Configure a User-Initiated Remote Access VPN Configuration for iOS Endpoints Using MobileIron

In a remote access (On-Demand) VPN configuration, users must manually launch the app to establish the secure GlobalProtect connection. Traffic that matches specific filters (such as port and IP address) configured on the GlobalProtect gateway is routed through the VPN tunnel only after users initiate and establish the connection.
Use the following steps to configure a user-initiated remote access VPN configuration for iOS endpoints using MobileIron:
  1. Download the GlobalProtect app for iOS.
  2. Add a certificate configuration and then configure the certificate settings.
    All on-demand VPN configurations require certificate-based authentication.
  3. Add an on-demand (remote access) VPN configuration.
    • Set the configuration type to VPN On Demand.
  4. Configure VPN on-demand settings for iOS.
    • Set the Connection Type to Palo Alto Networks GlobalProtect, and then configure the associated settings.

Related Documentation