Generally, if your goal is to enforce the VPN on an iPhone or iPad, it's much more effective to enable Remote Supervision instead. Remote Supervision makes it much easier to manage VPNs for a few key reasons:
- Remote supervision is seamless, and configs sync automatically
- It's not possible to delete or disable the VPN that is enforced via remote supervision
However, it's still possible to enforce the VPN using manual configs, but if you try this with a single config, you'll likely see this error on the Config Generator:
You can proceed to install this config file to your iPhone, but if you ever need to update it later, that config needs to be removed first; otherwise, you will see an error like the one below when you try to sync the config:
Here's how to get around the error:
- Unlock your Tech Lockdown profile
- On your current config, deselect everything under VPN Protection.
The Config Generator should look like this (note that Cloudflare VPN is not enforced and New VPNs are allowed):
- Re-sync your existing config to your iPhone
- Create a new config and assign it to yourself (or whoever the device is going to be associated with)
This new config is going to be used to enforce Cloudflare's VPN, so you may want to enter its name accordingly.
- On your new config, enforce the Cloudflare VPN
That new config should look like this under VPN Protection. Note the new error:
- Sync the new config to your iPhone
- On your iPhone, force close and reopen the Cloudflare One app (see https://support.apple.com/en-us/109359 for details)
The Cloudflare VPN should now be locked onto a version of the config that can't be deleted. Finish up:
- On your main config, toggle on Restrict New VPNs.
- Sync your main config to your iPhone again.
- Lock your Tech Lockdown Profile again.
Your main config should look like this under the VPN Protection section:
How do I Remove the Cloudflare VPN Later?
Use these instructions:
- Unlock your Tech Lockdown profile
- First, uninstall your main config
- Uninstall the VPN config
If you try to uninstall the configs in the wrong order, you will get this error message: