cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
154882
Views
75
Helpful
74
Replies

MacOS Catalina 10.15 Support

Rina5495
Level 1
Level 1

 

Cisco Any connect client fails with an error. Error details can find here. https://support.apple.com/en-us/HT208436 

 

In Summary,  it seems that 32bit software isn't supported in MacOS Catalina.  

 

Is there a 64bit version for MacOS? or a version compatible with 10.15? 

 

 

74 Replies 74

We are having the exact same issue. The profile and group work just fine with Windows, and on Windows the default gateway for each of the networks in the route through the tunnel are mapped to the next hop and not the IP assigned to the client. On a Mac with the same client and OS the roues all map to the assigned IP address of the client, and not the next hop. A connection can be made without an error message and there is not access to anything through the tunnel. We have opened a case with Cisco and performed a DART process and we have submitted it to Cisco for analysis. Hopefully something will come of it.

Also the MAC was first upgraded, and this did not work. Then it was freshly installed with Catalina and the client freshly installed. This resulted in the exact same issue. There actually were two times when we actually got traffic to flow through the tunnel, but as soon as a disconnect and connection to another network was made, and further attempt to reconnect to the client and pass traffic failed. Even a reboot did not help.

If you find a solution share with us.

 

We have made some progress. Initially the laptop was installed with Yosemite with Anyconnect 4.7. it was then upgraded to Catalina and the client would not work. We upgraded the client to 4.8, and it still did not work. A factory re-install was performed back to Yosemite and freshly upgraded to Catalina and a fresh install of AnyConnect 4.8 and this did not work, except for once or twice then failed after a reboot. We opened the case with Cisco and have been running DART to gather information multiple time with no success at a resolution. After several days and even installing Java we still could not get traffic to pass even with a successful login. So, while running Catalina, the Catalina install was downloaded and written to a bootable USB stick. The laptop was restarted and the installer booted from the USB and formatted the drive and performed a clean install without any remnants of Yosemite. The AnyConnect client was installed and is now working. We plan to test this in several different locations, and for a couple more days. So, what appears to have been the issue for us, was the upgrade from the 32 bit Yosemite to the 64 bit Catalina. There must be remnants of the 32 bit network stack left behind that interferes with the proper functioning of the VPN client. I have never been a fan of upgrades having more experience with Windows, and I know OS-X is solid, however the transition from 32 bit to 64 bit is a major transition. Upgrading probably works well for most people, but in our case was what appears to have caused our issue with the AnyConnect client at the time of this writing. Time will tell. Sorry for the lengthy post, and I hope this helps someone.

I tried to perform the same steps that arrived you succeeded in traffic between networks, but I was unsuccessful.
I think some other step is that allowed access. I did the same process twice and both times without success.
any new progress I'll back and share

Sorry to hear that. To provide a little more detail, here are the steps from the actual person who owns the laptop and what he did to clean off the drive before he re-installed fresh. "When I boot into Recovery (including from USB) on Mac I am taken to the install but I closed out of that and went into DiskUtility to format the drive, then I go back and run the install." Just in case it is different than what you tried.

mashrurmia57909
Level 1
Level 1

4.800175 works with Catalina - I just tried

wechua0015
Level 1
Level 1

i have another question , have anybody knows how can i do?

Anyconnect : 4.8.00175

macOS : 10.15 Catalina

 

Thanks.


截圖 2019-10-17 08.31.12.png

open terminal and do the following (you will need administrator rights on your Mac)

cd /opt/cisco/AnyConnect

sudo nano AnyConnectLocalPolicy.xml
Then edit the field for ExcludeMacNativeCertStore to "true"
<ExcludeMacNativeCertStore>true</ExcludeMacNativeCertStore>
^X  (control X to exit)
press Y to indicate that you want to save
press enter to accept the existing name
Quit AnyConnect and start it up again.  You will now receive a certificate warning with the option to continue and, if available, install the certificate.
--
Please remember to select a correct answer and rate helpful posts

yes!

i can connect  again,thanks bro!!!!

Glad I could help.  Thanks for the rating.

--
Please remember to select a correct answer and rate helpful posts

This doesn't work for us as the certificates needed for AC are installed and trusted via JAMF.

 

Therefore by doing the suggested change the following popup warning appears:

 

"Security Warning: Untrusted Server Certificate!"

 

By checking the box: "Always trust this server and import the certificate" - although it doesn't give you the option to look at the certificate. 

 

Then pressing the button: "Connect Anyway"

 

Then the message "AnyConnect cannot confirm it is connected to your secure gateway. The local network may not be trustworthy. Please try another network."

Which means that for my particular case, it still fails hard. I suppose the issue is with Cisco not being able to fetch the necessary information from Keychain? Any more ideas?

This has happened to me also the first time but the second time I tried to connect it was successful. But then again I use username and password for authentication. Do you use certificate based authentication? 

--
Please remember to select a correct answer and rate helpful posts

Yes :(

 

I dont understand what you are trying to say here.

--
Please remember to select a correct answer and rate helpful posts