iOS VPN On Demand: Only outside company

Viewed 2618

I was reading about the VPN On Demand feature built on the latest versions of iOS.

The problem here is: We run a VPN to access a WebApp hosted in-house on a subdomain like salexxx.company.net that has an A record to an internal IP of your network (eg. 172.20.1.100). In order for someone to access the WebApp he needs to be a) connected to our network directly, or b) connected to the VPN.

We've zero interest in having every request coming from user devices going through the VPN (way much traffic). iOS VPN On Demand seems to solve the issue, however when I'm at the company office and try to access the domain the phone also fires the VPN... Causing unnecessary redundancy on the network.

  • Is it possible to tell the devices to only connect to the VPN if they're outside of the company network?

Thank you.

2 Answers

Another alternative is to use a URLStringProbe

This uses a standard https get to determine whether or not you're already on your companies' network

            <key>OnDemandRules</key>
            <array>
                <dict>
                    <key>Action</key>
                    <string>Ignore</string>
                    <key>URLStringProbe</key>
                    <string>https://intwebsite.yourcompany.com</string>
                </dict>
            </array>

It's worth pointing out that the server you quote should be available with NO redirects, and should return a 200. https is preferred, but you can use http also.

From Apple's MDM Technical reference:

URLStringProbe. Optional. A server to probe for reachability. Redirection is not supported. The URL should be to a trusted HTTPS server. The device sends a GET request to verify that the server is reachable.

Apple MDM Technical reference

Related