Documentation

Guides, tutorials, and frequently asked questions

Switch Policies Without a Mixed-State Tunnel | Raven

Frequently asked questions

Can I switch policy groups without the tunnel ending up in a mixed state?
Yes. Profile refreshes and policy changes publish versioned snapshots, and the live tunnel accepts only the matching revision.
What routing modes does Raven support?
Rule, Global and Direct, with select and URL-test policy groups.
What does the versioned snapshot prevent?
Old and new state crossing over — the tunnel never runs a mixture of two configurations.
Where do profiles and credentials live?
On device, with redacted diagnostics staying local too.

The short answer

Profile refreshes and policy changes publish versioned snapshots, and the live tunnel accepts only the matching revision.

The problem this solves

A network client has two things that must agree: the configuration you asked for, and the configuration the tunnel is actually running. If those two can differ — because a refresh landed half-applied, or because a policy change and a profile update raced — then you get the worst kind of bug: a tunnel that is running some of what you asked for.

A versioned snapshot removes the partial state by construction. There is no version the tunnel is allowed to accept except the one it was given.

Routing modes

Use Rule, Global, or Direct modes with select and URL-test policy groups, and every choice belongs to an explicit profile revision — so the config you are running can always be named, and rolled back to by revision rather than by guesswork.

The privacy boundary

Profiles, credentials, selections and redacted diagnostics stay on device. Raven operates no VPN servers, accounts, or telemetry system.