On iOS devices, client certificate authentication and “Always-on” VPN configuration" is created with one configuration profile and distributed through MDM.
The Cato Client app is also purchased through Volume Purchasing and distributed through MDM.
https://support.catonetworks.com/hc/en-us/articles/360016152418-Distributing-Device-Certificates-to-macOS-and-iOS-Devices-with-Jamf
Our user's Cato Client authenticates using the Registration code.
Although Cato recommends against creating multiple VPN configurations, once the user authenticates with the Registration code, a second configuration profile "Cato Networks VPN" is automatically created by Cato Client.
The problem with this is that users can manually turn off the VPN switch.
I can manually delete the second profile, but it will be re-created after a while.
This issue is fundamental to the Always-on feature and is so serious that organizations are starting to talk about discontinuing their use of Cato.
Does anyone know of a good solution to this problem?
shiva
