MacOS Sequoia blocking VPN, won't allow use of Messages and iCloud

On a MacMini M1, MacOS 15.


I've been using ExpressVPN for years for my work, recently I discovered I can't use iCloud while using VPN. I could work around it by simply using it on my phone, but it wasn't optimal. I also can't airdrop while using VPN.


Now in this latest update, the MacOS is actively blocking my messages while using VPN which is a big problem now as my clients communicate through that.


I can't whitelist anything through ExpressVPN and I don't see what I can do in MacOS since I can't do anything to adjust this. It went from working to not working after the update.


Anyone else having this issue? I'd love a work around as right now, it's not at all ideal with the new OS. Most of the features that I looked forward to aren't even available in Europe which makes no sense. I somewhat understand the AI issue, but the screen sharing with your iPhone isn't available? Why? If I can screen share with my local machines why not the iphone? Something doesn't sit right with me in these latest updates.


Any help would be appreciated. Thank you in advance


PS. How can I downgrade if I have to?

Mac mini, macOS 15.0

Posted on Sep 17, 2024 8:31 AM

Reply
Question marked as Top-ranking reply

Posted on Oct 27, 2024 11:36 AM

I worked with Express VPN support and was able to get things to work.


TLDR:

  • Download the latest Mac client from Express VPN (they've made an update - more on this below)
  • Completely uninstall Express VPN - I used AppCleaner to remove left over files
  • Uninstall the left over IKEv2 Network configuration
  • Reboot
  • Install newly downloaded version of Express VPN
  • Login and configure Express VPN but do not select the new "Allow Apple Services to bypass VPN checkbox" - more on this below.
  • Enjoy


Further history:

  • I was unable to get iCloud drive, notes, or messages to sync
  • The only workaround for me that worked was switching to IKEv2 (you have to turn off advanced protection to do that).
  • I reached out to support and had a long chat where we tested many things.
  • They have created a new version with a new checkbox to allow Apple Services to bypass VPN. See https://www.expressvpn.com/support/knowledge-hub/network-lock/#apple-services
  • For some reason Express VPN did not suggest the update. Maybe it is on a rolling canary and it would have in the next few weeks.
  • I installed the new version on top of the my existing version and tried enabling the new setting based on advice from support.
  • This messed my machine up further. iCloud stopped syncing even when quitting Express VPN. I tried multiple configuration permutations but could not sync.
  • I told support I was going to do a full uninstall and did the steps listed above. At that point it was working even without turning on the new "Allow Apple service to bypass VPN..." checkbox.
  • But I was curious and checked it and did more testing. It seems that did allow Messages to work. But iCloud drive and Notes would not sync. My suspicion is that in a rush to fix it they only tested Messages and somehow made things worse for the other Apple services.
  • I've gone back to using what is working for me which is the uninstall / reinstall of a the new version with the settings I normally used (auto protocol, Advanced Protection turned on, network lock and allow access to network devices. But I did no not have "Allow Apple Services...".
    • Note that this new setting like the Allow network devices setting is tied to network lock. If you do not have network lock enabled, it is irrelevant and apple services will work regardless of it being set.


All of this makes me wonder if the change Apple made is causing issues with pre-installed VPNs but somehow allows traffic for newly installed ones. It seems to either be that or some other change Express VPN made in the new release.


I hope this helps someone else.


95 replies

Sep 20, 2024 5:50 PM in response to Cthulhu

Cthulhu wrote:

As an information security professional, your advice is irresponsible, and some items in the link are uninformed or out of date. Many of us require a VPN for work, many of us for travel, and others use them to greatly reduce the advertising traffic which, if you've ever used one, you'd know can be a transformative online experience.

Please everyone saying "just stop using the VPN" - stop giving us advice. If you have no helpful advice on the topic, please just stay silent.

So many of us are reeling from the loss of services after this update, and we're trying together to find a solution. The solution is not to stop using a VPN. Just move on, please.


As an information security professional, you are undoubtedly well aware the difference between end-to-end VPNs intended to connect into the internal network of an affiliated organization, and the first-few-hops VPNs.


The former are useful and necessary in some cases, though zero trust / beyondcorp is where many folks are new headed.


The latter first-few-hops VPNs provide negligible added security given widely-known credentials, and at substantial added overhead around the existing and secure end-to-end connections, while also being perfectly positioned to collect personally-identified network connection metadata. to many of the vendors running these services appear sketchy, as well.


If you somehow do need a first-few-hops tunnel for CDN testing or geo-testing or such (and if somehow your own end-to-end VPN doesn't provide egress to the internet), an option that avoids the metadata collection of the commercial first-few-hops servers is running your own Algo VPN server.


