Configuring Tunnel VPN for Windows 10 (Core)

Windows 10 devices use an IP_ANY tunnel service configured on Standalone Sentry to access backend resources.

Before you begin 

If you are configuring per app VPN, ensure that you have created an IP_ANY AppTunnel service in Standalone Sentry. For information on setting up an IP_ANY AppTunnel service see “Working with Standalone Sentry for AppTunnel” in the Standalone Sentry Guide for Core.

If you are configuring Tunnel for securing authentication traffic with Access see the Access Guide.


1. In the Admin Portal, go to Policies & Configs > Configurations.
2. Click Add New > VPN.
3. For Connection Type, select Tunnel (Windows).
4. Specify the following:
- the Standalone Sentry on which you created the IP_ANY service
- client certificates
- how Tunnel is triggered
- whether specified traffic or all traffic goes through Tunnel
- Tunnel app behavior .
5. Click Save.
6. Apply the configuration to a label that contains the Windows 10 devices to which you want to distribute the configuration.
For a description of the configuration fields for Tunnel (Windows) VPN, see Tunnel VPN for Windows 10 field description.

For a description of the key-value pairs, see Key-value pairs for custom data.

For examples of custom data configuration, see Examples of custom data configurations.