📘 Step-by-Step Guide · Every Platform

Get connected to the cross-border network in three minutes

On Windows, macOS and Android, sign in to Yunoc with your website account to sync your lines. For iPhone / iPad, Linux and other clients, follow the setup steps below.

🍎 iPhone / iPad
1

Install the client

Search the App Store for "Cisco Secure Client" and install it (available in China).
2

Enable External Control · required

Open Cisco → Settings → "External Control" → set it to "Enabled". Skip this and none of the buttons below will do anything! One-time setup.
3

Register & sign in

Register with your email (you'll automatically get 24 hours free), then sign in here.
4

Create one connection first · required

Open the "Connection Info" page and tap "Create connection". A freshly installed Secure Client has no connections at all, and the two "import" buttons below require one to exist — skip this and you get "Please select a connection before attempting to import profile data." When iOS asks to allow the configuration, approve it and enter your device passcode (not your account password).
5

Install the certificate

Back on "Connection Info", tap "Install certificate" (nothing happens? External Control is probably off). Install it once and you never type a password again; keep the connection Certificate on Automatic or pick the one you imported.
6

Import all lines in one tap

Then tap "Import all lines" to pull every line into the client at once — each one carries backup addresses, so when you redial a line that is down is swapped automatically. The newly imported lines pick up the certificate from the previous step on their own.
7

Connect

Flip the switch in Secure Client. If the first attempt fails, that is normal — tap it once more and it connects password-free.
⚠️ On iPhone the order matters: create one connection → install the certificate → import all lines. Seeing "Please select a connection before attempting to import profile data." means you skipped the first one — a known iOS requirement.
Already using Shadowrocket?
There is no need to switch to Cisco: the Connection Info page now has a separate one-tap import. This route uses username and password and does not support certificate sign-in.
1

Open Connection Info

In Safari, sign in and open Member centre → Connection Info. Scroll to the bottom and expand Already using Shadowrocket? One-tap import. It appears only on iPhone / iPad.
2

Add every line at once · recommended

Tap Add all lines at once → allow iOS to open Shadowrocket → confirm the import in the app. Every line arrives together, and refreshing the subscription follows later line changes.
3

Button does nothing? Copy the subscription URL

Tap Copy subscription URL, create a Subscribe entry in Shadowrocket, paste and save the URL, then refresh the subscription.
4

Or add only one line

Each line underneath has Add / Copy. Adding one is useful temporarily, but it does not follow later line changes like a subscription does.
5

Pick a line and connect

Return to Shadowrocket and choose a line. It uses your username + connection password; the connection password is shown separately on the page and is not your website sign-in password.
6

Protect the subscription URL

The URL carries your connection password, so never forward it or include it in a screenshot. If it may have leaked, tap Revoke & reissue on Connection Info, then add it again. It expires after 90 days: imported lines keep working, and adding it again restores updates.
⚠️ Two acceleration apps cannot control the system connection at the same time. Fully quit the other app before using Shadowrocket — do not merely disconnect it.
🤖 Android
1

Install the latest Yunoc client

Install Yunoc from the Download Center and check the installer for system requirements. If Android warns about an unknown source, confirm the installer came from this website before allowing it. No "Account" page in the client? Update to a version that supports account sign-in.
2

Sign in with your website account

Open "Account" in Yunoc, enter your website email and sign-in password — not your connection password — and complete any security check. If you opened an account through Telegram, check the bot’s account-creation message for your website sign-in details.
3

Sync your plan and lines

After sign-in, your plan and available lines sync to the client. There is no need to import from the website first. Refresh them from "Account" when needed. Syncing does not connect automatically.
4

Choose a line and connect

Before your first connection, confirm the routing mode on this device in "Routing". Return to "Connection", choose a line and connect. Approve the system connection prompt; notifications help you keep track of connection status.
5

Already using imported or manual connections?

You can keep using them. For these options, follow the alternative setup instructions on the website’s "Connection Info" page. Account sync is recommended and does not require importing a certificate first.
6

Dropping after the screen turns off?

