VMware Tunnel (Per-App VPN) is configured with basic settings in the Workspace ONE UEM console.

The Tunnel server hostname configured in the Workspace ONE UEM console for VMware Tunnel (Per-App VPN) settings resolves to the floating IP address configured for HA in Unified Access Gateway. The connections on this floating IP address are distributed among the configured nodes on Unified Access Gateway.

Figure 1. VMware Tunnel (Per-App VPN) Connection with Basic Configuration

Mode and Affinity: Least connections algorithm is used for HA and load distribution. A new request is sent to the server with the fewest number of current connections to clients. Session affinity is not required as they are stateless connections.