(..continued)
NEFilterManager must be enabled after the System Extension is activated and enabled, it might be a disaster if NEFilterManager is enabled without a runnable System Extension (all network connection lost, or even T2 watchdog panic).
A new status API/notification would help developer to implement this feature more easily.
Topic:
App & System Services
SubTopic:
Core OS
Tags: