This screen allows you to configure the Connect on Demand functionality provided by Apple iOS. You can create lists of rules that will be checked whenever other applications initiate network connections that are resolved using the Domain Name System (DNS). These rules consist of lists of host names (host.example.com), domains (.example.com), or partial domains (.internal.example.com), but cannot include IP addresses (10.0.0.1). When matched, these rules specify one of the three following Connect On Demand behaviors:

Always Connect

iOS will always attempt to initiate a VPN connection when rules in this list are matched.

Never Connect

iOS will never attempt to initiate a VPN connection when rules in this list are matched. Any rules in this list will take precedence over the rules in the other two lists.

When Connect On Demand is enabled, the application automatically adds the server address to this list. This prevents a VPN connection from being automatically established if you try accessing the server's clientless portal with a web browser. This rule can be removed if you do not want this behavior.

Connect if Needed

iOS will attempt to initiate a VPN connection when rules in this list are matched only if the system could not resolve the address using DNS.