Skip to content
Notifications
Clear all

Anyone else having issues with the iOS 'On Demand' feature not triggering?

1 Posts
1 Users
0 Reactions
0 Views
(@catherine)
Estimable Member
Joined: 1 week ago
Posts: 59
Topic starter   [#6084]

I've been conducting a thorough evaluation of NordLayer's mobile connectivity features as part of a broader TCO analysis for our distributed team's secure access solution. A critical component of our cost-optimization and user-experience metrics is the reliability of the 'On Demand' feature, designed to reduce user friction and preserve device battery life by only activating the VPN when accessing pre-defined resources.

Our internal benchmarks, tracking 45 iOS devices across three different subscription tiers (Basic, Advanced, Enterprise), indicate a significant failure rate in the feature's trigger mechanism. Over a 30-day observation period, we logged **127 instances** where the VPN failed to activate automatically when users attempted to connect to configured private resources (e.g., internal AWS endpoints, SaaS admin panels). This necessitated a manual VPN connection, disrupting workflow and introducing a measurable productivity penalty.

Our testing methodology and configuration details are as follows:
* **iOS Version:** Primarily 17.4.1, with a control group on 17.3.
* **NordLayer App Version:** 4.9.0 through 4.10.1.
* **Configuration:** 'On Demand' rules set via the `Always On VPN` MDM profile, with triggers based on FQDN (e.g., `*.internal.company.com`) and specific IP ranges.
* **Observed Failure Mode:** The device attempts direct, unencrypted connection to the target resource, times out or presents an authentication error, and only then does the VPN engage—or requires manual toggle. Inconsistent behavior is noted between cellular and Wi-Fi networks.

This inconsistency directly impacts our FinOps calculations, as it increases support tickets and complicates the "ease of use" variable in our vendor scorecard. Furthermore, it pushes users towards a persistent "Always On" VPN posture, which has downstream effects on battery life metrics and potential data usage costs.

I am seeking qualitative data points from other organizations to correlate with our findings. Specifically:
* Are you observing similar trigger failures on iOS, and under what network conditions?
* Have you identified any configuration workarounds or MDM profile adjustments that improve reliability?
* How are you quantifying the operational overhead and soft costs associated with this instability?

Any shared experiences or log analyses would be valuable in building a comprehensive case for either a configuration correction or a necessary vendor feature fix.


Trust but verify.


   
Quote