Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Use the following enrollment process to silently install the BloxOne Mobile Endpoint app This guide provides step-by-step instructions for silently installing Infoblox Mobile Endpoint on iOS and Android devices that use MaaS 360.using IBM MaaS 360. The process includes downloading configuration files, registering devices, installing the Infoblox app, and configuring silent DNS proxy authorization.

Important Notes

  • Proxy Mode Warning: The proxy mode feature has not been tested and may not function correctly.

  • Authorization Changes:

    • Infoblox Endpoint iOS version 2.0.7 and above uses joinToken instead of customerId for authorization.

    • Infoblox Endpoint Android version 1.0.10 and above replaces customerId with joinToken for authorization.

    • The customerId attribute will be removed in future app versions. Until all devices are updated to version 1.0.10 or later, you may need to maintain both customerId and joinToken in the app configuration.

Step 1: Download the

...

MDM Configuration File from the

...

Infoblox Portal

An app-config file is required to update an the app’s configuration in MDM. To download the file, do the following:

  1. Log

...

  1. into the Infoblox Portal.

  2. Navigate to Configure > Security > Endpoints > Endpoint Groups.

...

  1. Click Download MDM Configuration,

...

  1. then select iOS Config File

...

  1. or Android Config File, depending on the device.

...

...

  1. Image Added

Image Removed 

  1. To assign an endpoint

...

  1. to a specific endpoint group

...

  1. :

    • Click the three horizontal bars icon next to the endpoint group name.

    • Select Download MDM Configuration

...

    • > Android Config File or iOS Config File

...

Image 2
Image Removed

...

    • .

    Image Added

  1. Save the downloaded

...

  1. configuration file to

...

  1. an easily accessible directory.

App Config File Parameters

The downloaded MDM configuration file contains the following parameters:

  • customerId: The

    joinToken – The value in the XML file, required for authentication.

  • groupName

    : In the Cloud Services Portal, the name of the

    – The Infoblox Portal group to which the endpoint

    is to

    will be

    moved

    assigned. If the

    name is not present in the Cloud Services Portal, then add it to the All BloxOne Endpoints group before installing the app-config file.userId: The

    group does not exist, the endpoint will be added to All Infoblox Endpoints.

  • userId – A unique name that identifies

    the

    a mobile device

    . The configured name is

    , displayed in

    the Cloud Services Portal, on the Manage Endpoints page

    Infoblox Portal > Configure > Security > Endpoints.

  • allowServiceControl

    :

    By default, this value

    will be 

    is True. To

    disallow

    disable and hide service control,

    use the

    toggle

    switch to change

    this value

    to False.  

    to False.

  • extensionType (iOS only) – Defaults to "vpn", but can be set to "dnsproxy" to intercept DNS traffic via the DNS Proxy Provider.

Step 2: Register a Mobile Endpoint for Use with IBM MaaS 360

To register an endpoint device, follow the IBM MaaS 360 enrollment process:

  1. Log

...

  1. into the IBM MaaS 360 console

...

  1. .

  2. Follow the steps

...

  1. to register a device.

...

  1. For detailed enrollment instructions, refer to

...

  1. :

...

...

Step 3: Install the

...

Infoblox App Using IBM MaaS 360

Installation on an iOS Device

To install the BloxOne app on an iOS device, do the following: 

...

  1. Log into the IBM MaaS 360 console.

...

  1. Navigate to Apps

...

  1. > App Catalog.

...

  1. Click Add

...

  1. > iOS

...

  1. > iTunes App Store

...

  1. .

Image 3
Image Removed

4. Search for  BloxOne EP, and click Add to add it to your configuration: 

Image 4
Image Removed

...

  1. Image Added

  2. Search for Infoblox Endpoint, and click Add to include it in the app configuration.

    Image Added

  3. Select the devices and users to which

...

  1. the app will be distributed.

...

Installation on an Android Device

...

  1. Log

...

  1. into the IBM MaaS 360 console.

...

  1. Navigate to Apps

...

  1. > App Catalog.

...

  1. Click Add > Android > Google Play App

...

Image 5
Image Removed

...

  1. .

    Adding the Android application to the IBM MaaS 360 catalogue.Image Added

  2. On the Add Google Play

...

  1. App screen

...

  1. , search for Infoblox Endpoint, and click Add.

