2.5.1 Ensure 'VPN' is 'Configured'

Information

This recommendation pertains to establishing a virtual private network (VPN) connection as appropriate.

Rationale:

The network a device connects to provides important services that may be exploited by a malicious actor. Establishing a VPN mitigates the associated risks by encrypting data in transit and using known good network services, such as DNS.

Solution

This remediation procedure cannot be accomplished with a checkbox. As mentioned above, a per-app VPN configuration is the preferred solution, but a system-wide VPN is also acceptable. An appropriate solution will need to be determined and implemented. From the Configuration Profile:
1. Open Apple Configurator.
2. Open the Configuration Profile.
3. In the left windowpane, click on the 'VPN' tab.
4. In the right windowpane, enter an appropriate VPN configuration.
5. Deploy the Configuration Profile.

From the device,
1. Tap 'Settings'.
2. Tap 'General'.
3. Tap 'VPN'.
4. Enter an appropriate VPN configuration.

Impact:

None.

See Also

https://workbench.cisecurity.org/files/1688