What the VPN profile on iPhone actually configures
iOS doesn't let ordinary apps take over network traffic directly. Any client that can route traffic off an iPhone has to register a VPN configuration through the system's NetworkExtension framework, and iOS itself builds and maintains that tunnel. Two consequences follow: the authorization prompt on the first connection is unavoidable — it isn't the client asking for extra permissions, it's iOS confirming with you; and once the tunnel is up the system keeps it running, so sending the app to the background or even having it reclaimed won't drop an established connection.
There are two common ways to configure a VPN on an iPhone, and the difference is bigger than you'd expect:
| Aspect | Manual setup in iOS Settings | Subscription import in a client |
|---|---|---|
| What you need | Server address, account and key, typed in by hand | A single subscription link |
| Changing servers | Go back into Settings and edit the configuration | One tap in the client's list |
| Split tunneling | No domain-based routing | Routed by the rule set delivered with the subscription |
| DNS | Follows the system | Can be set separately, with lookups going through the server |
| Server updates | Edit the configuration by hand | Refreshed by updating the subscription |
| Best for | One fixed server, occasional use | Many servers, switching by scenario |
For everyday use, go with the second option: a single subscription link carries the server list, split-tunneling rules and DNS settings, and when servers change you just tap Update Subscription once in the client to sync.
VPN-LG subscriptions cover 120+ countries and regions across 190+ servers. Changing servers needs no reconfiguration — just tap one in the client's list.
Getting the client: what to check in the App Store
There are more options in the App Store than you'd think. Follow these four steps and you'll rarely install the wrong one:
- Search for the client's name, then check that the developer name and icon match the official site. There are plenty of apps with the same or a similar name, and installing the wrong one throws off every step after it.
- Look at two things: the minimum iOS version required and the date of the last update. A client that hasn't been updated in a long time is more likely to hit compatibility problems on a new version of iOS.
- If you can't find the listing, check which region your Apple ID is registered in. Some clients are only published in certain storefronts — switching regions will surface them, which doesn't mean the app was pulled.
- Once it's installed, don't rush to connect. Open it and check whether it supports Subscription import — that's the prerequisite for managing every server from a single link later on.
To judge whether an iOS client is worth using, check three things: can it import a subscription link, does it offer split-tunneling rules, and does it connect through the system network extension. That third one decides whether it can keep the connection alive after the screen locks.
Getting the subscription link: three things to confirm before you copy it
Sign in to the VPN-LG dashboard and copy the subscription link from the subscription section. Three details are worth noting:
- The subscription link is a string starting with https:// and it works like account credentials. Don't post it in group chats, and don't share it in a screenshot.
- Use Copy rather than retyping it. The parameters in the link are case-sensitive, and a single missing character will make the client report a format error.
- The same link can be reused: when you move to a new phone or reinstall the client, just copy it from the dashboard again and import it — no need to configure each device separately.
Importing the subscription: two methods and that authorization prompt
Once you have the subscription link, there are two ways to import it. Pick whichever your client supports:
Method one: add it inside the client. Open the client, find the Subscriptions (or Server Subscriptions) entry, create a new subscription, paste the link into the address field, save, then tap Update. The server list will refresh — this is the most compatible route.
Method two: tap the link for one-tap import. Tap the subscription link directly on the iPhone; if a client that handles the URL scheme is installed, iOS will ask which app to open it with, and the subscription address is filled in automatically once you pick one. If you have several clients installed, be careful to pick the right one.
After importing, tap any server to connect and iOS shows an authorization prompt: "Client Name" Would Like to Add VPN Configurations, with Allow and Don't Allow below it. Tap Allow, then confirm once more with Face ID or your passcode, and the connection is actually established.
This prompt only appears the first time you connect. If you tap Don't Allow by accident, connections will keep failing. To fix it: go to Settings → General → VPN & Device Management (on older versions of iOS this item is just called VPN), delete the leftover configuration that was created, then connect again from the client and the prompt will reappear.
Don't edit or delete a VPN configuration that's in use. When you switch clients, first complete a connection in the new client and confirm you can browse normally, then go back to Settings and delete the old configuration. Doing it in the opposite order can leave two configurations fighting over traffic.
Verifying it works: four checks, not just the connection icon
A VPN icon in the status bar and a Connected label on the client's home screen only prove the configuration exists — not that traffic is actually going through the server. Confirm all four of these:
- ✅ The client shows live upload/download counters. If the numbers sit still for a long time, the connection usually isn't really established.
