Skip to content

Commit c2e6795

Browse files
authored
Merge pull request #7963 from Brenduns/9295335-disable-udp-for-tunnel
2207 oob - 8/3/2022 - 9295335, disable UDP for Microsoft Tunnel
2 parents 71a1487 + 4317df2 commit c2e6795

3 files changed

Lines changed: 27 additions & 18 deletions

File tree

memdocs/intune/fundamentals/in-development.md

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -263,11 +263,6 @@ Applies to:
263263

264264
## Device security
265265

266-
### Disable use of UDP connections on your Microsoft Tunnel Gateway servers<!-- 9295335 -->
267-
You’ll soon be able to configure your Microsoft Tunnel Servers to disable use of UDP. When you disable use of UDP, the VPN server supports only TCP connections from tunnel clients. To support use of only TCP connections, your devices must use the generally available version of [Microsoft Defender for Endpoint as the Microsoft Tunnel client app](../protect/microsoft-tunnel-migrate-app.md) as the tunnel client app.
268-
269-
You’ll be able to disable UDP when creating or editing a *Server configuration* for Microsoft Tunnel Gateway. The Server configuration will support a new option named **Disable UDP Connections** that will be available for the *Server port* field. [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) > **Tenant Administration** > **Microsoft Tunnel Gateway** > **Server configurations**.
270-
271266
### Reusable groups of settings for Microsoft Defender Firewall Rules<!-- 5653346, 6009514 -->
272267

273268
You’ll soon be able to add reusable groups of settings to your profiles for Microsoft Defender Firewall Rules. The reusable groups are collections of remote IP addresses and FQDNs that you define one time and can then use with one or more firewall rule profiles. You’ll no longer need to reconfigure the same group of IP addresses in each individual profile that might require them.

memdocs/intune/fundamentals/whats-new.md

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: Erikre
88
ms.author: erikre
99
manager: dougeby
10-
ms.date: 07/27/2022
10+
ms.date: 08/03/2022
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: fundamentals
@@ -62,6 +62,14 @@ You can use RSS to be notified when this page is updated. For more information,
6262

6363
## Week of August 1, 2022
6464

65+
### Device security
66+
67+
#### Disable use of UDP connections on your Microsoft Tunnel Gateway servers<!-- 9295335 -->
68+
69+
You can now disable the use of UDP by your Microsoft Tunnel Servers. When you disable use of UDP, the VPN server supports only TCP connections from tunnel clients. To support use of only TCP connections, your devices must use the generally available version of [Microsoft Defender for Endpoint as the Microsoft Tunnel client app](../protect/microsoft-tunnel-migrate-app.md) as the tunnel client app.
70+
71+
To disable UDP, [create or edit a *Server configuration* for Microsoft Tunnel Gateway](../protect/microsoft-tunnel-configure.md#create-a-server-configuration) and select the checkbox for the new option named **Disable UDP Connections**.
72+
6573
### App management
6674

6775
#### Company Portal for Windows bulk app install<!-- 6401437 -->

memdocs/intune/protect/microsoft-tunnel-configure.md

Lines changed: 18 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ keywords:
55
author: brenduns
66
ms.author: brenduns
77
manager: dougeby
8-
ms.date: 07/05/2022
8+
ms.date: 08/03/2022
99
ms.topic: how-to
1010
ms.service: microsoft-intune
1111
ms.subservice: protect
@@ -49,17 +49,23 @@ Use of a *Server configuration* lets you create a configuration a single time an
4949
- If the client IP address range conflicts with the destination, it will loopback and fail to communicate with the corporate network.
5050
- You can select any client IP address range you want to use if it doesn't conflict with your corporate network IP address ranges.
5151

52+
- **Server port**: Enter the port that the server listens to for connections.
53+
5254
- **DNS servers**: These servers are used when a DNS request comes from a device that's connected to Tunnel Gateway.
5355

5456
- **DNS suffix search** *(optional)*: This domain is provided to clients as the default domain when they connect to Tunnel Gateway.
5557

56-
- **Split tunneling** *(optional)*: Include or exclude addresses. Included addresses are routed to Tunnel Gateway. Excluded addresses aren’t routed to Tunnel Gateway. For example, you might configure an include rule for *255.255.0.0* or *192.168.0.0/16*.
58+
- **Disable UDP Connections** *(optional)*: When selected, clients only connect to the VPN server using TCP connections. Because the standalone tunnel client requires use of UDP, only select the checkbox to disable UDP connections after you’ve configured your devices to use Microsoft Defender for Endpoint as the tunnel client app.
5759

58-
Split tunneling supports a total of 500 rules between both include and exclude rules. For example, if you configure 300 include rules, you can only have 200 exclude rules.
60+
4. Also on the **Settings** tab, configure *Split tunneling rules*, which are optional.
5961

