- In Jamf School, navigate to Profiles > Overview in the sidebar.
- Click + Create Profile.
- Select the operating system you want to make the profile for.
- Select the type of enrollment you want to make the profile for.
- Enter the name of the iboss security filter group name in the Profile name field and configure the additional settings as needed, including the removal policy and time filter.
- Click Finish.
- In the list of payloads on the left side of the pane, locate the iOS payload category and click the VPN payload.
- Click Configure to configure the following settings:
- Connection Name —VPN
- Connection Type —Custom SSL
- Server —Set this to the DNS hostname of your preferred iboss cloud DNS cluster.
- Account —Use one of the following variables for the identifier type that will be populated for each device:
%Username%
%Name%
%SerialNumber%
- Identifier —Set this to the bundle identifier that corresponds to the iboss cloud Enterprise app.
- Provider Type —App Proxy
- Enable VPN On Demand —Enabled
- In the Custom Data settings, click + Add custom data and enter the following keys and values:
GatewayPort—Set this to the port used by the iboss cloud proxy.RunTimeMode—standardProxyAutoConfigurationScriptURL—Set this to the URL for the iboss cloud PAC script.ComputerOverrideUser—If you want auto group categorization to occur with iboss cloud, set this to 0. If you want all group categorization to occur based on the device's configuration policy, set this to 1.—Set this to the group security key for the policy's targeted filter group.WebSecurityKeyGatewayHost—Use the hostname of the preferred DNS cluster used for the Server field.CloudRegistrationSSLPort—If the proxy port was provisioned as 8009, set this to 8016. If the proxy port was provisioned as 80, set this to 443.LogLevel—0AutoLoginSecurityGroups—Set this to the group name that is associated with the security key from the WebSecurityKey parameter.
- Configure the following settings:
- User Authentication —Certificate
- (Optional) If you plan to use SSL decryption, you must add the iboss cloud SSL decryption certificate to the profile by doing the following:
- In the list of payloads on the left side of the pane, locate the General payload category and click the Certificates payload.
- Upload your iboss cloud SSL decryption certificate.Note:
The file you upload to Jamf School must use the .cer file type.
- Click Upload certificate.
- In the list of payloads on the left side of the pane, locate the General category and click the Scope payload to add a device group to the scope, ensuring the installation method is "Automatic installation".
- Click Save.
After saving the profile, check one of the devices included in the scope to confirm that the profile has installed successfully. Inspect the device's Certificate Trust settings to confirm that all relevant certificates are trusted.