Chapter 4 Infrastructure and integration 36
For more information, see the F5 technical brief
Secure iPhone Access to Corporate Web Applications.
•
Juniper Junos Pulse SSL VPN: iOS supports Juniper Networks SA Series SSL VPN Gateway
running version 6.4 or later with Juniper Networks IVE package 7.0 or later. Install the Junos
Pulse app, available on the App Store.
For more information, see Junos Pulse on the Juniper Networks website.
•
Mobile Iron SSL VPN: For information, see the Mobile Iron website.
•
NetMotion SSL VPN: For information, see the NetMotion website.
•
OpenVPN SSL VPN: iOS supports OpenVPN Access Server, Private Tunnel, and OpenVPN
Community. For conguration, install the OpenVPN Connect app, available on the App Store.
•
Palo Alto Networks GlobalProtect SSL VPN: iOS supports the GlobalProtect gateway from Palo
Alto Networks. Install the GlobalProtect for iOS app, available on the App Store.
•
SonicWALL SSL VPN: iOS supports SonicWALL Aventall E-Class Secure Remote Access
appliances running 10.5.4 or later, SonicWALL SRA appliances running 5.5 or later, and
SonicWALL Next-Generation Firewall appliances including the TZ, NSA, E-Class NSA running
SonicOS 5.8.1.0 or later. Install the SonicWALL Mobile Connect app, available on the App Store.
For more information, see the SonicWALL website.
VPN setup guidelines
Cisco IPSec setup guidelines
Use these guidelines to congure your Cisco VPN server for use with iOS devices. iOS supports
Cisco ASA 5500 Security Appliances and PIX Firewalls congured with 7.2.x software or later.
The latest software release (8.0.x or later) is recommended. iOS also supports Cisco IOS VPN
routers with IOS version 12.4(15)T or later. VPN 3000 Series Concentrators don’t support iOS
VPN capabilities.
Proxy setup
For all congurations, you can specify a VPN proxy:
•
To congure a single proxy for all connections, use the Manual setting and provide the
address, port, and authentication if necessary.
•
To provide the device with an auto-proxy conguration le using PAC or WPAD, use the Auto
setting. For PACS, specify the URL of the PACS or JavaScript le. For WPAD, iOS asks DHCP and
DNS for the appropriate settings.
The VPN proxy conguration gets used when the VPN is providing the following:
•
The default resolver and the default route: The VPN proxy is used for all web requests on
the system.
•
A split tunnel: Only connections to hosts that match the VPN’s DNS search domains will use
the VPN proxy.
Authentication methods
iOS supports the following authentication methods:
•
Pre-shared key IPSec authentication with user authentication via xauth.
•
Client and server certicates for IPSec authentication, with optional user authentication
via xauth.
•
Hybrid authentication, where the server provides a certicate and the client provides a pre-
shared key for IPSec authentication. User authentication is required via xauth.
•
User authentication is provided via xauth and includes the following authentication methods:
100% resize factor