Pulse Secure SSL

This VPN connection type is supported on iOS, macOS, Android, and Windows devices.

Ivanti, Inc recommends using the Pulse Secure SSL connection type instead of Juniper SSL.

Use the following guidelines to configure Pulse Secure SSL VPN.

Within these selections, you may make settings for:

Proxy - None (default)

Use the following guidelines to configure a Pulse Secure SSL VPN without a proxy.

Table 70.  Proxy - None (default) settings

Item

Description

Name

Enter a short phrase that identifies this VPN setting.

Description

Provide a description that clarifies the purpose of these settings.

Channel

For macOS only. Select one of the following distribution options:

Device channel - the configuration is effective for all users on a device. This is the typical option.

User channel - the configuration is effective only for the currently registered user on a device.

Connection Type

Select Pulse Secure SSL.

Samsung Knox

Select this option to use per-app VPN (either inside or outside the Knox Workspace) or per-container VPN. A Samsung Knox license is required.

A VPN setting with this option selected cannot be successfully applied to a non-Samsung Android device.

This setting is ignored on non-Android devices.

Deploy inside Knox Workspace

Select this option to deploy the VPN client app inside the Knox Workspace (container). Deploying the app inside the container means that the Knox security platform protects the app and its data.

This option is available only if you select the Samsung Knox option.

See:

Configuring VPN modes when VPN client is outside the Knox container

Server

Enter the IP address, hostname, or URL for the VPN server.

Proxy

This setting is not supported on Android devices.

Username

Enter a value for the username (required.) The default value is $USERID$. Include at least one of the following variables:

$USERID$, $EMAIL$, $SAM_ACCOUNT_NAME$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$

You can use combinations such as the following:

$USERID$:$EMAIL$

$USERID$_$EMAIL$

Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant username.

User Authentication

Select the user authentication to use:

Password - see next row for information.

Certificate - If you select Certificate, select the identity certificate to be used as the account credential.

If you select Certificate, and extended authentication (EAP) is not used, this certificate will be sent out for IKE client authentication. If extended authentication is used, this certificate can be used for EAP-TLS.

Password

Specify the password to use (required.) The default value is $PASSWORD$. Use this field to specify a custom format, such as $PASSWORD$_$USERID$.

Include at least one of the following variables:

$USERID$, $EMAIL$, $PASSWORD$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$

You can use combinations such as $EMAIL$:$PASSWORD$

Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant password.

Role

Specify the Pulse user role to use as a restriction.

Realm

Specify the Pulse realm to use as a restriction.

VPN On Demand

If the Samsung Knox and per-App VPN fields are both selected, then select this option to use VPN On Demand.

Per-app VPN

When selecting this option, a Samsung Knox license is required.

Provider Type

This setting applies to iOS and macOS devices only.

Continue with Custom Data.

Proxy - Manual

Use the following guidelines to configure a Pulse Secure SSL VPN with a manual proxy.

Table 71.  Proxy - Manual settings

Item

Description

Name

Enter a short phrase that identifies this VPN setting.

Description

Provide a description that clarifies the purpose of these settings.

Channel

For macOS only. Select one of the following distribution options:

  • Device channel - the configuration is effective for all users on a device. This is the typical option.
  • User channel - the configuration is effective only for the currently registered user on a device.

Connection Type

Select Pulse Secure SSL.

Samsung Knox

Select this option to use per-app VPN (either inside or outside the Knox Workspace) or per-container VPN. A Samsung Knox license is required.

A VPN setting with this option selected cannot be successfully applied to a non-Samsung Android device.

This setting is ignored on non-Android devices.

Deploy inside Knox Workspace

Select this option to deploy the VPN client app inside the Knox Workspace (container). Deploying the app inside the container means that the Knox security platform protects the app and its data.

This option is available only if you select the Samsung Knox option.

See:

Configuring VPN modes when VPN client is outside the Knox container

Server

Enter the IP address, hostname, or URL for the VPN server.

Proxy

This setting is not supported on Android devices.

Proxy Server

This setting is not supported on Android devices.

Proxy Server Port

This setting is not supported on Android devices.

Type

This setting is not supported on Android devices.

Proxy Server User Name

This setting is not supported on Android devices.

Proxy Server Password

This setting is not supported on Android devices.

Proxy Domains (iOS only)

This field applies to iOS and macOS devices only.

