This guide is for readers who have imported their own working configuration into Shadowrocket and want to reduce manual steps when switching between Wi-Fi and cellular networks. It covers the setup sequence in Settings → On Demand, how to enter Wi-Fi names and domains, and how to check each condition when automatic connections don’t behave as expected.
First, distinguish On Demand from rule-based routing
On Demand controls when to connect: when the device enters a certain network environment or a matching domain request occurs, the system tries to connect or disconnect using the saved VPN configuration. The configuration and node selected in Home, along with Global Routing, determine how traffic is handled after the connection is established. Confusing these two layers can lead to the mistaken conclusion that “the switch turned on automatically, but websites aren’t being routed as expected.”
Before you start, connect manually once in Home to confirm that VPN permission has been granted and your existing configuration works. Then open Settings → On Demand to review the settings. After enabling On Demand for the first time or changing a condition, compare the system VPN status with the status in Shadowrocket’s Home. Don’t assume that every request uses the same route just because a switch is on in the app.
Set connection and disconnection actions by Wi-Fi name
Wi-Fi conditions use the name of the wireless network the device is currently connected to—the SSID—not a router nickname or a web address. Before setting a condition, check the actual name in the device’s Wi-Fi settings. Using the same SSID for different networks makes them harder to distinguish. If your home and workplace use the same SSID, the name alone can’t tell those locations apart.
- In the device’s Wi-Fi settings, note the SSID you want to test, such as
Home-WiFi, and confirm that the device is connected to that network. - In Shadowrocket, go to Settings → On Demand, enable On Demand, and enter or select the network name in the Wi-Fi conditions provided. Check the actions, such as Connect or Disconnect, for matching and non-matching networks according to your needs. Available options may vary; refer to the in-app settings.
- For now, keep only this Wi-Fi condition enabled. Disconnect from that Wi-Fi and reconnect, then check the system VPN status and the connection status in Home. Repeat the test on a Wi-Fi network with a different name.
For example, if you want to disconnect when joining Home-WiFi and connect after leaving it based on other conditions, check the results for both joining and leaving separately. Verify the SSID’s capitalization, spaces, and trailing characters. Even a one-character typo can prevent a match. If the device is near the router but still using cellular data, the result isn’t caused by the Wi-Fi condition.
Wi-Fi check card
- Where to find it
- Settings → On Demand
- What it matches
- The currently connected SSID
- Example name
- Home-WiFi
- Test action
- Leave and reconnect to the network
Test with a unique SSID first, then add other network names.
Status check card
- Wi-Fi status
- Confirm the device is connected to the target network
- VPN status
- Check the system status and Home
- Reverse test
- Switch to a network with a different name
- Possible issue
- Duplicate SSID or mistyped network name
A network change starts the test; a status change is what you check.
How to test cellular conditions on their own
Cellular conditions are useful for triggering an action when the device leaves Wi-Fi and actually switches to cellular. Before testing, confirm that cellular data is available. Turning off Wi-Fi when cellular data is unavailable won’t show whether the On Demand cellular condition works. Cellular capability on iPad depends on the specific device.
- Keep the same configuration in Home that you’ve already confirmed works. Go to Settings → On Demand and set only the Cellular condition you want to test.
- Turn off Wi-Fi in the device settings, confirm the status bar shows a cellular connection, and check whether the system VPN status changes as specified by the selected action.
- Turn Wi-Fi back on, connect to a known SSID, and record the second status change. If the two results differ, note the network type, connection status, and test time for each, then add other conditions.
“Connect on cellular” does not mean “route all cellular requests through PROXY.” After the connection is established, requests may go directly if Global Routing is set to Direct. If it’s set to Config, requests are matched against the configuration’s rules. Proxy, Direct, Config, and Scene are different Global Routing modes; check them separately from On Demand connection actions. To isolate a problem, keep one Global Routing mode fixed so you aren’t changing multiple variables at once.
First, confirm the network has switched
If a cellular test doesn’t trigger the expected action, first confirm that the device has left Wi-Fi and cellular data is available. Then check On Demand. Don’t start by changing nodes, rules, or subscriptions; those settings can’t confirm whether the cellular trigger matched.