- ✅ Open this service's network check page and confirm the exit IP's location matches the server you picked. The IP location is an answer from the outside, which makes it more trustworthy than the client's own status display.
- ✅ Open a service that isn't normally reachable from your network and see whether it loads. This step verifies the traffic path, not just configuration permissions.
- ✅ Check where DNS resolution happens: if the exit IP is abroad but lookups are still answered by a local DNS server, resolution isn't following the server and you have a DNS leak.
- ❌ Assuming you're done because the client icon is lit. After switching Wi-Fi networks the status display can lag, so the real path needs to be confirmed again.
- ❌ Treating a speed test as verification. Speed only reflects server quality, not where your traffic exits.
If any of the four doesn't line up, disconnect and reconnect once. If it still doesn't line up, troubleshoot in this order: is the subscription up to date → are the configuration permissions still there → has the split-tunneling mode been switched to Direct.
Pass criteria: the exit IP's location, the services you can open and the DNS resolution location all point to the same region — only then is the setup complete. If they don't match, disconnect and reconnect first, then check the subscription, permissions and split-tunneling mode in that order.
Split tunneling, DNS and on-demand connection
Split tunneling: rules for daily use, global for troubleshooting
Most iOS clients offer three modes:
- Global: all traffic goes through the server. The most direct way to get a baseline when troubleshooting.
- Rules: the rule set delivered with the subscription decides — domains that need the server go through it, everything else connects directly. Use this day to day: it saves bandwidth and keeps local services from taking a long detour.
- Direct: nothing goes through the server, equivalent to temporarily turning it off.
The rule set updates along with the subscription. After changing your subscription, remember to tap Update Subscription once in the client so the rules refresh.
DNS: resolution location should match where your traffic exits
Clients usually offer two DNS options: Follow System and Manual. If verification shows the exit IP abroad but lookups answered locally, switch DNS to a manually specified public resolver and make sure lookups go through the server too — that usually fixes it.
On-demand connection and background behavior
With On-Demand enabled, iOS establishes the connection automatically when you switch to cellular or join a new Wi-Fi network, so you don't have to tap connect each time. Turn it off and you'll connect manually every time.
Two common misconceptions are worth clearing up: locking the screen won't drop the connection, because the system — not the app — maintains the tunnel; and turning off Background App Refresh in the client doesn't affect an established connection, only how often data refreshes inside the app.
Won't connect on cellular
If it works on Wi-Fi but drops when you switch to cellular, first check whether the client's toggle is on under Settings → Cellular. iOS lets you restrict cellular data per app, and with that toggle off the client can't refresh subscriptions or update its server list.
FAQ
The server list is empty after importing the subscription — what now?
First check whether the link was copied in full — the most common cause is a few missing characters at the end, or a stray space pasted in. Once you're sure it's intact, tap Update Subscription once in the client. If it's still empty, copy the link from the dashboard again and retry.
It says Connected, but pages won't load?
Switch the split-tunneling mode to Global and try again. If Global works but Rules doesn't, the problem is in the rule set — updating the subscription fixes it. If neither mode works, check the DNS settings and the exit IP's location.
Got a new iPhone — do you have to set up the configuration again?
You'll need to import the subscription once more, following exactly the same steps as the first time. Accounts aren't tied to devices, there's no limit on the number of devices, and five devices can be online at once. Whether you delete the configuration on the old phone makes no difference.
Will it affect iCloud sync?
In Rules mode, Apple domains generally connect directly, so sync isn't affected. If you switch to Global and notice sync slowing down, switch back to Rules.
Do you need to re-import the subscription to change servers?
No. The server list comes from the subscription — just tap another server in the client to switch. You only need to re-import if the subscription link itself changes.
Summary: set it up once, then just two things
The whole process only needs hands-on work once: get the client, import the subscription, allow the configuration, verify the three indicators. After that, day-to-day use comes down to two actions — tap a server in the list when you need a different region, and tap Update Subscription once when servers change.
If you're stuck at a step, work backwards in order: does the client support subscription import → is the subscription link complete → was the VPN configuration allowed → do the exit IP and DNS point to the same region. One of those four will match your symptom.
The short version: install a client that supports subscription import, import the subscription, tap Allow in the system prompt, then confirm the server is live using three things: the exit IP, the services you can open, and the DNS resolution location.