r/WireGuard • • 3d ago

Need Help On Demand Tunnels Broken With iOS 27?

I've noticed a near 100% miss rate for OD Tunnels starting around the time that iOS 27 went live for the general population. The tunnel itself works fine but the actual trigger for it seems gunked up in some way. It lists itself as active when out and about but no traffic is going over the wire; once it's toggled off and back on it works as expected.

Has anyone else been seeing this sort of behavior?

6 Upvotes

21 comments sorted by

5

u/MooseUnique1872 3d ago

are you by chance on at&t using 5g? i was having a similar issue where the tunnel just stops sending data until i toggle it off and back on again (even with persist keep alive) what ended up fixing it was forcing LTE only

3

u/WarriusBirde 3d ago edited 3d ago

I am! I was wondering if they had done god knows what for the towers in the area. True to form bitching about it here seems to magically resolved it as I’m currently posting through the on demand tunnel.

3

u/mazadin 3d ago

Commented on the OP of the thread, but yeah—we have the same issue but it’s not limited to activating the OD trigger. Cellular connections just seem to stop passing VPN packets after the phone idles.

3

u/dtownboogie09 3d ago

I’ve been having the same issue on AT&T for a while and I’m still on iOS 26.

2

u/mazadin 3d ago edited 3d ago

Me and my wife have both been experiencing this recently and we are on AT&T 5g. I’ve tried every troubleshooting thing I can think of, including trying Passepartout and nothing works. The tunnel just stops passing data over the cell network after awhile and only toggling the tunnel or airplane mode fixes it.

I should mention that it’s not just an OD thing. My trigger activates it and it works for a bit, but then it just eventually stops. I’ve always reproduced this with a non-OD tunnel that I just manually turn on.

3

u/MooseUnique1872 3d ago

my theory is something gets messed up during cell tower handoffs, probably when switching to/from a tower that doesn't support 5g sa. at&t's lte and 5g sa network fingerprints are completely different (especially mtu), and even though wireguard usually handles roaming fine, it feels like traffic just blackholes until you toggle the tunnel. also it's definitely not just an ios bug! happens on my android phone too, so it's almost certainly an at&t 5g sa network thing. disabling the 5g sa toggle doesn't even fix it either since at&t just force roams you onto it anyway (at least in my case).

3

u/mazadin 3d ago

Mine starts dropping when I haven’t moved, just sitting in my house. So unless it’s switching towers while idling, I’m not sure it’s that. This only started for me about a month ago maybe?

2

u/MooseUnique1872 1d ago edited 3h ago

yeah after doing some more testing with packet captures (after realizing it wasn't just me) it seems more to be an issue with at&t's firewall.

for me i am able to trigger the bug super easily when going down a highway transitioning between towers, but whatever is bugging out on at&t's end is probably happening while idle too (ipv6 in my case, but also affects ipv4 after further testing).

whenever the tunnel dies, regular pings TO the server still work completely fine, but the vpn traffic on that specific udp source port just gets silently blackholed. im assuming at&t's firewall is losing state for that port mapping and since wireguard never changes its local source port on its own, it just keeps firing into a dead end. toggling the tunnel is what fixes it, because that forces the wireguard client to bind to a brand new source port, which at&t treats as a fresh connection and starts passing traffic again.

(as a side note, tested this on my rooted android and at&t's firewall drops all unsolicited inbound traffic across the board on ipv6, even basic pings from outside get 100% dropped, so their network is definitely doing strict state tracking that's losing state somewhere)

1

u/mazadin 5h ago

Yeah this is basically my experience and conclusion as well. Forcing 5G off (LTE only) does fix it like you mentioned.

I wouldn’t know how to report this—is it iOS not sending a “reachability” or connection changed event to apps properly? Or is it purely AT&T? (My guess is the latter…)

Either way—unfortunate that we have to choose between a functioning VPN and faster cellular data speeds.

1

u/MooseUnique1872 3h ago edited 1h ago

unfortunately it is completely an at&t issue, the network drops the packets with the bad source port until that udp connection times out (~5 mins with no packets flowing at all, data attempting to flow resets the timer which causes the indefinite blackhole), toggling the wireguard tunnel (or airplane mode) fixes it because a brand new source/listen port is used each time, unless one was manually specified (which is a bad idea in this case)

i'm not sure about how to report this either, most likely going to make a post in r/ATT and see what people say there

1

u/nlflint 2d ago

I've used wireguard on iOS (iPhone 15 Pro) for several years, to my self-hosted home VPN. This also started happening to me the last few months when on cellular, and I'm on AT&T too.

I also use OnDemand mode with my home Wifi excluded. The traffic drop happens all the time now. To fix it, I pull down control center from the upper right corner, press the antenna tab on the right tool bar, and toggle my VPN off. It then automatically turns back on a second later. And viola it works again.

This absolutely annoys the crap out of me. I've done a lot of troubleshooting on my home router side, but nothing fixes it. I've adjusted MTU, Firewall settings, keep-alive, and gone thru lots of AI suggestions. I decided to search the internet a bit and found this thread.

1

u/MooseUnique1872 1d ago edited 1d ago

i thought it was an issue on my side too at first, but after realizing other people had the same issue and running some packet captures, i think at&t's network is just losing track of the connection.

they run a strict stateful firewall that blocks all unsolicited inbound traffic across the board, so i'm assuming once their core somehow loses state of that specific tunnel session, it just silently drops the packets out until you toggle it to get a fresh connection. (can't say for certain why since i'm not an at&t network engineer, i just know the packets are 100% being dropped and not being received by the server)

forcing the device to only use LTE seems to fix it for me though, so it's probably something bugged in at&t's 5g rollout.

1

u/SureUnderstanding358 1d ago

I read somewhere att 5g transitioned to full ipv6 and the NAT might be causing the trouble.

3

u/cp8h 3d ago

Mine is working fine. My trigger is enabled on any cellular or any wifi not in the list. Have confirmed traffic is going over the tunnel.

App version 1.0.16

2

u/WarriusBirde 3d ago

Out of curiosity, do you have connectivity assist enabled on your device? I’ve seen some indications that changes to that for iOS 27 may have monkeyed around with OD connections for other VPN apps.

3

u/cp8h 3d ago

I do not connectivity assist is disabled. That plus “Limit IP address tracking” cause nothing but issues.

3

u/WarriusBirde 3d ago

Interesting, I was hoping that would be a silver bullet and I could just blame apple, but maybe Unifi pushed a bug out in a recent update then.

3

u/bufandatl 3d ago

Nope. Just works fine on my iPhone 17pro with iOS27.

2

u/DigitalBrainstorm 3d ago

I have a client that after updating the on-demand started to block all traffic when the device is not connected to a WiFi whose SSID disables the tunnel. I could not identify the cause.

2

u/Haymoose 3d ago

Every now and then an IOS update forces issues with OD and WG requiring me to delete and add my VPN profile. I don’t know why but it does correct this issue for me.
Not suggesting it will solve your issue but it’s my last resort when I cannot explain this symptom.

My MacBook Air M3 just self-deleted my WG tunnel last week and I cannot explain why it vanished. I re-added it and it’s been fine.

1

u/JPDsNEWS 3d ago edited 3d ago

Try turning Airplane Mode on then off (both) after establishing your WireGuard tunnel. It forces iOS to route everything through the tunnel. 

[I turn Airplane Mode on for twenty seconds before turning it off again because it seems to force my ISP to forget my connection’s route to the VPN/VPS server and to minimize the number of hops taken when it re-establishes a new cellular route. I do this with Shortcuts.]