60-
- **Server port**: Enter the port that the server listens to for connections.
62+
You can include or exclude addresses. Included addresses are routed to Tunnel Gateway. Excluded addresses aren’t routed to Tunnel Gateway. For example, you might configure an include rule for *255.255.0.0* or *192.168.0.0/16*.
63+
64+
Use the following options to include or exclude addresses:
65+
- **IP ranges to include**
66+
- **IP ranges to exclude**
6167

62-
4. On the **Review + create** tab, review the configuration, and then select **Create** to save it.
68+
5. On the **Review + create** tab, review the configuration, and then select **Create** to save it.
6369

6470
## Create a Site
6571

@@ -191,13 +197,13 @@ To use the Microsoft Tunnel, devices need access to a Microsoft Tunnel client ap
191197
- **Microsoft Tunnel** client app - For iOS/iPadOS, download the **Microsoft Tunnel** client app from the Apple **App Store**. See Add iOS store apps to Microsoft Intune.
192198

193199
> [!Important]
194-
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
200+
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
201+
>
195202
> - On July 29, 2022, the standalone tunnel client app will no longer be available for download. Only the generally available version of *Microsoft Defender for Endpoint* will be available as the tunnel client app.
196203
> - On August 1, 2022, the *Microsoft Tunnel (standalone client) (preview)* connection type will cease to connect to Microsoft Tunnel.
197204
>
198205
> To avoid a disruption in service for Microsoft Tunnel, plan to migrate your use of the deprecated tunnel client app and connection type to those that are now generally available.
199206
200-
201207
For more information on deploying apps with Intune, see [Add apps to Microsoft Intune](../apps/apps-add.md).
202208

203209
## Create a VPN profile
@@ -218,14 +224,14 @@ After the Microsoft Tunnel installs and devices install the Microsoft Tunnel cli
218224
219225
- **iOS/iPadOS**:
220226

221-
222-
- **Microsoft Tunnel ** – Use this connection type with Microsoft Defender for Endpoint as the tunnel client app.
227+
- **Microsoft Tunnel** – Use this connection type with Microsoft Defender for Endpoint as the tunnel client app.
223228

224229
- **Microsoft Tunnel (standalone client) (preview)** – Use this connection type when you use the standalone Microsoft Tunnel client app. This connection type doesn’t support Microsoft Defender for Endpoint as the client Tunnel app.
225230

226231
> [!Important]
227-
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
228-
> - On July 29, 2022, the standalone tunnel client app will no longer be available for download. Only the generally available version of *Microsoft Defender for Endpoint* will be available as the tunnel client app.
232+
> **Plan for change**. On April 29, 2022 both the *Microsoft Tunnel* connection type and *Microsoft Defender for Endpoint* as the tunnel client app became generally available. With this general availability, the use of the *Microsoft Tunnel (standalone client)(preview)* connection type and the standalone tunnel client app are deprecated and soon will drop from support.
233+
>
234+
> - On July 29, 2022, the standalone tunnel client app will no longer be available for download. Only the generally available version of *Microsoft Defender for Endpoint* will be available as the tunnel client app.
229235
> - On August 1, 2022, the *Microsoft Tunnel (standalone client) (preview)* connection type will cease to connect to Microsoft Tunnel.
230236
>
231237
> To avoid a disruption in service for Microsoft Tunnel, plan to migrate your use of the deprecated tunnel client app and connection type to those that are now generally available.
@@ -253,7 +259,7 @@ After the Microsoft Tunnel installs and devices install the Microsoft Tunnel cli
253259
- Apps that are assigned in the per-app VPN profile send app traffic to the tunnel.
254260
- On Android, launching an app won't launch the per-app VPN. However, when the VPN has *Always-on VPN* set to *Enable*, the VPN will already be connected and app traffic will use the active VPN. If the VPN isn't set to be *Always-on*, the user must manually start the VPN before it can be used.
255261
- If you're using the Defender for Endpoint app to connect to Tunnel, have web protection enabled, and are using per-app VPN, web protection will only apply to the apps in the per-app VPN list. On devices with a work profile, in this scenario we recommend adding all web browsers in the work profile to the per-app VPN list to ensure all work profile web traffic is protected.
256-
- To enable a per-app VPN, select **Add** and then browse to custom or public apps you’ve imported to Intune.
262+
- To enable a per-app VPN, select **Add** and then browse to the custom or public apps you’ve imported to Intune.
257263

258264
- **Always-on VPN**:
259265
- For *Always-on VPN*, select *Enable* to set the VPN client to automatically connect and reconnect to the VPN. Always-on VPN connections stay connected. If *Per-app VPN* is set to *Enable*, only the traffic from apps you select go through the tunnel.

0 commit comments

Comments
 (0)