Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Lulu breaks Microsoft Remote Desktop on macOS Sequoia #637

Open
Hawkedon opened this issue Sep 17, 2024 · 24 comments
Open

Lulu breaks Microsoft Remote Desktop on macOS Sequoia #637

Hawkedon opened this issue Sep 17, 2024 · 24 comments

Comments

@Hawkedon
Copy link

When enabling Lulu, after about 15 seconds with Microsoft Remote Desktop, I received the following error message:

Your session ended because of a data encryption error. If this keeps happening, contact your network administrator for assistance.

Error code: 0x407

Disabling Lulu fixed the problem. I never encountered this problem on macOS before Sequoia. Seems some updates in macOS Sequoia break Lulu.

@xorxoxor
Copy link

I am having similar Problems since the update with SSH connections. I'm randomly getting disconnects. Yesterday I also had issues with stalling downloads via https. I can also confirm your RDP Issues.

@Hawkedon
Copy link
Author

Seems there are quite a bit of change for network filtering in Sequoia. For example, this initializer has been deprecated

networkRule = [[NENetworkRule alloc] initWithRemoteNetwork:nil remotePrefix:0 localNetwork:nil localPrefix:0 protocol:NENetworkRuleProtocolAny direction:NETrafficDirectionOutbound];

and replaced with

https://developer.apple.com/documentation/networkextension/nenetworkrule/4360323-initwithremotenetworkendpoint

@wastez
Copy link

wastez commented Sep 17, 2024

The problem seems to be related to the internal firewall of sequoia.

Just disable the internal firewall until apple will fix that.

@anarchy89
Copy link

I am getting drops for ssh (mac/linux), vnc(mac) and Remote Desktop for windows as well.

@sammcj
Copy link

sammcj commented Sep 18, 2024

Out of interest - if you temporarily disable macOS's inbound firewall - does it resolve the issue?

@jdwhite
Copy link

jdwhite commented Sep 18, 2024

Out of interest - if you temporarily disable macOS's inbound firewall - does it resolve the issue?

Yes, it does. It very much does.

Name of this issue should be renamed to "Lulu breaks networking on macOS Sequoia" except it's not really Lulu. Point is it's not just Remote Desktop. I first noticed it with SSH. Then my Zoom calls were dropping several seconds of audio randomly while others sharing the same internet pipe were entirely unaffected.

@sammcj
Copy link

sammcj commented Sep 18, 2024

Ok, I’m not surprised. I have a theory that Apple hosed something in the packet filtering stack and it’s causing problems for a lot of applications.

I can reproduce the problems without any third party packet filter - as I can the workaround.

@got3nks
Copy link

got3nks commented Sep 18, 2024

It's an issue with the firewall in MacOS Sequoia.

https://discussions.apple.com/thread/255759412

@FideliusFalcon
Copy link

FideliusFalcon commented Sep 18, 2024

I have simular issues with MacOS Sequoia, but it's general DNS resolve issues mostly in Firefox.
It seems like the solution is either disabling LuLu (and other network filtering tools) or disabling the build in Firewall on MacOS.

@andrey-admin
Copy link

any fix available?

@FideliusFalcon
Copy link

@andrey-admin Disable LuLu or Host Firewall until Apple fixes this

@hellpf
Copy link

hellpf commented Sep 19, 2024

Just use ethernet instead of wifi + off firewall and it works just fine 🤷‍♂️ (for me)

@objective-see
Copy link
Owner

This has now been confirmed, to yes, be due to an Apple bug in macOS 15, that is widely impacting many 3rd-party security tools, that then in turn causes macOS networking to break.

This has been reported to Apple (and was so before macOS 15 was released), who have confirmed the issue and are hopefully working on a fix.

More info: "Apple’s new macOS Sequoia update is breaking some cybersecurity tools"

@jdwhite
Copy link

jdwhite commented Sep 19, 2024

Just use ethernet instead of wifi + off firewall and it works just fine 🤷‍♂️

If I'm correcting parsing this as use (ethernet + enabled firewall) instead of (wifi + disabled firewall), then no -- it does not work just fine.

Obviously, I can only speak for me but the network interface I used on my M1 MPB did not matter. I tried WiFi, an external 10GB adapter (OWC), and even the virtual interfaces between my host and guest machines in UTM! SSH connections on any of these interfaces would fail miserably. FYI/FWIW.

@iplotin
Copy link

iplotin commented Oct 6, 2024

Yes, APPLE left everyone in 15.x without a firewall, even their own. Looks like apple is not on the side of security and this was done intentionally. Apple does not equal security.

@wdormann
Copy link

wdormann commented Oct 8, 2024

Just use ethernet instead of wifi + off firewall and it works just fine 🤷‍♂️ (for me)

Wired ethernet is no better than Wi-Fi for me. Even on wired, I get a Remote Desktop disconnect within minutes if LuLu and the macOS firewall are both enabled. I'm on 15.1 Public Beta 3, FWIW.
Screenshot 2024-10-08 at 10 14 34 AM

@bezzoh
Copy link

bezzoh commented Oct 18, 2024

Agreed. It happens equally with wired connections as it does WiFi.
For me it occurs on 2x iMac M1's. One is wired, one is WiFi. It does not occur on my M3 MacBook Air.
"Just" turning off the firewall is not a fix. Thats like saying, "Just' leave your front door open because you've broke your key. "Just" - no.

@FideliusFalcon
Copy link

"Just" turning off the firewall is not a fix. Thats like saying, "Just' leave your front door open because you've broke your key. "Just" - no.

Incorrect. You dont know what a host based firewall is, and what risks it mitigate.

@bezzoh
Copy link

bezzoh commented Oct 18, 2024

Well if you say so, I guess you could just ring all the various Cyber Insurance underwriters who insist that they're enforced to keep the premiums down then...

In an enterprise environment, these are on by policy for such reasons. See we wont be paying an additional £10k on the policy, just so that we can turn this off...

and yes, it protects the device from the other 4000 or so other devices in the estate which may or may not at some point potentially become compromised. In additional to all the home workers who take their laptops into the various public WiFi locations at coffee shops and such like... I see this feature as pretty important.

@FideliusFalcon
Copy link

If you work at an enterprise and have a device that is not rolled into a MDM, they don't care about endpoint security.

I'm pointing out that your analogy is wrong, not that every security policy is.

I will stop replying now because it's out of scope of the original thread

@bezzoh
Copy link

bezzoh commented Oct 18, 2024

Fair one 😊

In other news, one of my staff currently using one of the affected iMacs advises me that it updated to 15.1 about an hour ago (I set that particular one to the public beta channel,) and he reckons it seems to have fixed the problem. All RDP connections via the Windows App have been rock solid since.

@wdormann
Copy link

I can confirm that RDP works again fine with LuLu once I installed the recently released Sequoia 15.1 public beta 4.

@M4rt1n12
Copy link

M4rt1n12 commented Oct 25, 2024

The problem seems to be related to the internal firewall of sequoia.

Just disable the internal firewall until apple will fix that.

Unfortunaly not in my case. Both Jump App and Microsoft App fail.
nmap port scan is OK. Other iMac with Ventura work.

I even don't have LuLu installed and don't know it. It doesn't work anyway, or it only works "sometimes".

@M4rt1n12
Copy link

With the beta it actually works again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests