Omnissa Workspace ONE Web supports the ability to tunnel websites through the Tunnel gateway component. Learn how to set up Omnissa Workspace ONE Tunnel for Workspace ONE Web.
The Tunnel gateway provides stronger encryption and authentication, increased browsing speed, and more detailed traffic controls. This does not require the use of the Workspace ONE Tunnel app for SDK-built applications, but other third-party applications still need support from the Tunnel app.
To take advantage of the improved tunneling capabilities, make sure you have deployed the Tunnel gateway and are using Workspace ONE UEM Console 1905 or higher version.
Select an App Tunnel
Workspace ONE UEM supports a number of application tunneling (app tunneling) solutions that allow individual applications to authenticate and securely communicate with internal back-end resources. By enabling an app tunnel for a specific set of business applications, you can be certain that unauthorized or malicious apps do not have access to your network.
Note: Workspace ONE console 1905 introduces a new Allow all non-FQDN URLs through tunnel setting that gives you the option to deactivate the feature which is enabled by default.
For more infomration, see Omnissa Workspace ONE Tunnel Documentation at Omnissa Product Documentation.
Supported App Tunneling Technologies
Workspace ONE UEM supports the following technologies for app tunneling using the Settings and Policies configuration.
| App Tunnel | Description |
|---|---|
| Standard Proxy | Enables devices to rely on an existing HTTP or SSL Proxy to determine which content the Workspace ONE Web or other web can access. |
| Omnissa Tunnel Proxy | Accesses corporate content from within your network such as an intranet site. With the Omnissa Workspace ONE Tunnel enabled, you can access internal corporate content on your device. For information on configuring the Omnissa Workspace ONE Tunnel, see the Omnissa Workspace ONE Tunnel Admin and Install Guide. |
| Omnissa Tunnel | Enables app-tunneling to both SDK-built applications and applications managed on MDM enrolled devices across major platforms. Tunnel provides better speed and performance over Tunnel Proxy, more secure authentication and encryption utilizing certificates, TLS 1.2, and tighter network access control through domain filtering. |
| F5 Proxy | Use to access your internal network as an alternative to the Workspace ONE Tunnel. |
Migrate Proxy App Tunnel URLs to Tunnel SDK
Tunnel with the Per-App Tunnel (Tunnel SDK) provides a unique feature called Device Traffic Rules. You can set individual traffic policies for tunneling, blocking, and bypassing traffic for each of your apps with the Device Traffic Rules. For information on Device Traffic Rules, see Create Device Traffic Rules in Tunnel.
- If you migrate from Tunnel Proxy to Tunnel SDK (Per-App Tunnel) and want to keep the domains that use the tunnel, enter the App Tunnel URLs from the Proxy to the Device Traffic Rules settings for Tunnel SDK.
- Navigate to Groups & Settings > All Settings > Apps > Settings and Policies > Security Policies > App Tunnel Mode > Omnissa Tunnel Proxy and record the entries in the App Tunnel URLs field.
- Navigate to Groups & Settings > All Settings > System > Enterprise Integration > Omnissa Tunnel > Network Traffic Rules > Device Traffic Rules
- Select the applicable SDK application (like Workspace ONE Web).
- Add multiple applications. This configuration differs from the default SDK setting because you need to enter the domains to tunnel by the app rather than as a blanket entry for all SDK-built apps.
- Select Tunnel for the Action.
- Enter the app tunnel URLs from the Omnissa Tunnel Proxy option in Destination Hostname.
- Define a default policy for domains that do not match patterns with your destination host names.
- Navigate to Groups & Settings > All Settings > Apps > Settings and Policies and select App Tunnel Mode and change from Omnissa Tunnel Proxy to Omnissa Tunnel.
Configure App Tunnel for the Default SDK Profile
Use App Tunnel to allow an application to communicate through a VPN or reverse proxy to access internal resources, such as a SharePoint or intranet sites.
You must set up the menu items for Omnissa Tunnel Proxy or Omnissa Tunnel before using them.
To set up configurations and device traffic rules for the Omnissa Tunnel Proxy or the Omnissa Tunnel, see Omnissa Workspace ONE Tunnel documentation at Omnissa Product Documentation.
If you are replacing the Tunnel Proxy with Tunnel SDK, migrate the App Tunnel URLs entries. See Migrating from Tunnel Proxy to Per-App Tunnel.
Was this page helpful?