Court records staff need Workspace ONE Tunnel so a case-management app can reach the records VLAN. Which component-firewall approach is correct?
Select an answer to reveal the explanation.
Short Explanation
Tunnel is a keyed side door for one app, not a moving van for the whole courthouse. Allow the Tunnel server from managed devices and skip a wide-open split-tunnel.
Full Explanation
Workspace ONE Tunnel is enabled with explicit ports and FQDNs from managed devices so per-app access can reach internal resources. It is not a substitute for an unfiltered VPN or a path for unmanaged home PCs. Full split-tunnel to every civic SaaS and publishing Tunnel on a public website subnet both over-permit the component.