fighting for truth, justice, and a kick-butt lotus notes experience.

Get prepared - Apple will change with iOS 6.1 VPN On Demand functionality

 April 12 2013 04:28:33 PM
Falls jemand unter Apple iOS VPN-Zugriff mit der Option On Demand - Always verwendet, ist in den kommenden Wochen Vorsicht geboten.

Bedingt durch eine durch Apple verlorene Patentklage, muss Apple die "VPN On Demand"-Option mit dem nächsten iOS Update 6.1 deaktivieren bzw. deren Verhalten ändern.

Mit iOS 6.1 ist relativ schnell in den nächsten Tagen zu rechnen.
Daher sollte jeder der iOS-Devices mit eingerichtetem VPN-Zugang verwendet, prüfen ob er auch hiervon betroffen ist und sich vorbereiten.

Apple beschreibt in einem öffentlichen Supportdokument bereits die zu erwartenden Probleme:



Symptoms

Due to a lawsuit by VirnetX, Apple will be changing the behavior of VPN On Demand for iOS devices using iOS 6.1 and later.

Devices using iOS 6.1 and later with VPN On Demand configured to "Always" will behave as if they were configured with the "Establish if needed" option. The device will establish a VPN On Demand connection only if it is unable to resolve the DNS name of the host it is trying to reach. This change will be distributed in an update later this month.

If the name of a host can be resolved without a VPN connection, you may see one of the following behaviors:

        ▪        If the host is a web server that presents different content to internal and external users, the VPN On Demand connection will not be established and you will see the external content.
       ▪        If the host is a web or mail server that has a name that can be resolved externally but cannot be contacted externally, the VPN On Demand connection will not be established and you will not be able to connect to the server.
       ▪        If you are using a public DNS service that provides an alternative IP address for hosts that it cannot resolve, the VPN On Demand connection will not be established and you will not be able to connect to the server.
       ▪        If you are using a VPN configuration that includes wildcard entries (such as *.com) that match top-level domains that are publicly accessible, the VPN On Demand connection will not be established when you contact hosts in those domains.
 

Resolution

To establish a VPN connection, turn on VPN manually in Settings > General > VPN.

Apple will address this functionality with alternatives in a future software update.

Additional Information

If you are currently using the "Always" option for VPN On Demand, you can see how this change will work before it takes effect by creating a new VPN configuration that uses the "Establish if needed" option for the same set of domains.

Quelle: support.apple.com

Archive