They talk about the client having a whitelist of IPs to form secure channels to, and using a combination of a dns proxy and cooperating client to form secure communication layers.
The actual described thing sounds a little different (i.e. 'requests for 192.168/24 have a transparently encrypted link' rather than tls handshakes), but not different enough that it's not obvious.
From the existence of SSL, dns, and a VPN, this idea seems quite obvious to me. In 1998, all of those things existed. The existence of SSL (in 1995), should have by itself invalidated this patent entirely IMO.
From the case filings, it sounds like the supposedly infringing part of Apple's tech is "VPN On Demand" and "FaceTime".
I am not a patent lawyer, I likely don't know what I'm talking about.