Username

Enter a value for the username (required.) The default value is $USERID$. Include at least one of the following variables:

$USERID$, $EMAIL$, $SAM_ACCOUNT_NAME$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$

You can use combinations such as the following:

$USERID$:$EMAIL$

$USERID$_$EMAIL$

Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant username.

User Authentication

Select the user authentication to use:

Password - see next row for information.

Certificate - If you select Certificate, select the identity certificate to be used as the account credential.

If you select Certificate, and extended authentication (EAP) is not used, this certificate will be sent out for IKE client authentication. If extended authentication is used, this certificate can be used for EAP-TLS.

Password

Specify the password to use (required.) The default value is $PASSWORD$. Use this field to specify a custom format, such as $PASSWORD$_$USERID$.

Include at least one of the following variables:

$USERID$, $EMAIL$, $PASSWORD$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$

You can use combinations such as $EMAIL$:$PASSWORD$

Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant password.

Role

Specify the Pulse user role to use as a restriction.

Realm

Specify the Pulse realm to use as a restriction.

VPN On Demand

If the Samsung Knox and per-App VPN fields are both selected, then select this option to use VPN On Demand.

Per-app VPN

When selecting this option, a Samsung Knox license is required.

Select Yes to create a per-app VPN setting.

When multiple labels are assigned to associate the selected VPN configurations in the Per-App VPN section, then VPN prioritization will happen in the order of the selected list.

See the Ivanti EPMM Apps@Work Guide for information about how to add or edit apps.

Provider Type

This setting applies to iOS and macOS devices only.

Continue with Custom Data.

Proxy - Automatic

Use the following guidelines to configure a Pulse Secure SSL VPN with an automatic proxy.

Table 72.  Proxy - Automatic settings

Item

Description

Name

Enter a short phrase that identifies this VPN setting.

Description

Provide a description that clarifies the purpose of these settings.

Channel

For macOS only. Select one of the following distribution options:

Device channel - the configuration is effective for all users on a device. This is the typical option.

User channel - the configuration is effective only for the currently registered user on a device.

Connection Type

Select Pulse Secure SSL.

Samsung Knox

Select this option to use per-app VPN (either inside or outside the Knox Workspace) or per-container VPN. A Samsung Knox license is required.

A VPN setting with this option selected cannot be successfully applied to a non-Samsung Android device.

This setting is ignored on non-Android devices.

Deploy inside Knox Workspace

Select this option to deploy the VPN client app inside the Knox Workspace (container). Deploying the app inside the container means that the Knox security platform protects the app and its data.

This option is available only if you select the Samsung Knox option.

See:

Configuring VPN modes when VPN client is outside the Knox container

Server

Enter the IP address, hostname, or URL for the VPN server.

Proxy

This setting is not supported on Android devices.

Proxy Server URL

This setting is not supported on Android devices.

Proxy Domains (iOS only)

This setting applies to iOS and macOS devices only.

Username

Enter a value for the username (required.) The default value is $USERID$. Include at least one of the following variables:

$USERID$, $EMAIL$, $SAM_ACCOUNT_NAME$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$

You can use combinations such as the following:

$USERID$:$EMAIL$

$USERID$_$EMAIL$

Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant username.

User Authentication

Select the user authentication to use:

Password - see next row for information.

Certificate - If you select Certificate, select the identity certificate to be used as the account credential.

If you select Certificate, and extended authentication (EAP) is not used, this certificate will be sent out for IKE client authentication. If extended authentication is used, this certificate can be used for EAP-TLS.

Password

Specify the password to use (required.) The default value is $PASSWORD$. Use this field to specify a custom format, such as $PASSWORD$_$USERID$.

Include at least one of the following variables:

$USERID$, $EMAIL$, $PASSWORD$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$

You can use combinations such as $EMAIL$:$PASSWORD$

Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant password.

Role

Specify the Pulse user role to use as a restriction.

Realm

Specify the Pulse realm to use as a restriction.

VPN On Demand

If the Samsung Knox and per-App VPN fields are both selected, then select this option to use VPN On Demand.

Per-app VPN

When selecting this option, a Samsung Knox license is required.

Provider Type

This setting applies to iOS and macOS devices only.

Continue with Custom Data.

Custom Data

  • Add+ - Click to add a new key / value pair.
  • Key / Value - Enter the Key / value pairs necessary to configure the VPN setting. The app creator should provide the necessary key / value pairs.