What the VPN profile on iPhone actually configures

iOS doesn't let ordinary apps take over network traffic directly. Any client that can route traffic off an iPhone has to register a VPN configuration through the system's NetworkExtension framework, and iOS itself builds and maintains that tunnel. Two consequences follow: the authorization prompt on the first connection is unavoidable — it isn't the client asking for extra permissions, it's iOS confirming with you; and once the tunnel is up the system keeps it running, so sending the app to the background or even having it reclaimed won't drop an established connection.

There are two common ways to configure a VPN on an iPhone, and the difference is bigger than you'd expect:

AspectManual setup in iOS SettingsSubscription import in a client
What you needServer address, account and key, typed in by handA single subscription link
Changing serversGo back into Settings and edit the configurationOne tap in the client's list
Split tunnelingNo domain-based routingRouted by the rule set delivered with the subscription
DNSFollows the systemCan be set separately, with lookups going through the server
Server updatesEdit the configuration by handRefreshed by updating the subscription
Best forOne fixed server, occasional useMany servers, switching by scenario

For everyday use, go with the second option: a single subscription link carries the server list, split-tunneling rules and DNS settings, and when servers change you just tap Update Subscription once in the client to sync.

120+Countries and regions
190+Servers to choose from
14 daysMoney-back guarantee
UnlimitedDevices online at once

VPN-LG subscriptions cover 120+ countries and regions across 190+ servers. Changing servers needs no reconfiguration — just tap one in the client's list.

Getting the client: what to check in the App Store

There are more options in the App Store than you'd think. Follow these four steps and you'll rarely install the wrong one:

  1. Search for the client's name, then check that the developer name and icon match the official site. There are plenty of apps with the same or a similar name, and installing the wrong one throws off every step after it.
  2. Look at two things: the minimum iOS version required and the date of the last update. A client that hasn't been updated in a long time is more likely to hit compatibility problems on a new version of iOS.
  3. If you can't find the listing, check which region your Apple ID is registered in. Some clients are only published in certain storefronts — switching regions will surface them, which doesn't mean the app was pulled.
  4. Once it's installed, don't rush to connect. Open it and check whether it supports Subscription import — that's the prerequisite for managing every server from a single link later on.

To judge whether an iOS client is worth using, check three things: can it import a subscription link, does it offer split-tunneling rules, and does it connect through the system network extension. That third one decides whether it can keep the connection alive after the screen locks.

Getting the subscription link: three things to confirm before you copy it

Sign in to the VPN-LG dashboard and copy the subscription link from the subscription section. Three details are worth noting:

Importing the subscription: two methods and that authorization prompt

Once you have the subscription link, there are two ways to import it. Pick whichever your client supports:

Method one: add it inside the client. Open the client, find the Subscriptions (or Server Subscriptions) entry, create a new subscription, paste the link into the address field, save, then tap Update. The server list will refresh — this is the most compatible route.

Method two: tap the link for one-tap import. Tap the subscription link directly on the iPhone; if a client that handles the URL scheme is installed, iOS will ask which app to open it with, and the subscription address is filled in automatically once you pick one. If you have several clients installed, be careful to pick the right one.

After importing, tap any server to connect and iOS shows an authorization prompt: "Client Name" Would Like to Add VPN Configurations, with Allow and Don't Allow below it. Tap Allow, then confirm once more with Face ID or your passcode, and the connection is actually established.

This prompt only appears the first time you connect. If you tap Don't Allow by accident, connections will keep failing. To fix it: go to Settings → General → VPN & Device Management (on older versions of iOS this item is just called VPN), delete the leftover configuration that was created, then connect again from the client and the prompt will reappear.

Don't edit or delete a VPN configuration that's in use. When you switch clients, first complete a connection in the new client and confirm you can browse normally, then go back to Settings and delete the old configuration. Doing it in the opposite order can leave two configurations fighting over traffic.

Verifying it works: four checks, not just the connection icon

A VPN icon in the status bar and a Connected label on the client's home screen only prove the configuration exists — not that traffic is actually going through the server. Confirm all four of these:

If any of the four doesn't line up, disconnect and reconnect once. If it still doesn't line up, troubleshoot in this order: is the subscription up to date → are the configuration permissions still there → has the split-tunneling mode been switched to Direct.

Pass criteria: the exit IP's location, the services you can open and the DNS resolution location all point to the same region — only then is the setup complete. If they don't match, disconnect and reconnect first, then check the subscription, permissions and split-tunneling mode in that order.

Split tunneling, DNS and on-demand connection

Split tunneling: rules for daily use, global for troubleshooting

Most iOS clients offer three modes:

The rule set updates along with the subscription. After changing your subscription, remember to tap Update Subscription once in the client so the rules refresh.

DNS: resolution location should match where your traffic exits

Clients usually offer two DNS options: Follow System and Manual. If verification shows the exit IP abroad but lookups answered locally, switch DNS to a manually specified public resolver and make sure lookups go through the server too — that usually fixes it.

On-demand connection and background behavior

With On-Demand enabled, iOS establishes the connection automatically when you switch to cellular or join a new Wi-Fi network, so you don't have to tap connect each time. Turn it off and you'll connect manually every time.

Two common misconceptions are worth clearing up: locking the screen won't drop the connection, because the system — not the app — maintains the tunnel; and turning off Background App Refresh in the client doesn't affect an established connection, only how often data refreshes inside the app.

Won't connect on cellular

If it works on Wi-Fi but drops when you switch to cellular, first check whether the client's toggle is on under Settings → Cellular. iOS lets you restrict cellular data per app, and with that toggle off the client can't refresh subscriptions or update its server list.

FAQ

The server list is empty after importing the subscription — what now?

First check whether the link was copied in full — the most common cause is a few missing characters at the end, or a stray space pasted in. Once you're sure it's intact, tap Update Subscription once in the client. If it's still empty, copy the link from the dashboard again and retry.

It says Connected, but pages won't load?

Switch the split-tunneling mode to Global and try again. If Global works but Rules doesn't, the problem is in the rule set — updating the subscription fixes it. If neither mode works, check the DNS settings and the exit IP's location.

Got a new iPhone — do you have to set up the configuration again?

You'll need to import the subscription once more, following exactly the same steps as the first time. Accounts aren't tied to devices, there's no limit on the number of devices, and five devices can be online at once. Whether you delete the configuration on the old phone makes no difference.

Will it affect iCloud sync?

In Rules mode, Apple domains generally connect directly, so sync isn't affected. If you switch to Global and notice sync slowing down, switch back to Rules.

Do you need to re-import the subscription to change servers?

No. The server list comes from the subscription — just tap another server in the client to switch. You only need to re-import if the subscription link itself changes.

Summary: set it up once, then just two things

The whole process only needs hands-on work once: get the client, import the subscription, allow the configuration, verify the three indicators. After that, day-to-day use comes down to two actions — tap a server in the list when you need a different region, and tap Update Subscription once when servers change.

If you're stuck at a step, work backwards in order: does the client support subscription import → is the subscription link complete → was the VPN configuration allowed → do the exit IP and DNS point to the same region. One of those four will match your symptom.

The short version: install a client that supports subscription import, import the subscription, tap Allow in the system prompt, then confirm the server is live using three things: the exit IP, the services you can open, and the DNS resolution location.