Use the following enrollment process to silently install the BloxOne Mobile Endpoint app This guide provides step-by-step instructions for silently installing Infoblox Mobile Endpoint on iOS and Android devices that use MaaS 360.using IBM MaaS 360. The process includes downloading configuration files, registering devices, installing the Infoblox app, and configuring silent DNS proxy authorization.
Important Notes
Proxy Mode Warning: The proxy mode feature has not been tested and may not function correctly.
Authorization Changes:
Infoblox Endpoint iOS version 2.0.7 and above uses
joinToken
instead ofcustomerId
for authorization.Infoblox Endpoint Android version 1.0.10 and above replaces
customerId
withjoinToken
for authorization.The
customerId
attribute will be removed in future app versions. Until all devices are updated to version 1.0.10 or later, you may need to maintain bothcustomerId
andjoinToken
in the app configuration.
Step 1: Download the
...
MDM Configuration File from the
...
Infoblox Portal
An app-config file is required to update an the app’s configuration in MDM. To download the file, do the following:
Log
...
into the Infoblox Portal.
Navigate to Configure > Security > Endpoints > Endpoint Groups.
...
Click Download MDM Configuration,
...
then select iOS Config File
...
or Android Config File, depending on the device.
...
...
To assign an endpoint
...
to a specific endpoint group
...
:
Click the three horizontal bars icon next to the endpoint group name.
Select Download MDM Configuration
...
> Android Config File or iOS Config File
...
Image 2
...
.
Save the downloaded
...
configuration file to
...
an easily accessible directory.
App Config File Parameters
The downloaded MDM configuration file contains the following parameters:
- customerId: The
joinToken – The value in the XML file, required for authentication.
groupName
: In the Cloud Services Portal, the name of the– The Infoblox Portal group to which the endpoint
is towill be
movedassigned. If the
name is not present in the Cloud Services Portal, then add it to the All BloxOne Endpoints group before installing the app-config file.userId: Thegroup does not exist, the endpoint will be added to All Infoblox Endpoints.
userId – A unique name that identifies
thea mobile device
. The configured name is, displayed in
the Cloud Services Portal, on the Manage > Endpoints pageInfoblox Portal > Configure > Security > Endpoints.
allowServiceControl
:– By default, this value
will beis
disallowTrue
. Todisable and hide service control,
use thetoggle
switch to changethis value
to False.to
False
.extensionType (iOS only) – Defaults to
"vpn"
, but can be set to"dnsproxy"
to intercept DNS traffic via the DNS Proxy Provider.
Step 2: Register a Mobile Endpoint for Use with IBM MaaS 360
To register an endpoint device, follow the IBM MaaS 360 enrollment process:
Log
...
into the IBM MaaS 360 console
...
.
Follow the steps
...
to register a device.
...
For detailed enrollment instructions, refer to
...
:
...
...
Step 3: Install the
...
Infoblox App Using IBM MaaS 360
Installation on an iOS Device
To install the BloxOne app on an iOS device, do the following:
...
Log into the IBM MaaS 360 console.
...
Navigate to Apps
...
> App Catalog.
...
Click Add
...
> iOS
...
> iTunes App Store
...
.
Image 3
4. Search for BloxOne EP, and click Add to add it to your configuration:
Image 4
...
Search for Infoblox Endpoint, and click Add to include it in the app configuration.
Select the devices and users to which
...
the app will be distributed.
...
Installation on an Android Device
...
Log
...
into the IBM MaaS 360 console.
...
Navigate to Apps
...
> App Catalog.
...
Click Add > Android > Google Play App
...
Image 5
...
.
On the Add Google Play
...
App screen
...
, search for Infoblox Endpoint, and click Add.
...
Select Infoblox Android app from
...
the
...
list.
...
Click Select > Approve > Add to include the app in the catalog.
Click Distribute to assign the app to specific users.
Step 4: Add the App
...
Configuration for the
...
Infoblox iOS App
To add an app config configuration for a BloxOne iOS device, do the followingiOS devices:
...
Navigate to Apps
...
> App Configuration.
...
Click Add Configuration
...
.
Image 7
...
Enter a configuration name,
...
then select the iOS app from the app catalog
...
.
Image 8
...
Click Next to proceed to the Configuration screen.
...
Select Manual Configuration,
...
then upload the previously downloaded config file
...
from the
...
Infoblox Portal.
6. The app config with the editable groupName and userId attribute fields should appear:
Image 9
...
The app configuration fields for
groupName
anduserId
will be displayed.Click Next to continue to the iOS Distribution screen.
...
Click Publish to publish and distribute the configuration
...
.
...
...
After a few minutes,
...
Infoblox Endpoint will be automatically installed on the client devices.
Step 5: Perform
...
Silent Authorization of DNS Proxy Permissions
...
(iOS Only)
Log
...
into the IBM MaaS 360 console.
...
Navigate to Security
...
> Policy Management
...
> Policies.
Select an iOS policy to
...
apply.
...
Navigate to iOS Policy
...
> Supervised Settings
...
> DNS Proxy,
...
Image 11
5. Select an iOS policy to be pushed to iOS devices.
6. Go to iOS Policy> Supervised Settings> DNS Proxy, and click Edit.
7. In the Edit panel, do the following:
...
and click Edit.
In the Edit panel, enter the following values:
App Bundle ID:
com.infoblox.atc.b1dnsproxy
...
...
Provider Bundle
...
ID:
com.infoblox.atc.b1dnsproxy.dnsproxy
...
Image 12
8. At the end of the configuration process, click Confirm Publish:
Image 13
...
Click Confirm Publish to finalize the configuration.
Navigate to Devices > Inventory, select a device, and click More > Request Data Refresh.
Infoblox Endpoint will be automatically installed on the client devices.
...
Image 14
13. Open the BloxOne EP app on your device; on Android devices, find the app in the Work Profile. If prompted, accept the DNS Proxy acknowledgement. After a moment, the app will be in a protected state:
...
Open the Infoblox Endpoint app on an iOS device. The app will display its protected state.
Step 6: Add
...
the App
...
Configuration for the
...
Infoblox Android
...
App
To add an app config for a BloxOne iOS device, do the following:
...
configuration for Android devices:
Navigate to Apps > App Configuration.
...
Click Add Configuration
...
.
Image
...
: Adding the Android app configuration in IBM MaaS 360.
Enter a configuration name,
...
then select the Android app from the app catalog
...
.
Image 17
...
Click Next to proceed to the Configuration screen.
...
Upload the previously downloaded config file
...
from the
...
Image 18
...
Infoblox Portal.
...
The app configuration fields for
groupName
anduserId
will be displayed.Click Next > Publish to finalize the configuration.
Infoblox Endpoint will be automatically installed on the client devices
...
.
...
Open the Infoblox Endpoint app on an Android device. If prompted, accept the VPN acknowledgement. The app will display its protected state.