Enable Rapid DTR on iOS for Omnissa Tunnel
Rapid DTR refers to the ability to quickly update Device Traffic Rules (DTR) in Workspace ONE Tunnel. It allows App or Network policy changes (like bypassing, blocking, or tunneling traffic) to be applied faster at scale on the gateway and then synced to devices automatically without reconfiguring profiles. In short, Rapid DTR enables fast, dynamic control of network traffic policies for better security and flexibility.
While Rapid DTR (Device Traffic Rules) are there for some time on Android , I still get from time to time asked mainly on iOS the following Question . “When updating DTRs on iOS devices, do changes take effect automatically—or do we still need to repush the VPN profile?” So let us have a look and demystify the requirements , setting s and what it exactly does.
Note: This DTR Sync mechanism is not changing any Client Certs for Authentication or the SSL Pinning of Tunnel (Server Cert). For updating the Client updates the Profiles still have to be re-pushed.
Pre-Reqs :
To enable the DRT for iOS the following Pre-reqs need to be met:
- UAG 25.06.1 / Tunnel Container and later
- iOS Tunnel App Version 25.08 or Newer
- Android Tunnel App Version 25.12 or Newer
- Enablement: Set Tunnel server KVP
ztna_dtrto 1
The set the Tunnel Server KVP in the UEM Console , Ensure the “ztna_dtr” is set to 1. Once saved ensure the UAT/ Tunnel settings on the serverside are reloaded (Resave the Settings)

Enable the Device UI
To get the visibility on the Device Ensure the “enable_rapid_dtr” KVP is enabled in the VPN Profile for iOS. A sample Profile here:

On the Device itself it looks like this then once enabled:

This Provides the User a idea when the last sync was , but also the User can trigger the re-sync of the Device Traffic Rules directly. The Default sync is 240 Minutes / 4 hours.
vExpert, blogger and VMware & Omnissa champion. Worked 10 years as a Architect for a partner before joining VMware in 2017. Moved to Omnissa in 2024.