Guides
ProductDeveloperPartnerPersonal

Cisco Meraki MDM

For Meraki administrators, once you have deployed the Cisco Secure Client, use the Meraki dashboard to deploy the app to devices. After the endpoints register with Umbrella, Umbrella lists the devices in the dashboard. For information about how to configure and enroll an Android device, see Meraki documentation.

Table of Contents

Prerequisites

  • An Android Enterprise compatible device deployment. The legacy Device Admin (DA) system is not supported at this time.
  • Android mobile devices running Android OS version 6.0.1 and above. Devices examples are Samsung, Google, and Motorola. FireOS devices and other Android forks are not supported.
  • An MDM for deploying the software; in this case, Meraki.
  • Access to an Umbrella subscription including mobile device coverage.
  • A network meeting access requirements.
    • Access over UDP 53 and UDP 443 to 208.67.222.222 from the device.
  • For on-network scenarios, Trusted Network Detection (TND) may also be used to disable the client on network and pass traffic to a Virtual Appliance. The following prerequisites apply:
    • All VAs in use are defined by FQDN (IPs entered will not allow the client to go into trusted network mode) in the umbrella_va_fqdns configuration property.
      • The format for this field is comma separated, for example, (va1.domain.com, va2.domain.com)
    • VAs must be registered to the same Umbrella organization as the Android devices.
    • HTTPS mode for user events enabled on the Virtual Appliance.
      • If the VA’s FQDN is not publicly signed, the self-signed root certificate for the VA domain used for HTTPS mode on the VA must also be pushed to the Android device to sign the connection.
      • VA certificates should contain Subject Alternate Name (SAN) matching the VA’s configured domain to successfully communicate with the VA over HTTPS mode.
      • For more information on how to configure HTTPS mode on the VA, see Umbrella Virtual Appliance: Receiving User-IP mappings Over a Secure Channel.

Add App to Cisco Meraki

This process needs to be done only once.

  1. In Meraki, navigate to System Manager > Apps > Add Apps > Add New Android App.
1600
  1. Search for AnyConnect or for the bundle id com.cisco.anyconnect.vpn.android.avf.
512
  1. Select the app and approve the permissions, then click Approve. If the app has been previously approved, simply re-approve it.
1478

Add Configuration for App

  1. Navigate to System Manager > Settings and click Add Profile.
  2. Select Device Profile (default) from the pop-up, then click Continue.
1214
  1. Name the profile.
1600
  1. Click Add Settings.
  2. Select the Android device type, then search for Managed App Config.
3410
  1. Choose Android from the Platform menu, then choose AnyConnect from the App menu.
  2. Click +.
1600
  1. Choose umbrella_org_id from the menu, and enter your org ID value. (Refer to the orgId property in the mobileconfigAndroid.json file.)
  2. Click +. Choose umbrella_reg_token from the menu and enter the value. (Refer to the regToken property in the mobileconfigAndroid.json file.)
  3. Click +. Choose umbrella_va_fqdns from the menu and enter the value. For example, va1.yourdomain.com.
1600
  1. Click Add Settings, then search for Certificate. Click to select the result.
  2. Name the certificate, then click Choose File.
1600
  1. In the popup window, select the Umbrella root CA file you downloaded from the Umbrella dashboard. For example, https://dashboard.umbrella.com/o/<*YOUR-ORG-ID*>/#/deployments/configuration/rootcertificate.
  2. Click Save.
  3. Upload the CA certificate, then click Save.
  4. Navigate to Profile Configuration and deploy the configuration to one or more Android devices.
  5. Click Save.

Push the App to Devices

Multiple Device Push

  1. Open Systems Manager > Apps.
  2. Select AnyConnect > Push, then push the app to the desired devices.
  3. Click Save.
1600

Single Device Push

  1. Open Systems Manager > Apps.
  2. Select AnyConnect, then scroll to the device list.
  3. Select a specific device, then click Push.
  4. Click Save.
512

Push the Umbrella Certificate

For information, see Push the Umbrella Certificate to Devices.

Manage Pop-Ups and App Controls

For information about configuring the client's deployment options, see Manage Pop-Ups and App Controls.


Android Configuration Download < Cisco Meraki MDM > MobileIron MDM