Supervised iOS9, HTTP proxy, always-on VPN, anyone please?

New Contributor

Supervised iOS9 devices, Squid as HTTP proxy, StrongSwan server for VPN ikev2, Apple Configurator, OS X 10.11 server for profile management.

Small SOHO family business, less than 20 iOS devices, inside LAN and on the road.
Need to force certain DNS servers onto them.
Would like to have devices use our proxy server.

Idea is to use always-on VPN to connect to our LAN, StrongSwan will assign dedicated DNS server for devices.
Then to utilize Global HTTP proxy payload to force all traffic thru our proxy server.

Unfortunately, all elements work ok for themselves, but not together in one scenario.

Anybody able to point us to a solution which fulfills our requirements? Thanks a lot!