Skip Navigation

Set up VPN using Knox StrongSwan for
UEM
dark site environments

In a
UEM
dark site environment you must set up VPN access to your environment so that
Samsung Knox
devices can access your internal servers and resources. For more information about
UEM
in dark site environments, see Installing or upgrading BlackBerry UEM in a dark site environment in the Installation content.
Download the
Knox Service Plugin
and Android VPN Management for Knox StrongSwan apps and add the .apk files to the shared network location for internal apps.
  1. Add the
    Knox Service Plugin
    and Android VPN Management for Knox StrongSwan apps to the app list.
  2. Select the
    Knox Service Plugin
    app and click The Plus icon to set app configuration options.
    1. Under
      VPN profile
      , select
      Knox built-in VPN
      .
    2. Under
      Parameters for Knox built-in VPN for StrongSwan
      , set the following options:
      • Set the
        Authentication type
        to "ipsec_ike2_rsa".
      • Set the
        User certificate alias
        to the user name with "_1 [Knox]" appended. You can use variables for the user name (for example,
        %UserFirstName% %UserLastName% _1 [Knox]
        .)
      • Set the
        CA certificate alias
        to the user name with " [Knox]" appended. You can use variables for the user name (for example,
        %UserFirstName% %UserLastName% [Knox]
        .)
  3. Assign the app to the user.
  4. Create a CA certificate profile to send the VPN server certificate to devices and assign it to users.