Alright, let's wade into the murky, frustrating waters of corporate network overlays, shall we? I'm here to talk about the specific, teeth-grinding scenario where Twingate, the shiny new zero-trust contender, has to coexist with the entrenched legacy behemoth: the always-on, corporate-mandated VPN. In my case, it's Cisco AnyConnect, but I suspect this is a genre of pain, not a singular title.
The setup is textbook: Windows 11 enterprise machine, AnyConnect is configured to auto-connect and essentially *become* the default route for all traffic. It's a religion for the security team. Then, we layer on Twingate for specific, granular access to development resources. In theory, they should play nice. In practice? It's a carnival of intermittent failures. Twingate clients will just... lose their minds. Connections to Twingate resources timeout, the system tray icon flickers between connected and reconnecting, and sometimes the whole service just gives up and needs a manual restart. The kicker? It's not reproducible on demand. It happens just often enough to destroy a flow state during a deployment, but vanishes when you call IT support.
Now, I've done the dance. I've looked at the routing tables when both are active, and it's a Rube Goldberg machine of priorities and exceptions. AnyConnect, by design, wants to own the stack. Twingate, to do its job, needs to intercept and redirect specific traffic. When two pieces of software both think they're the network sheriff, you get a silent, probabilistic shootout where my productivity is the casualty. I've seen suggestions about split-tunneling configurations on the AnyConnect side, but convincing the network overlords to modify their sacred always-on profile for a "newfangled" tool is a negotiation worthy of its own thread.
So, the real question for this community isn't just "does it happen?"—I know it does. It's whether anyone has successfully brokered a *stable* ceasefire between these two forces. What specific routing adjustments, client ordering (install Twingate before/after AnyConnect?), or service dependencies have you enforced? Has anyone moved beyond workarounds like "just disable the always-on VPN when you need Twingate" (a non-starter for compliance) to an actual harmonious configuration? Or are we all just quietly accepting that zero-trust and always-on traditional VPNs on the same Windows endpoint is fundamentally, philosophically, and practically broken?
—Bella
Price ≠ value.