End-of-Life (EoL)

Configure a Device-Level VPN Configuration for Android Devices Using AirWatch

You can easily enable access to internal resources from your managed Android mobile endpoints by configuring VPN access using AirWatch. In a device-level VPN configuration, you route all of the traffic that matches the access routes configured on the GlobalProtect gateway through the GlobalProtect VPN.
  1. Download the GlobalProtect app for Android:
  2. From the AirWatch console, modify or add a new Android profile.
    1. Navigate to
      Devices
      Profiles
      List View
      .
    2. Select an existing profile to which to add the VPN configuration or add a new one (select
      Add
      Add Profile
      ).
    3. Select
      Android
      as the platform and
      Device
      as the configuration type.
  3. Configure
    General
    profile settings:
    • Name
      —Provide a meaningful name for this configuration.
    • Version
      —This field is auto-populated with the latest version number of the configuration profile.
    • Description
      —A brief description of the profile that indicates its purpose.
    • Profile Scope—Scope for this profile, either
      Production,
      Staging
      , or
      Both
      .
    • Assignment Type
      —Determines how the profile is deployed to endpoints. Select
      Auto
      to deploy the profile to all endpoints automatically,
      Optional
      to enable the end user to install the profile from the Self-Service Portal (SSP) or to manually deploy the profile to individual endpoints, or
      Compliance
      to deploy the profile when an end user violates a compliance policy applicable to the endpoint.
    • Managed By
      —The Organization Group with administrative access to the profile.
    • Assigned Smart Group
      —The Smart Group to which you want the device profile added. Includes an option to create a new Smart Group which can be configured with specs for minimum OS, device models, ownership categories, organization groups and more.
    • Allow Removal
      —Determines whether or not the profile can be removed by the endpoint's end user. Select
      Always
      to enable the end user to manually remove the profile at any time,
      Never
      to prevent the end user from removing the profile from the endpoint, or
      With Authorization
      to enable the end user to remove the profile with the authorization of the administrator. Choosing
      With Authorization
      adds a required Password.
    • Exclusions
      —If
      Yes
      is selected, a new field
      Excluded Smart Groups
      displays, enabling you to select those Smart Groups you wish to exclude from the assignment of this device profile.
  4. Save and Publish
    this profile to the assigned Smart Groups.
  5. To configure the VPN settings, select
    VPN
    and then click
    Configure
    .
  6. Configure
    Connection Info
    , including:
    • Connection Type
      —Select
      GlobalProtect
      as the network connection method.
    • Connection Name
      —Enter the name of the connection name that the endpoint will display.
    • Server
      —Enter the hostname or IP address of the GlobalProtect portal to which to connect.
  7. Configure
    Authentication
    information:
    1. Choose the method to authenticate end users:
      Password
      or
      Certificate
      .
    2. Enter the
      Username
      of the VPN account or click add ( “
      +
      ” ) to view supported lookup values that you can insert.
    3. Enter a
      Password
      or upload an
      Identity Certificate
      that GlobalProtect will use to authenticate users.
  8. Save & Publish
    this profile to the assigned Smart Groups.

Recommended For You