Configuring Email+ with Ivanti Tunnel for Android Enterprise
2 min
configure email+ with ivanti tunnel to setup access to exchange server through exchange web services (ews) protocol and to support email+ configuration when vpn access is required before you begin configure email+ android enterprise docid\ wypooh01d4uneln7e8dqg add local certificate authority (ca), see configuring ivanti epmm as an independent root ca (self signed) https //help ivanti com/mi/help/en us/core/11 x/dmgw/dmgfiles/configuring mobileiron c htm?highlight=local section in the ivanti epmm device management guide for android and android enterprise devices the following steps describe how to configure apptunnel with standalone sentry procedure in the ivanti epmm admin portal, go to services > sentry > add new > standalone sentry in the new standalone sentry window, enter the sentry hostname / ip name select the enable apptunnel check box, and deselect enable activesync if enable apptunnel is enabled, other sentry services such as kerberos proxy and email+ notification service are disabled in the device authentication configuration section select identity certificate from the drop down menu upload local ca to the trusted root certificate upload field in the apptunnel configuration section, add \<ip any> as apptunnel service in services in the ivanti epmm admin portal, go to services > sentry > standalone sentry and click on manage certificate for configuring standalone sentry in the manage certificate window, from the certificate options drop down menu select upload certificate to add public certificate to standalone sentry configuring ivanti tunnel for email+ android enterprise the following steps describe how to configure ivanti tunnel rules for email+ procedure in the ivanti epmm admin portal , go to apps > app catalog > +add select the ivanti tunnel app for android enterprise and click edit scroll down to configuration choices click add+ to add a new tunnel configuration in the default configuration for ivanti tunnel section update the following restrictions restriction description sentry server specify the fqdn for the sentry server that is configured with the ip any service configure sentry server if you selected one of the following tunnel profile modes sentry profile only sentry + access profile addedroutes enter the network routes that are allowed through tunnel use cidr format each entry in the list is separated by a semicolon (;) ipv4 only this enables split tunneling where only specific traffic can be taken through tunnel the routes configured only impact apps that use tunnel example 10 0 0 0/8;101 210 48 9/32 clientcertalias this is the certificate alias set up with local certificate from the same ca that was uploaded to sentry the value is $cert alias \<name of scep>$ where \<name of scep> is the certificate enrollment setting configured in ivanti epmm ui example $cert alias\ scepidentitycert$ where scepidentitycert is the name of the scep configured in ivanti epmm disablepinning check disable pinning after configuring and successfully connecting the email+ app with ivanti tunnel, the tunnel record appears in apps > app tunnels
