About the setup for single sign-on with Kerberos

The setup described allows Safari and managed apps that support Kerberos to securely access an internal resource using SSO when the device is outside the corporate network. The Key Distribution Center (KDC) sits inside the corporate network. A major architectural change was introduced in Ivanti Tunnel 2.0 allowing Tunnel to use Network Extension framework introduced in iOS 9.0. Due to the support for Network Extension framework, use of Standalone Sentry as a KKDCP is no longer required for SSO with Kerberos.