NetworkExtension connectOnDemand规则不起作用

时间:2016-04-07 13:55:50

标签: ios objective-c swift vpn networkextension

我有一个由新的NetworkExtension框架创建的VPN配置的应用程序。它运行得很好,但现在我需要添加一些规则才能在我尝试连接到特定URL时转换此VPN。我计划使用NEVPNManager的connectOnDemand功能,但它似乎对我有用。当我在safari中打开http://some-site.com时,我的VPN连接应该建立,但由于某种原因它确实没有。我尝试了不同类型的配置以及使用生成的.mobileconfig文件来使connectOnDemand工作,但没有运气。它出什么问题了? 我正在对这样的代码进行测试:

let manager = NEVPNManager.sharedManager()

manager.enabled = true

manager.loadFromPreferencesWithCompletionHandler { (err) -> Void in
    manager.removeFromPreferencesWithCompletionHandler { (err0) -> Void in
                print("err0 \(err0)")
                print("err \(err)")
                let config = NEVPNProtocolIPSec()
                config.localIdentifier = "NEVPNProtocolIPSec"
                config.remoteIdentifier = "NEVPNProtocolIPSecRemote"
                config.disconnectOnSleep = true
                config.serverAddress = server
                config.authenticationMethod = .Certificate
                //configurating here
                manager.protocolConfiguration = config
                let onDemandRule1 = NEOnDemandRuleConnect()
                onDemandRule1.DNSSearchDomainMatch = ["some-site.com", "*.some-site.com"]

                manager.onDemandRules = [onDemandRule1]
                manager.onDemandEnabled = true
                manager.saveToPreferencesWithCompletionHandler({ (err2) -> Void in
                    print("err2 \(err2)")
                })
            }
        }

2 个答案:

答案 0 :(得分:6)

我使用了下一条规则:

let onDemandRule = NEOnDemandRuleEvaluateConnection()
let evaluateRule = NEEvaluateConnectionRule(matchDomains: ["*.some-site.com"], andAction: .ConnectIfNeeded)
evaluateRule.probeURL = NSURL(string: "https://a.url.accecable.only.from.vpn")

onDemandRule.connectionRules = [evaluateRule]
manager.protocolConfiguration = config
manager.onDemandRules = [onDemandRule]

答案 1 :(得分:0)

您需要添加

manager.onDemandEnabled = true