Configuring VPN chaining (2024)

VPN chaining is the nesting of a VPN tunnel in another VPN tunnel. VPN chaining provides additional security by hiding the Tunnel VPN end destination. With MobileIron Tunnel you can configure VPN chaining with OpenVPN as the outer tunnel and MobileIron Tunnel as the inner tunnel. VPN chaining can be configured for per-app only.

Before you begin

  • Configure MobileIron Tunnel for Samsung Knox Workspace as described in Configuration overview for MobileIron Tunnel for the Samsung Knox container (Core).
  • Configure an OpenVPN VPN setting in the MobileIron Core Admin Portal. For more information, see the “Configuring new VPN settings” and the “OpenVPN” sections in the MobileIron Core Device Management Guide for Android.

    NOTE: Use the OpenVPN setting on MobileIron Core only to configure Samsung “OpenVPN net.openvpn.knox.connect” for Samsung Knox devices. The configuration is available only to limited customers as approved by Samsung. Contact Samsung to get the correct OpenVPN package. It is supported only on devices with the Samsung Knox option selected in the VPN setting.

Procedure

  1. In the MobileIron Core Admin Portal, go to Policies & Configs > Configurations.
  2. Select and Edit the Tunnel VPN configuration for Samsung Knox Workspace.
    1. In the Tunnel VPN configuration for Samsung Knox Workspace, for VPN Chaining, select Inner.
    2. Click Save.
  3. Select and Edit the OpenVPN configuration.
    1. In the OpenVPN configuration, for VPN Chaining, select Outer.
    2. Click Save.
  4. Select and Edit the Samsung Knox container configuration.

    Figure 1. Apps configuration

    Configuring VPN chaining (1)

  5. In the Apps section of the Samsung Knox container configuration, do the following:
    1. For VPN for Tunnel, select the OpenVPN configuration with outer VPN chaining (Configured in Configuring VPN chaining).
    2. For apps that will use VPN chaining, select the Tunnel VPN configuration with inner VPN chaining (Configured in step 2).
  6. Ensure that the configurations are applied to a label that contains the devices for which you want to allow VPN chaining with MobileIron Tunnel.
Configuring VPN chaining (2024)
Top Articles
Latest Posts
Article information

Author: Kareem Mueller DO

Last Updated:

Views: 5579

Rating: 4.6 / 5 (66 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Kareem Mueller DO

Birthday: 1997-01-04

Address: Apt. 156 12935 Runolfsdottir Mission, Greenfort, MN 74384-6749

Phone: +16704982844747

Job: Corporate Administration Planner

Hobby: Mountain biking, Jewelry making, Stone skipping, Lacemaking, Knife making, Scrapbooking, Letterboxing

Introduction: My name is Kareem Mueller DO, I am a vivacious, super, thoughtful, excited, handsome, beautiful, combative person who loves writing and wants to share my knowledge and understanding with you.