Mobile Tunnel
How to use Service Tunnels in the mobile app
- Last validated: Aug 31, 2026
Mobile Tunnel Overview
The mobile app allows end users to connect to Service Tunnels assigned to them. End users can be assigned to multiple Service Tunnels but can connect to only one at a time.
Service Tunnel over Port 443
The mobile app can establish the Service Tunnel over TCP port 443, which helps end users connect on networks that block the default Service Tunnel UDP port. It is a toggle in the mobile app, available on both iOS and Android, and is off by default. It works the same way as the equivalent setting in the desktop app.
DNS in Mobile Tunnel
When the tunnel is enabled, all DNS requests on the device will be funneled via the mobile app to the associated Access Tier; the Access Tier will determine the resolution of the DNS requests.
Mobile Tunnel Limitations
Due to mobile platform capabilities, Service Tunnels on the mobile app have the following limitations:
- Dynamic routing is not supported; routes will be added when the tunnel is enabled.
- Wildcard domains are not supported.
- Connect on Login is not supported.