Skip to Content.
Sympa Menu

cat-users - Re: [[cat-users]] Eduroam and iCloud Private Relay

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

Chronological Thread  
  • From: Christina Klam <cklam AT ias.edu>
  • To: Andrew Reddin <andrew.reddin1 AT port.ac.uk>
  • Cc: cat-users <cat-users AT lists.geant.org>
  • Subject: Re: [[cat-users]] Eduroam and iCloud Private Relay
  • Date: Wed, 19 Feb 2025 14:10:03 -0500 (EST)

Andrew,
As we block all DNS lookups to anything but our own DNS servers, users will experience latency when Private IP Relay is enabled.  Clients try to resolve against mask.icloud.com or mask-h2.icloud.com, fail, and then try our DNS servers.  See Apple's explanation and suggested workaround:

 

See https://developer.apple.com/icloud/prepare-your-network-for-icloud-private-relay/  


Hope that helps,

Christina Klam
Network Engineer
Institute for Advanced Study
1 Einstein Dr
Princeton, NJ 08540
(m) +1 609-751-7899
(o) +1 609-734-8154
cklam AT ias.edu



From: "Andrew Reddin" <cat-users AT lists.geant.org>
To: "Tomasz Wolniewicz" <twoln AT umk.pl>
Cc: "cat-users" <cat-users AT lists.geant.org>
Sent: Wednesday, February 19, 2025 9:02:52 AM
Subject: Re: [[cat-users]] Eduroam and iCloud Private Relay

Thanks - users are able to connect without issue but are reporting 'disruption' once connected.

Andrew Reddin
Senior Network Engineer
University of Portsmouth

University of Portsmouth, St Andrews Court, St Michael's Rd, Portsmouth PO1 2PR




On Wed, 19 Feb 2025 at 12:25, Tomasz Wolniewicz <cat-users AT lists.geant.org> wrote:

I just tested turning it on and off and connecting to my local eduroam - no problem with this.

Tomasz Wolniewicz


W dniu 19.02.2025 o 12:48, Andrew Reddin (via cat-users Mailing List) pisze:
Apologies if this isn't the correct forum for this but has anyone else started experiencing issues with the Apple Private Relay on Eduroam in the last few weeks?

As far as I'm aware it's been around for a long time (since Monterey?) so I'm not sure why we've suddenly started having complaints about it.

The nature of it suggests that it's likely to cause connectivity issues on a WPA Enterprise network but I suppose something's changed in the last few weeks?

Andrew Reddin
Senior Network Engineer
University of Portsmouth

University of Portsmouth, St Andrews Court, St Michael's Rd, Portsmouth PO1 2PR


-- 
Tomasz Wolniewicz
To unsubscribe, send this message: mailto:sympa AT lists.geant.org?subject=unsubscribe%20cat-users
Or use the following link: https://lists.geant.org/sympa/sigrequest/cat-users




Archive powered by MHonArc 2.6.24.

Top of Page