We use Packet Tunnel under network extension framework on iOS for traffic forwarding. Deployment is per app vpn through MDM.
When there is captive portal network, we clear all include routes(virtual ip is still there) so that end user can authenticate with captive portal network. But to our surprise, traffic is still coming to virtual ip.
Is this expected? Shouldn't traffic go direct when there is no include routes there?