Cisco VPN and why does it work on guest?

Has anyone identified the specific Eero feature that doesn’t play well with the Cisco AnyConnect VPN? I was having issues for the last month or two and then stumbled on the guest network trick and this is working solid. What I was wondering is what does the guest work not enable? And has anyone identified exactly what feature is conflicting?

Eero Pro 6 (3) FW v6.14.0-4275
Windows 11
Cisco AnyConnect Client v4.10.05085

Issue was VPN specific and not wired/wifi.

Update your Cisco AnyConnect. The current version is 4.10.06090. Making sure you have the latest version should be your first troubleshooting step.

We have a several folks experiencing the same problem, but it only started for us last month. Previously, AnyConnect worked just fine.

Connecting wired directly to the ISP router or using Guest is a workaround, but not ideal for everyone. As I understand it, one thing that Guest does differently is use the WAN interface’s DNS servers. For us, however, either folks were already using their ISP’s DNS with Eero Plus turned off, or reverting to ISP DNS, 8.8.8.8, etc. had no impact.

I have a ticket with Eero that has been escalated to engineering, so they are aware, but so I’m in a wait loop.

Using AnyConnect for many years with eero here, no real issues.

I currently use AnyConnect 4.10.05111 on macOS 13.2.1, two separate eero Pro 6 networks on eeroOS 6.14.0, not using Guest network on either. No issues on either network.

I do disable IPv6 on the eero networks as our split-include AnyConnect tunnel has DNS resolution issues if it is enabled. Other than that, nothing special.

What exactly are the symptoms you’re seeing? Lack of DNS resolution? You could try disabling IPv6 if it’s enabled.

The Guest network as far as I know only isolates devices from each other and the main network. It used to be that it was hardcoded to use Google Public DNS, not sure if that’s still the case in 6.14.0.

Do you have eero Plus enabled? I could see that possibly causing issues. If enabled, you could try disabling it.

I use Cisco any connect. Has been working fine for me since I moved to eero in jan

No issues here. Are you subscribed to the eero+ stuff?

When you encountered first encountered the issue, were you on windows 11?

My wife updated her laptop to windows 11 and then was instructed by her IT to use the guest network as a workaround. They said they were getting a lot of calls after they had their employees update to Windows 11.

Does appear to be a Win11 issue with specific versions. Mine is Win11 and AnyConnect v4.10.05085. And unlike personal computers, our corporate controls dictate which version we are on. Until they upgrade, or we change VPN clients, the guest network trick works.

I’m interested in what you get out of Eero support. Still just using guest mode on my network.

I forgot to add that the latest AnyConnect version did not have a positive impact.

It starts dropping connection. I would set a ping on repeat and watch it go through frequent times of missing repeated pings.

I’ve not tried disabling IPv6, but do see it is disabled in the vpn status info.

This was never an issue on the original eero mesh and I don’t recall it being an issue when I first got the Pro 6es.

macOS, v5 of any connect

I don’t recall. Was Win 11 when ip6 was possibly made default or something? No idea.