Device VPN provides VPN access to user devices when a user is not logged in. Device VPN is supported on Windows using the Connect Tunnel client.
In SMA1000 12.4.3, the Device VPN Communities (under Services > Network Tunnel Service) has two additional check boxes that allows users to bypass entering VPN credentials for User VPN, when the client machine is powered on or restarts in secure network. Also, if Device VPN is enabled, Allow user to disconnect option takes precedence over Always On VPN configuration. Below are the two Device VPN options:
Refer to the Configuring Device VPN section.