Set up VPN using Knox StrongSwan for UEM dark site environments

In a UEM dark site environment you must set up VPN access to your environment so that Samsung Knox devices can access your internal servers and resources. For more information about UEM in dark site environments, see Installing or upgrading BlackBerry UEM in a dark site environment in the Installation content.
Download the Knox Service Plugin and Android VPN Management for Knox StrongSwan apps and add the .apk files to the shared network location for internal apps.
  1. Add the Knox Service Plugin and Android VPN Management for Knox StrongSwan apps to the app list.
  2. Select the Knox Service Plugin app and click The Plus icon to set app configuration options.
    1. Under VPN profile, select Knox built-in VPN.
    2. Under Parameters for Knox built-in VPN for StrongSwan, set the following options:
      • Set the Authentication type to "ipsec_ike2_rsa".
      • Set the User certificate alias to the user name with "_1 [Knox]" appended. You can use variables for the user name (for example, %UserFirstName% %UserLastName% _1 [Knox].)
      • Set the CA certificate alias to the user name with " [Knox]" appended. You can use variables for the user name (for example, %UserFirstName% %UserLastName% [Knox].)
  3. Assign the app to the user.
  4. Create a CA certificate profile to send the VPN server certificate to devices and assign it to users.
  5. Add a VPN client certificate for each user.