If you want fewer ads, load an ad blocker. (Apple has been going to some effort to make data collection more difficult for entities with those ad blockers, too.)


In addition to the existing end-to-end encryption, Apple iCloud+ Private Relay also includes ODoH (which can be configured to the server of your choice) and obfuscates source and destination IP addresses; somewhat analogous to a two-hop Tor connection.

Oct 1, 2024 6:49 PM in response to g_wolfman

I did not read it that way and do not see it as sloppy. It does technically bypass the VPN for all Apple Services services, and leaks your real IP to Apple in VPN parlance (assuming no other layers of networking protection). And while I don't have any particular distrust of Apple, exceptions like this without split tunneling specifically configured by a user is not a pattern you want to start seeing. And there are important reasons in some parts of the world to be sure your data is properly proxied.

Oct 3, 2024 8:01 AM in response to Oberon-Station

YES YES YES , SAME HERE BEEN USING VPN FOR YEAR

UPDATED SEQUOIA 15 and VPN ON , IMESSAGES WONT WORK

I REACHED OUT TO APPLE SERVICE , THEY HAVE TOLD ME

THERE HUNDREDS IF NOT THOUSANDS OF US IN THE SAME BOAT as YOU n I

She said that they will fix this with next UPDATE VERSION , God know when that will be , but it really made me double think about APPLE PRODUCTS AGAIN ,


long story short you not the only one that is extremely dissapointed with this update

Oct 7, 2024 3:10 PM in response to ssd550

ssd550 wrote:


etresoft wrote:
But that is a very important debugging step. If you turn the VPN off and that corrects the problem, then you know, with certainty, that the VPN is the problem.
Using the same logic: if you upgrade the OS and that breaks Messages and other apps while using a VPN, then you know, with certainty, that the OS is the problem?

No, it doesn’t work that way. Logic is rarely invertible. If A then B does not imply if B then A.


System modifications must be written to work with the OS. It does not work the other way around.

Oct 7, 2024 5:06 PM in response to ssd550

The moderator removed the last statement I made (because it "because it contained information about beta software"). It actually referenced the early release versions of 15.0. My point was that if breaking changes were introduced in Sequoia (already released at this point so this post is also not revealing any pre-release information, and it's common for major releases to change APIs) and VPN vendors did not make updates to handle those changes, then the VPN vendors are to blame for issues. The moderator-edited version makes it look like I'm blaming Apple. I'm not, as I don't have enough information. The same is true for the VPN vendors. I'm just hoping for a quick resolution.


The updated version provided to me by PIA today did not work.

Oct 9, 2024 12:44 PM in response to Cthulhu

When the issues started to crop up with Apple News and Stocks, the VPN vendor informed me that they were aware of the situation and were looking to Apple for a fix as it was out of their hands.


I can’t fully recall if this VPN issue started before macOS 15 moved out of beta, but I want to say it started with macOS 14.x.x.


At the time of this writing, Apple News, Stocks, and iCloud is working, but Messages is fully blocked.

Sep 17, 2024 8:59 AM in response to etresoft

good idea, I'll try with Proton VPN for a moment to see if it makes a difference.


So wait, basically the EU is putting us all at risk by inviting that scenario?? Then people should start a EU petition to go against it and side with Apple to get some financial support to win a court ruling on this. This all sounds very counterintuitive from the EU to go against Apple this way. Come to think of it, the additional App store other than the apple one, never made sense to me and opens up risks that isn't worth it.

Sep 19, 2024 7:17 AM in response to Oberon-Station

Bad news - I’ve even tried contacting ExpressVpn to tell them that Apple Mac users who have upgraded to Sequoia in Europe are now unable to send IMessages etc if using ExpressVpn. ……. Despite pleading with them to help I get a sense it’s just sending out AI responses as nothing they have suggested so far has worked.


any one able to get a sensible answer from actual engineers at ExpressVPN. ????

Sep 19, 2024 8:53 AM in response to Oberon-Station

Same here. I am able to use all the client-side certs and crazy complicated things to access various sites/portals, and all the low-level daemons and comms apps we work on are all up with no issues. All of that was well-tested before we updated, as was the VPN we were issued. I'd like to call out Apple for clearly not even trying Messages and FaceTime on any VPN, but, uh - neither did we. So blame all around, I suppose. Unfortunately it's the "corporate" VPN that I really need for work, but I did try ProtonVPN without success. We're wading through Wireshark traces, and we're stumped. I don't think it's something we or the VPN vendors can fix at this point. I am hoping it's something so obvious that we're all missing it looking deep in the weeds. :-)

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

MacOS Sequoia blocking VPN, won't allow use of Messages and iCloud

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.