You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Can't get Universal Control to work when Cisco Anyconnect VPN is enabled

What are the network requirements for this to work? computers can see each other over wifi after the VPN connection is established

MacBook Pro 14″, macOS 12.3

Posted on Mar 15, 2022 10:16 PM

Reply
13 replies

Mar 16, 2022 7:47 AM in response to mac-pablo

I have the same issue when using the AnyConnect VPN client. When I use the OpenConnect VPN client Universal Control and other services work fine.


I also have 'allow local lan' access enabled in the AnyConnect options. I can actually ping my 192.168.* IP addresses and resolve their <host>.local host names while connected. But continuity, shared clipboard, airdrop, universal control, etc, all do not work while connected. I don't have these problems with the OpenConnect client.

Mar 15, 2022 10:56 PM in response to mac-pablo

Just to be sure I understand, which of the following two scenarios are true:

  1. While your notebook is connected via a VPN, you are not able to use Universal Control with other devices on your local network?
  2. While your notebook is connected via a VPN, you are not able to use Universal Control with other devices on the remote network?


Regardless, does the Cisco VPN client allow control over "full" and "partial" tunneling?

Mar 18, 2022 11:41 AM in response to rwm4604

Take what I have to share with a grain of salt, and understanding that most enterprise IT departments view new network features of OSs to be a bit suspect and worthy of review to both the business and security impacts. Even though this feature is now "shipped", Apple continues to mark it "Beta" in System Preferences.


tl;dr: Changes your IT dept makes today to enable it may be undone by changes Apple makes later.


----


First of all, I yearn for this to work for me too. I have an AnyConnect "all traffic" VPN computer I do work from, and a personal laptop nearby for background sound and personal communication.


I am not the VPN expert on my team, but I have been party to much discussion on features of AnyConnect. I know that there exist recent features that allow a user's collection of devices to be visible to each other when all are connected, however this would not help a user like me, who needs the all-traffic options to do my normal work, but uses a personal laptop to play music, youtube, podcasts, etc without sending that data through my corporate network while working from home.


This is something that needs to be a conversation with your VPN administrators, and usually has larger reaching impacts on other services or potential security review. If your IT department is anything like those I've served under or with, there is often too much work to do and too few people to do it, and turning on a feature or building out another profile or VPN group to cover all the permutations of features is multiplying work.


For example, "Virtual Private Network" has no intrinsic requirement for encryption, it's taken as a de facto feature of most service configurations, but the term refers more to the extension of a network into logical groups and shapes that the original specs for network subdivision did not account for. VPN servers are configured to use a host of encryption methods, or to use none at all, depending on the use and context.


Also consider that the "Back To My Mac" service was introduced in 2007, the technical details were not published until 2011. https://www.rfc-editor.org/rfc/rfc6281.html

Mar 18, 2022 11:32 AM in response to kiodane

I am the administrator for Anyconnect VPN at work and I'm willing to make some changes when possible to allow this but I can't because there is no information on what is required to allow the connection between these devices to work. Only information available online is that they need to be on the same Wifi and close to each other. I need something more technical than that.

Mar 18, 2022 11:48 AM in response to mac-pablo

For clarity, I meant to offer context to customers who will come here seeking solutions, much as I have. I mean no offense by "mansplaining" to you or anyone to come. I too hope for a technical discussion of the feature or direct Cisco support for such present and future features across all platforms.


Good luck to us all in that.

Mar 22, 2022 12:17 PM in response to mac-pablo

Same situation here. I have two Macs (a MacBook Pro and an iMac) on Monterey. Universal Control works until I fire up the Cisco AnyConnect client on my primary computer (the MacBook Pro). Then it no longer works. Sometimes it seems to require a restart of that main computer to get Universal Control established and working again.


I can see all my LAN devices even when on the VPN. I previously used the Synergy mouse/keyboard sharing product on these devices, and it worked fine both on and off the VPN.




Can't get Universal Control to work when Cisco Anyconnect VPN is enabled

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.