When domain conditions are triggered
A domain condition tells Shadowrocket to try to connect when a request related to a specified domain occurs. It doesn’t necessarily trigger every time you type something into a browser’s address bar. Use a recognizable domain for testing, and observe actual name resolution or connection activity. An existing connection, a cached DNS result, or an app connecting directly to an IP address can all make a single page visit an unreliable test of a domain trigger.
Entering example.com shows the expected format, but it’s only an example—not a guaranteed domain-trigger test service. For a proper test, choose a domain you’re authorized to access that reliably generates a new request, and enter it in a format supported by the settings page. A domain condition is also different from the rule DOMAIN-SUFFIX,example.com,PROXY: the former determines whether to try to establish a VPN connection; the latter selects a policy for a request handled by the rules in Config mode.
- To test only a domain condition, temporarily remove Wi-Fi and Cellular conditions that could match at the same time. Note the initial VPN status, then make a new request to the domain.
- If the request doesn’t trigger a connection, make sure you entered a domain rather than an IP address. Check the hostname, suffix, and any matching options available in the app.
- If the connection is established but access doesn’t behave as expected, check the configuration in Home and Global Routing. Don’t mistake a rule-matching issue for a failed domain trigger.
For example, FINAL,PROXY is the fallback policy when no earlier rule matches. It can’t make On Demand recognize a domain condition that hasn’t been set. Conversely, a domain-triggered connection doesn’t guarantee that the domain will use PROXY: in Config mode, the policy still depends on rule order and the match result.
How to troubleshoot multiple conditions
Don’t assume Wi-Fi, Cellular, and domain conditions have one fixed priority that applies in every situation. The device’s actual network, whether a condition matches, the system VPN status, and whether a domain request occurs all affect the result. To troubleshoot an apparent conflict, check each prerequisite in turn and enable conditions one at a time rather than trying to guess how On Demand behaves by rearranging rules.
First, note whether the device is connected to the target SSID, another Wi-Fi network, or Cellular. Then check the corresponding condition and action. If the connection status changes as expected, check the selected configuration in Home and Global Routing. Check domain triggers and rules in Config only when diagnosing a specific website. This helps separate three issues: the connection didn’t trigger, the expected rule didn’t match after connecting, or the existing configuration doesn’t work.
Why doesn’t Shadowrocket disconnect as expected when I return to my home Wi-Fi?
In the device’s Wi-Fi settings, check whether the current SSID matches the name entered in On Demand. Then verify whether the condition is set to Connect or Disconnect. Disable other conditions first, then test only by leaving and reconnecting to that Wi-Fi network.
Why doesn’t Shadowrocket connect automatically when I turn off Wi-Fi?
First, confirm the device has switched to available Cellular rather than being temporarily offline. Then check only the cellular condition in Settings → On Demand. If a manual connection also fails, troubleshoot your existing configuration first.
Why doesn’t the VPN status change when I open a specific website?
Check the domain condition and make sure the request isn’t using an IP address directly. Retest with a clearly identifiable new request, and temporarily remove any network conditions that might also apply. This prevents an existing connection from being mistaken for a new trigger.
Why does traffic still seem to go direct when the VPN is connected?
In Home, check whether Global Routing is set to Direct. If you want traffic routed by your configuration’s rules, check the Config mode and the relevant rules. On Demand triggers connections; it doesn’t choose PROXY or DIRECT for rules.
After testing each condition separately, restore them one at a time, changing only one setting per test. Record the results on the target Wi-Fi, another Wi-Fi network, and Cellular. If a combination is hard to reproduce reliably, keeping only the essential trigger conditions is usually easier to verify than adding more. After making changes, rely on the system’s actual VPN status and the access results.
Checklist before saving
- The configuration in Home has been tested manually. On Demand can’t fix a configuration that doesn’t work.
- The Wi-Fi condition uses the actual SSID, and the device is connected to that network during testing.
- The Cellular condition has been tested separately with Wi-Fi off and cellular data available.
- The domain condition has been tested with a new domain request; rule keywords aren’t substitutes for trigger conditions.
- Check connection status and routing results separately. If you need rule-based handling, also check that Global Routing is in Config mode.
Shadowrocket is a one-time purchase on the App Store; buying the app does not include a network service plan. On Demand manages connection conditions on your device and still requires your own working configuration. If you haven’t verified the app’s source, start with our guide to verifying the genuine app, then follow the setup tutorial to make a basic connection.