...

  1. Select Infoblox Android app from

...

  1. the

...

  1. list.

...

  1. Click Select > Approve > Add to include the app in the catalog.

  2. Click Distribute to assign the app to specific users.

    Image Added

Step 4: Add the App

...

Configuration for the

...

Infoblox iOS App

To add an app config configuration for a BloxOne iOS device, do the followingiOS devices:

...

  1. Navigate to Apps

...

  1. > App Configuration.

...

  1. Click Add Configuration

...

  1. .

Image 7

Image Removed

...

  1. Image Added

  2. Enter a configuration name,

...

  1. then select the iOS app from the app catalog

...

  1. .

Image 8 
Image Removed

...

  1.  Adding the iOS configurationImage Added
  2. Click Next to proceed to the Configuration screen.

...

  1. Select Manual Configuration,

...

  1. then upload the previously downloaded config file

...

  1. from the

...

  1. Infoblox Portal.

6. The app config with the editable groupName and userId attribute fields should appear: 

Image 9
Image Removed 

...

  1. The app configuration fields for groupName and userId will be displayed.

  2. Click Next to continue to the iOS Distribution screen.

...

  1. Adding groupName ansd userID manually to the configuration.Image Added


  2. Click Publish to publish and distribute the configuration

...

  1. .

...

  1. Publishing the configuration.Image Added

...

After a few minutes,

...

 Infoblox Endpoint will be automatically installed on the client devices. 

Step 5: Perform

...

Silent Authorization of DNS Proxy Permissions

...

(iOS Only)

  1. Log

...

  1. into the IBM MaaS 360 console.

...

  1. Navigate to Security

...

  1. > Policy Management

...

  1. > Policies.

  2. Select an iOS policy to

...

  1. apply.

...

  1. Navigate to iOS Policy

...

  1. > Supervised Settings

...

  1. > DNS Proxy,

...

Image 11
Image Removed 

5. Select an  iOS policy to be pushed to iOS devices.
6. Go to iOS PolicySupervised SettingsDNS Proxy, and click Edit
7. In the Edit panel, do the following:

...

  1. and click Edit.

    Image Added

  2. In the Edit panel, enter the following values:

    • App Bundle ID: com.infoblox.atc.b1dnsproxy

...

...

    • Provider Bundle

...

    • ID: com.infoblox.atc.b1dnsproxy.dnsproxy

...


Image 12
Image Removed

8. At the end of the configuration process, click Confirm Publish:

Image 13
Image Removed

...

  1. Image Added

  2. Click Confirm Publish to finalize the configuration.

    Publishing the configuration.Image Added
  3. Navigate to Devices > Inventory, select a device, and click More > Request Data Refresh.

  4. Infoblox Endpoint will be automatically installed on the client devices.

...

Image 14
Image Removed

13. Open the BloxOne EP app on your device; on Android devices, find the app in the Work Profile. If prompted, accept the DNS Proxy acknowledgement. After a moment, the app will be in a protected state:

...

  1. Image Added

  2. Open the Infoblox Endpoint app on an iOS device. The app will display its protected state.

    The Infoblox Endpoint app displaying its protected status on an iOS device.Image Added


Step 6: Add

...

the App

...

Configuration for the

...

Infoblox Android

...

App

To add an app config for a BloxOne iOS device, do the following: 

...

configuration for Android devices:

  1. Navigate to Apps > App Configuration.

...

  1. Click Add Configuration

...

  1. .

    Image Added


    Image

...

  1. : Adding the Android app configuration in IBM MaaS 360.

  2. Enter a configuration name,

...

  1. then select the Android app from the app catalog

...

  1. .

Image 17
Image Removed

...

  1. Image Added
  2. Click Next to proceed to the Configuration screen.

...

  1. Upload the previously downloaded config file

...

  1. from the

...

Image 18
Image Removed

...

  1. Infoblox Portal.

...

  1. The app configuration fields for groupName and userId will be displayed.

    Image Added
  2. Click Next > Publish to finalize the configuration.

  3. Infoblox Endpoint will be automatically installed on the client devices

...

  1. .

...

  1. Open the Infoblox Endpoint app on an Android device. If prompted, accept the VPN acknowledgement. The app will display its protected state.

    The Infoblox Endpoint app displaying its protected status on an Android device.Image Added