Switch Policies Without a Mixed-State Tunnel | Raven
Frequently asked questions
- Can I switch policy groups without the tunnel ending up in a mixed state?
- Yes. Profile refreshes and policy changes publish versioned snapshots, and the live tunnel accepts only the matching revision.
- What routing modes does Raven support?
- Rule, Global and Direct, with select and URL-test policy groups.
- What does the versioned snapshot prevent?
- Old and new state crossing over — the tunnel never runs a mixture of two configurations.
- Where do profiles and credentials live?
- On device, with redacted diagnostics staying local too.
The short answer
Profile refreshes and policy changes publish versioned snapshots, and the live tunnel accepts only the matching revision.
The problem this solves
A network client has two things that must agree: the configuration you asked for, and the configuration the tunnel is actually running. If those two can differ — because a refresh landed half-applied, or because a policy change and a profile update raced — then you get the worst kind of bug: a tunnel that is running some of what you asked for.
A versioned snapshot removes the partial state by construction. There is no version the tunnel is allowed to accept except the one it was given.
Routing modes
Use Rule, Global, or Direct modes with select and URL-test policy groups, and every choice belongs to an explicit profile revision — so the config you are running can always be named, and rolled back to by revision rather than by guesswork.
The privacy boundary
Profiles, credentials, selections and redacted diagnostics stay on device. Raven operates no VPN servers, accounts, or telemetry system.