Transit IT wants every packet on a rider-information tablet to enter the civic LAN through always-on IPsec. Why is Workspace ONE Tunnel the wrong product for that goal?
Select an answer to reveal the explanation.
Short Explanation
Tunnel is a named-app pass, not a whole-tablet on-ramp. Always-on IPsec for every process is a different VPN story, and Horizon Client or Content lockers are not why Tunnel is wrong here. The exam definition of Tunnel is managed-app traffic, not a full-device network extension.
Full Explanation
Workspace ONE Tunnel provides application-scoped access for managed Workspace ONE apps rather than extending the entire device onto the civic LAN. A device-wide always-on IPsec design is therefore outside Tunnel's exam purpose. Tunnel does not replace Horizon Client, wrap Blast Extreme, or act as Workspace ONE Content. Associates should reject Tunnel when the stated goal is every packet from every process.