

A major objective of the on demand aspect of the VPN capability is to have the a VPN connection automatically created whenever the iOS device is either only on a cellular network or on a WiFi network that's not ours (i.e., so the above requirement is automatically fulfilled).This gives our mobile devices the benefit of some site filters provided by our firewall appliance (another 'how to' I have planned).All unencrypted (and normall SSL browsing, etc.) traffic emanates only from our LAN through our network's (land-based/hard-wired) router.

All the iOS device's traffic goes through our network and is encrypted while doing so - so the cellular data and WiFi parts of the device's traffic can't be monitored.One of the primary objectives was to document a setup where the VPN-connected iOS device routes all the device's traffic through our network – i.e.:.setting up a managed iOS device with VPN 'on demand' capabilities (for both IPSec and OpenVPN).The complete set of instructions include: See Setting Up an iOS 7 On-Demand VPN for the details (it's way too much stuff to post via MacOSXHints, as much as I've been a fan of this site for many years). I'm writing a detailed set of instructions for getting VPN 'on-demand' working with iOS 7.
