Skip to main content

July 28, 2026

Configure Workspace ONE Tunnel Settings for Workspace ONE UEM

Tunnel deployment secures the network traffic between an end-user device and a website through the Workspace ONE Web mobile application.

Procedure

  1. In the Unified Access Gateway admin UI, navigate to the Configure Manually section and click Select.

  2. In the General Settings > Edge Service Settings, click Show.

  3. Click Tunnel Settings gearbox icon.

  4. To enable Tunnel Settings, turn on the Enable or disable Tunnel Settings toggle.

  5. Configure the following edge service settings resources.

    OptionINI ParameterDescription
    API Server URLapiServerUrl Enter the URL to your Workspace ONE UEM API server. To find the URL, go to Groups & Settings > All Settings > Advanced > Site URLs > REST API URL. The appliance contacts the Workspace ONE UEM API server to fetch your Tunnel configuration. For example, enter as https://example.com:<port>.
    API Server User Name apiServerUsernameEnter the username of a Workspace ONE UEM console admin user account. The account must have Console Administrator privileges at a minimum. For the Tunnel Edge Service on UAG, the admin account used to save the Tunnel Service settings is only used at initial configuration. Once the Tunnel Edge Service is successfully saved and configured, further UEM API communication is secured through certificate-based authentication. The admin account will only be needed for a manual update to the Tunnel Edge Service. Workspace ONE Tunnel will continue to function even if this admin account is inactive.
    API Server PasswordapiServerPassword Enter the password of a Workspace ONE UEM console admin user account. You must have Console Administrator privileges at a minimum.
    Organization Group IDorganizationGroupCode (Optional) Enter the organization group ID in which this Tunnel configuration is configured. This field is not required if the Workspace ONE UEM console supports multi-tunnel configuration feature.
    Note: This setting is not available in the FIPS version.
    Tunnel Configuration IDtunnelConfigurationId (Optional) Enter the tunnel configuration ID. Tunnel Configuration ID configured in the Workspace ONE UEM Console. This field is supported only if the UEM console supports multi-tunnel configuration feature. When this field is blank, the default configuration from the specified organization group is fetched.
    Tunnel Server HostnameairwatchServerHostnameEnter the Tunnel external hostname configured in the Workspace ONE UEM console. The hostname must match the hostname entered in the Tunnel configuration wizard. Unified Access Gateway configures the instance as a relay server or an endpoint server based on the hostname. Ensure that you properly enter the hostname to avoid any issues in deployment.
  6. To configure other advanced settings, click More.

    OptionINI ParameterDescription
    Lock Configuration Turn on this toggle to prevent configuration auto updates being made from Workspace ONE UEM Console. Changes to custom configurations, authentication, certificates, and networking are locked on Unified Access Gateway. When you turn off this toggle, all the configuration auto updates are made through Workspace ONE UEM Console UI.
    Note: To apply changes to custom configurations, authentication, certificates, and networking, ensure that you re-save the Tunnel service.
    Outbound Proxy HostoutboundProxyHost Enter the host name where the outbound proxy is installed. Unified Access Gateway makes a connection to API Server through an outbound proxy if configured.
    Outbound Proxy PortoutboundProxyPort Enter the port number of the outbound proxy.
    Outbound Proxy User NameoutboundProxyUsername Enter the user name to log in to the outbound proxy.
    Outbound Proxy Password outboundProxyPasswordEnter the password to log in to the outbound proxy.
    NTLM authenticationntlmAuthentication Turn on this toggle to specify that the outbound proxy request requires NTLM authentication.
    Host EntrieshostEntry1 Enter the details to be added in the/etc/hosts file. Each entry should include an IP, a hostname, and an optional hostname alias in that order, separated by a space. For example, 10.192.168.1 example1.com, 10.192.168.2 example2.com example-alias. Click the '+' sign to add multiple host entries. Use this option if your DNS is not publicly available or accessible from the DMZ.
    Important: The host entries are saved only after you click Save.
    Trusted CertificatestrustedCert1
    • To select a certificate in PEM format and add to the trust store, click +.
    • To provide a different name, edit the alias text box.

      By default, the alias name is the filename of the PEM certificate.

    • To remove a certificate from the trust store, click -.
  7. Click Save. Unified Access Gateway initializes the gateway with the latest provided Tunnel settings and applies the configuration to the Tunnel service.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…