Creating a VPN Profile

A VPN profile is required to link the SCEP certificate profile to the Mobile Security Protect app on iOS devices. This section describes the procedure to create a VPN profile for iOS devices.
Note:
Use this procedure only if you do not already have a Mobile Security VPN integration configured. If a VPN configuration already exists, do not create a new VPN profile. Instead, follow the procedure in Zero Touch Deployment for iOS devices and modify it to set the Authentication method to the SCEP certificate you specified.
  1. Go to Devices > Apple mobile.
  2. Go to Manage devices > Configuration.
  3. Click Create > New Policy.

    The Create a profile window appears.

  4. Select Platform as iOS/iPadOS.
  5. From the Profile type list, select Templates and then select VPN.

  6. Click Create.
  7. In the Basic tab, enter a name for the profile.
  8. Click Next.
  9. In the Configuration settings tab:
    1. Select Connection type as Custom VPN.
    2. Under Base VPN, enter:
      1. Connection name

      2. VPN server address

      3. Select Authentication method as Certificates.

      4. In Authentication certificate, select the SCEP certificate profile you created.

      5. Enter VPN identifier as com.checkpoint.capsuleprotect.

      6. Enter the required key value pairs for custom VPN attributes.

  10. Click Next.
  11. Go to the Assignments tab and in the Included groups section, click Add groups.
  12. Search and select the groups that you want to include.
  13. Click Next.
  14. Review the details and click Create.
Continue with Configuring Netskope Integration in Mobile Security Administrator Portal.