection to the VPN server. It must be previously uploaded under  **Android > Security > Certificates**.User CertificateSelect the user certificate required for establishing L2TP/IPSec RSA connection. Users can assure their identity for remote VPN access by using user certificates. This certificate must be previously uploaded under **Android > Security > Certificates**.

 

 

### Configuring IPSec Xauth RSA Connection Type

IPSec Xauth RSA Connection

 IPSec Xauth RSA SettingsDescriptionCa CertificateChoose the Certificate Authority (Ca) trusted certificate uploaded under **Android > Security > Certificate** for authenticating the connection. It is this certificate that establishes the connection between the device and the VPN server. User CertificateSelect the user certificate required for establishing IPSec Xauth RSA connection. Users can assure their identity for remote VPN access by using user certificates. This certificate must be previously uploaded under **Android > Security > Certificates**.

 

 

### Configuring IPSec Hybrid RSA Connection Type

IPSec Hybrid RSA Connection

 IPSec Hybrid RSA SettingsSettingsCa CertificateFor establishing IPSec Hybrid RSA connection, select the Certificate Authority (Ca) trusted certificate uploaded under **Android > Security > Certificate**. This certificate authenticates the device to establish a connection with the VPN server.

 

 

### Configuring IPSec IKEv2 RSA Connection Type

IPSec IKEv2 RSA Connection

 IPSec IKEv2 RSA SettingsDescriptionUser CertificateSelect the user certificate required for establishing IPSec IKEv2 RSA connection. Users can assure their identity for remote VPN access by using user certificates. This certificate must be previously uploaded under **Android > Security > Certificates**.

 

 

Always-on VPN for Android
-------------------------

 Note: 
Supported on Android Enterprise devices running Android 7.0+.

 

You can configure the selected VPN network to be always active on the device by checking **Always-on** option. Selecting this option makes the device get connected to the VPN network always. This option is available for **L2TP/IPSec PSK, IPSec Xauth PSK, IPSec IKEv2 PSK, L2TP/IPSec RSA, IPSec Xauth RSA, IPSec Hybrid RSA, IPSec IKEv2 RSA, SonicWall, Check Point, F5 Access, Palo Alto,** and **Cisco AnyConnect.**

[![Always-on VPN option for Android. ](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/11/Always-on-VPN-for-Android.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/11/Always-on-VPN-for-Android.png)

Configuring Always-on Connection Type 
--------------------------------------

The **Always-on** connection type in Hexnode allows administrators to configure and enforce VPN connections on devices through third-party applications that support VPN configuration. These applications include Enterprise Apps—privately distributed within an organization—and Managed Google Play Apps—publicly available apps that can be managed through Hexnode.

You can also configure an app to use an Always-on VPN for its network connection by deploying the necessary configurations.

To configure the Always-on connection type:

1. Enter the VPN profile name.
2. Select the connection type as **Always-on**.
3. Click on the **Select App** option to choose the app to configure the VPN.
4. Select **Enterprise App** or **Managed Google Play App** depending on the type of app you want to configure VPN.
5. Click on the **Select** button to choose the app to configure.
6. The app configuration screen is displayed. Configure the available options and click **Done**. 
    - For **Enterprise apps**, click on the **Advanced settings** option. Upload the **JSON** file with the required configurations and click **Done**.
    - For **Managed Google Play App** configure the available options and click **Done**.
7. Enable the **VPN Lockdown** option to enforce the configured VPN connection, restricting access to other networks, including mobile data, whenever the VPN is disconnected or unavailable.
8. (Optional) You can enable the **Bypass Lockdown** option to allow selected apps direct access to the device’s cellular data or Wi-Fi network when the VPN is in lockdown mode but not connected. This option is available only when the **VPN Lockdown** option is enabled.
9. Click on the **Allowed Apps** option to allow specific apps to access the device’s cellular data/Wi-Fi network, even when the device is locked to the configured VPN. This option is available only when the **Bypass Lockdown** option is enabled.

 Notes:- Ensure that the selected app to configure VPN is installed on the device for the policy to take effect.
- **VPN Lockdown** and **Bypass Lockdown** options are supported on Android 10.0+ devices enrolled as Android Enterprise Device Owner and Profile Owner.
- System apps and Hexnode apps will be exempted from the lockdown even if the **VPN Lockdown** option is enabled.

 

### Configuring third-party VPN app Connection Types 

Third-party VPN app Connection

You can configure third-party VPN apps like **SonicWall, Check Point, F5 Access, Palo Alto,** and **Cisco AnyConnect** as connection types from the Hexnode console.

SettingsDescriptionProfile Name Provide a name to identify VPN on the device. Among the list of available connections, this will be the displayed name for the VPN.Server Provide the domain name of the server or the IP address of the server to which the devices get connected. Connection Type Select the connection type to be used. The available third-party VPN app connection types are **SonicWall, Check Point, F5 Access, Palo Alto,** and **Cisco AnyConnect.** Note: 
Install the following apps on the device before applying the policy:

- SonicWall – SonicWall Mobile Connect
- Check Point – Check Point Capsule VPN
- F5 Access – F5 Access
- Palo Alto – GlobalProtect
- Cisco Anyconnect – Cisco Secure Client-AnyConnect

Advanced configuration This field provides the options to configure third-party VPN apps.Always-on Selecting this option makes the device get connected to the VPN network always. VPN Lockdown Enabling this option enforces the configured VPN connection, restricting access to other networks, including mobile data, whenever the VPN is disconnected or unavailable.Bypass Lockdown If enabled, this option grants selected apps direct access to the device’s cellular data/Wi-Fi network, when the VPN is in lockdown mode but not connected. This option is available when the **VPN Lockdown** option is enabled. Allowed Apps Admins can allow specific apps to access the device’s cellular data/Wi-Fi network, even when the device is locked to the configured VPN. This option is available only when the **Bypass Lockdown** option is enabled.

 

 

Associate Policies with Devices / Groups
----------------------------------------

If the policy has not yet been saved.

1. Navigate to **Policy Targets**.
2. Click on **+Add Devices**.
3. Select the devices and click **OK**.
4. Click on **Save** to apply the policies to devices.

Apart from devices, you can also associate the policies with device groups, user and user groups from “Policy Targets”.

If the policy has been saved, you can associate it by another method.

1. From Policies tab, check the policies to be associated.
2. Click on **Manage → Associate Targets** and select the device.
3. Click on **Associate** to apply policy to the devices.

 What happens at the device end? 
---------------------------------

Once the policy is associated with the device, the pushed VPN network will be visible in the VPN section of the Settings app of the device. The user can connect to the configured network without authenticating with the network password.

 Warning: 
VPN won’t be configured if the device is not secured with a password. If the password is not set on the device and once the VPN policy has been associated, a prompt appears to set the password. VPN can then be configured after setting a device password.

 

 
 Exception: If Web Content Filtering is applied, features like VPN and tethering may have conflicts. This behavior is expected on Samsung Knox devices.