VPN service - Support information
Support requests
Please include the following information with your support request regarding the faulty VPN login attempt/problem:
- Exact time (day, hour, minute)
- Your IP address (IPv4) – can be found at https://www.heise.de/netze/tools/meine-ip-adresse
- Type/version of the operating system on the affected computer
- Version of the Cisco Secure Client,
- Brief description of the error/problem (ideally: error message word for word).
Cisco Secure Client for older Windows versions
Information (31 January 2023): Windows versions older than Windows 10 are no longer supported by the current Cisco Secure Client (5.x). To resolve the issue, the affected computer can and should be updated to a current Windows version. Current Windows versions are currently available to BTU members under a campus licence.
Cisco Secure Client for older versions of macOS
Information (13 August 2026): Versions of macOS older than version 14 are no longer supported by the current Cisco Secure Client (5.x). To resolve the issue, the affected computer can and should be updated to a current version of macOS. See also: http://www.apple.com/uk/macos/how-to-upgrade
Cisco Secure Client (macOS) Uninstallation
Information (28 April 2022): The AnyConnect client should be uninstalled on macOS as follows:
Finder => Applications => Cisco => Uninstall AnyConnect
If you attempt to uninstall the software in any other way, remnants of the AnyConnect client may remain on the system, preventing the AnyConnect client from being reinstalled. If this is the case, you can try to remove these remnants of the AnyConnect client with the following command (in a command line):
sudo pkgutil --forget com.cisco.pkg.anyconnect.vpn
This requires entering the admin password for the macOS system in question.
Cisco Secure Client and "Start before Login" under Windows
Information (updated on 03 August 2026): If you are logging in to a Windows domain (located on the BTU campus network), you may need to establish a VPN connection to the campus network before logging in to Windows.
In Windows, the Cisco Secure Client offers the following setting: ‘Start before Login’. To use this setting, the following component of the Cisco AnyConnect Secure Mobility Client must be installed separately: cisco-secure-client-win-5.1.19.1862-sbl-predeploy-k9.msi
Cisco Secure Client (Linux) error message: "Security Warning: Untrusted VPN Server Certificate"
Information (17 April 2014): For the Cisco Secure Client, access to the browser or system-internal certificate store is required to establish a VPN connection. This ensures that the Cisco Secure Client only establishes connections to trusted VPN servers.
If internal system access to the specified certificate stores is not possible, the following error message appears:
Security Warning: Untrusted VPN Server Certificate
AnyConnect cannot verify the VPN server: vpn-gate.b-tu.de
...To resolve the problem, we recommend activating the internal certificate store of the Cisco Secure Client and importing the HARICA TLS ECC Root CA 2021 certificate into it. To do this, use the following commands on your Linux system:
mkdir -p ~/.cisco/certificates/ca
cd ~/.cisco/certificates/ca
wget https://repo.harica.gr/certs/HARICA-TLS-Root-2021-ECC.pemAnyConnect Client (Windows) error message: ‘VPN Service not available’
Information (31 January 2023): The software ‘Lenovo Rapid Boot’, ‘RapidBoot Shield’ or ‘RapidBoot HDD Accelerator’ may be responsible for the message ‘VPN Service not available’ appearing when starting the AnyConnect client. These products are incompatible with the AnyConnect client. Uninstall or deactivate them if you want to use the AnyConnect client.
AnyConnect Client (Windows 7) error message: "The vpn client agent was unable to create the interprocess communication depot."
Information (26 October 2011): If the following error message appears when installing the Cisco AnyConnect Secue Mobility Client: ‘The VPN client agent was unable to create the interprocess communication depot.’ We recommend disabling ‘Share this connection to other network devices’ for all network cards on the system as follows:
- Start => Control Panel => Small icons (if necessary) => Network and Sharing Centre => Manage network connections (in Windows 7: Change adapter settings)
- Right-click on each network connection => Properties => Sharing
- Disable Internet connection sharing
We are experiencing intermittent problems establishing connections to Windows PCs or to our department's NT server. Sometimes the connection can be established, sometimes it cannot.
As with PPP dial-up, the IP addresses are assigned dynamically by the VPN gateway. This means that the VPN client is not always assigned the same IP address. On Windows PCs, this can lead to irregularities, especially when the IPSec connection is established and terminated multiple times. You can solve this problem by creating the file Lmhosts on the client PC (see also the documentation for your Windows operating system). In this file, enter the fixed assignment of the IP address to its name in the Windows environment for your target computer. For NT servers, the domain name must also be entered. If necessary, contact the system administrator in your department for the required data.
