Enable sinkhole VPN mitigation for iOS devices

Network threats can be mitigated using a sinkhole VPN profile in the MTD Local Actions configuration. Once you enable the MTD Local Actions Network Sinkhole option, you can optionally specify specific IP addresses, domains, and countries through the MTD console. See Sinkhole mitigation by IP address, domain, or country.

Ivanti, Inc recommends selecting the Network Sinkhole action ONLY for network-related threats. Use of Network Sinkhole action for device and application threats can result in disabling network connectivity to the device without the ability to restore network connectivity.

Before you begin 


  1. From the Ivanti Neurons for MDM Configurations page, create or edit an MTD local action configuration.
  2. From a threat in the Network Threats section, select Network Sinkhole from the Local Action iOS column.

    Figure 1. Network Sinkhole option in Actions menu.

  3. Finish your configuration choices, and click Next. The Configuration Distribution page displays.

    The VPN configuration cannot be edited. To remove the configuration, remove the Network Sinkhole options from the configuration.

  4. Click Enable this configuration.
  5. Select the devices you want the configuration pushed to.
  6. Click Done to push the configuration to the selected devices.