cancel
Showing results for 
Search instead for 
Did you mean: 
Matthieu_Dieric
F5 Employee
F5 Employee

Nowadays, with MDM, we can push VPN configurations to mobiles devices.

A new kind of VPN called Per-APP VPN (Android 5.0 or iOS 7.0 minimum) is available on MDM like AirWatch, MobileIron ... Per-APP is a brand new VPN tunnel concept. This Per-App VPN tunnel is started only for a specific application on the mobile terminal. All flow from this app are routed into this tunnel. All other trafic uses local NIC (WIFI, 3/4G without VPN).

It's a little bit different from On-Demand VPN. On-Demand start when a specific network is requested and all trafic goes through this tunnel whatever the application.

This video explains how to set AirWatch side and APM side

 

/////////////////////////////////////////////////////////////////////////////////////////

 

Avec un MDM (Mobile Device Manager), il est possible de pousser sur vos terminaux mobiles (iOS 7.x et Android 5.0 minimum) un profile de configuration VPN dit "Per-App VPN". 

Un Per-App VPN est un VPN monté à la demande par une application sur le terminal mobile. Cela se rapproche du "On-Demand" à la différence que seul le flux en sortie de l'application ira dans le tunnel SSL. Contrairement à un tunnel On-Demand où tous les flux transitent dans le tunnel SSL.

Dans cet article (vidéo en anglais), je vous présente la mise en place d'une solution Per-App VPN avec le MDM AirWatch et la gateway SSL F5 BIGIP APM. Pour cela :

  • AirWatch intègre dans son MDM les briques VPN SSL F5 afin de simplifier la configuration des profiles VPN SSL. Aucun code XML n'est nécessaire car le EDGE client est déjà connu du MDM AirWatch.
  • F5 intègre les API avec les solutions MDM telles que AirWatch.

 

 

Comments
Richard__147088
Nimbostratus
Nimbostratus
Waarom in het Frans en niet in het Engels? Anoying, isn't it, when you can't read what someone writes.
Matthieu_Dieric
F5 Employee
F5 Employee
Hi Richard, you are on the French blog (French tag on this article) and you do right, I don't speak Dutch ;). Let me translate for you : Nowadays, with MDM, we can push VPN configurations to mobiles devices. A new kind of VPN called Per-APP VPN (Android 5.0 or iOS 7.0 minimum) is available on MDM like AirWatch, MobileIron ... Per-APP is a brand new VPN tunnel concept. This Per-App VPN tunnel is started only for a specific application on the mobile terminal. All flow from this app are routed into this tunnel. All other trafic uses local NIC (WIFI, 3/4G without VPN). It's a little bit different from On-Demand VPN. On-Demand start when a specific network is requested and all trafic goes through this tunnel whatever the application. This video explains how to set AirWatch side and APM side. Hope this help.
amolari
Cirrus
Cirrus
Bonjour Matthieu. Il est donc possible d'avoir plusieurs tunnels depuis le même device (plusieurs apps lancées, chacune avec per-App VPN). Est-ce que l'APM compte 1 CCU par device dans ce cas ou non? Merci pour vos éclaircissements. Alexandre
amolari
Cirrus
Cirrus
Vous ne parlez pas de la partie "device validation" (sideband irule). Aucune référence à celle-ci sur Devcentral. Pourriez-vous nous donner quelques informations à ce sujet?
Yoann_Le_Corvic
Nimbostratus
Nimbostratus
Hi. Nice piece of work... But even though I see that the leatest Android Edge Client support Per App VPN, I see no way to enable it. The only function that seems available is On Demand VPN on Android. Or did I miss something ?
Matthieu_Dieric
F5 Employee
F5 Employee
Alexandre, les irules sont disponibles en passant par votre contact F5 local. Elles ne sont pas encore publiques. Yoann, Per-App VPN settings can only be done from an MDM. There is no way to enable it in EDGE Client app.
Roderick_Graham
Nimbostratus
Nimbostratus
Where can I find more detail regarding how the macro objects were configured ("Collect Device Info", "Enrollment" and "On-Demand Cert Auth")?
Daniel_W_
Cirrus
Cirrus
Hi Matthieu, does Edge Client on Android 5.0 starts the VPN connection, when the "per App-VPN" enabled App is started? On iOS, this works fine, but we couldn't do that on Android so far. According to my information, this should be possible with Android 5 now. I've raised a support call for that but they don't wanna help me ;( Thanks in advance.
lcpWidgit
Nimbostratus
Nimbostratus
Hi, Thankyou for the great guide. I am having problem finding the iApp and the irules used in the guide. Can you please provide the irule.
Matthieu_Dieric
F5 Employee
F5 Employee

iApp is available here : https://github.com/MattDierick/AirWatch-iApp

 

This one is not officially supported. On V12, you can use the new MDM agent in APM.

 

Version history
Last update:
‎04-May-2015 13:42
Updated by:
Contributors