Access to LAN when using Always-on VPN

With iOS devices using an Always-on VPN there is no way for apps to access resources on their local network.

If I exempt an app to allow traffic outside the VPN tunnel, then it does not use the VPN tunnel at all.


What I would like to be able to do is to allow an app to access to the local network but still use the Always-on VPN as it's default route.


Has anyone figured out a way to make something like this work?

Posted on Apr 13, 2021 9:55 AM

Reply
9 replies

Apr 13, 2021 10:21 AM in response to KiltedTim

I see your point for the majority of cases. It wouldn't be an issue really if iOS would actually route all traffic over the VPN, but it does not route the subnet your phone is connected to. For example if you're connected to wi-fi that is using 192.168.1.0/24 that subnet is dead. The phone won't route it over the VPN and also won't allow access to it directly.

Apr 13, 2021 10:58 AM in response to Artooro

Artooro wrote:

We have all the outside tunnel options turned on, for Air Print, Voicemail, Cellular Services.


If you’re on the current VPN client version, escalate a support request to the VPN provider for assistance establishing whatever particular local network access is required here, then.


VPN debugging can be “fun” with access to the VPN client and VPN server, and a switch port mirrored into packet capture.


Remotely debugging an unknown VPN (not) connecting to an unknown local service through forum postings...

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Access to LAN when using Always-on VPN

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.