(1) Leave its notification on — that ongoing notification is what stops the system suspending it. (2) Turn on Always-on in Settings → Network & internet → Yunoc → the gear icon; the system keeps it running, which beats anything the app can do for itself (connect once by hand first). Leave the blocking switch on that same screen alone — with it on, the device has no network at all whenever the line is down. (3) On phones with aggressive power management, also exclude it from battery optimisation and allow background activity.
7

Cisco Secure Client also works

If you already use Cisco, or Yunoc will not install, keep using it: install it, turn on "External Control", then tap a line on the Connection Info page. One difference: Cisco on Android accepts at most 100 split rules while routing domestic traffic directly needs more than 800, so with Cisco everything goes through the tunnel.
🪟 Windows
1

Install the latest Yunoc client

Install Yunoc for Windows from the Download Center and check the installer for system requirements. No "Account" page in the client? Update to a version that supports account sign-in.
2

Sign in with your website account

Open "Account", enter your website email and sign-in password — not your connection password — and complete any security check. If you opened an account through Telegram, check the bot’s account-creation message for your website sign-in details.
3

Sync your lines and connect

Your plan and available lines sync after sign-in; no website import is needed. Confirm the routing mode on this device, then choose a line on "Gateway" and connect. Refresh your lines from "Account" when needed.
4

Other connection methods

Imported and manual connections still work. For Cisco Secure Client and other clients, open the alternative setup instructions for your device on "Connection Info" and choose password or certificate setup. These use different steps from Yunoc account sign-in.
💻 macOS
1

Install the latest Yunoc client

On an Apple silicon Mac, install Yunoc for macOS from the Download Center. Check the installer for system and chip requirements. No "Account" page in the client? Update to a version that supports account sign-in.
2

Sign in with your website account

Open "Account", enter your website email and sign-in password — not your connection password — and complete any security check. If you opened an account through Telegram, check the bot’s account-creation message for your website sign-in details.
3

Sync your lines and connect

Your plan and available lines sync after sign-in; no website import is needed. Confirm the routing mode on this device, then choose a line on "Gateway" and connect. Refresh your lines from "Account" when needed.
4

Intel Mac / other connection methods

Use Cisco Secure Client or the openconnect command-line client, following the alternative instructions for your device on "Connection Info". Imported and manual connections still work; Yunoc account sign-in does not require importing a certificate first.
🐧 Linux
1

Install the client

openconnect ships in the official repositories of every mainstream distribution — pick the line for your system:
Debian / Ubuntusudo apt update && sudo apt install -y openconnect
Fedorasudo dnf install -y openconnect
Arch / Manjarosudo pacman -S openconnect
Alpinesudo apk add openconnect
On RHEL / Rocky / AlmaLinux enable EPEL first. Run openconnect --version to confirm.
2

Sign in for your connection details

Sign in and open "Connection Info". Note three things: Username (your registered email), Connection password (not your website login password), and the server address of the line you want (it looks like somestring.domain:port). The Global / PAC choice is stored on your account — after switching, disconnect and reconnect once for it to take effect.
3

Connect

Use the address shown on "Connection Info" as-is; just prefix it with https://.
Replace the two placeholders below with your own values:
Connectsudo openconnect --protocol=anyconnect --user='your@email' "https://SERVER-ADDRESS"
Enter your connection password when prompted. ⚠️ Wrap the whole address in quotes — the ? is a shell wildcard, and without quotes zsh fails with no matches found before the command even runs.
4

Disconnecting and running in the background

In the foreground press Ctrl + C to disconnect. ⚠️ Never use kill -9 — only a clean exit restores your routing and name-resolution settings.
To run it in the background:
Backgroundecho 'CONNECTION-PASSWORD' | sudo openconnect --protocol=anyconnect --user='your@email' --passwd-on-stdin --background --pid-file=/run/oc.pid "https://SERVER-ADDRESS"
Stopsudo kill $(cat /run/oc.pid)
Note this leaves the password in your shell history; use read -s into a variable if that matters to you.
5

Password-free connection (optional)

On "Connection Info" expand "Advanced · certificate" → download the .p12 → run:
Certificatesudo openconnect --protocol=anyconnect --certificate=/absolute/path/downloaded.p12 "https://CERTIFICATE-ADDRESS"
Normally you will not be asked for a passphrase. If you do see Enter PKCS#12 pass phrase:, just press Enter (the passphrase is empty) — both behaviours are normal. The download link is valid for 30 minutes; the certificate itself also expires, after which you download a fresh one from the same page.
6

Cannot connect? Check in this order

① Refused immediately by the server → the address was copied wrong, or that line is not available on your plan;
② Terminal says no matches found or the address is mangled → you forgot the quotes;
③ Permission error / cannot create the network device → add sudo;
④ Shows connected but nothing loads → some minimal systems lack the companion network-configuration script; installing from your distribution's official repository normally includes it;
⑤ Want a different line → swap in another address from "Connection Info"; everything else stays the same.
📶 OpenWrt Router
1

Check the firmware and local access

This route is for users familiar with LuCI / SSH. Make sure you can recover through a local wired connection; do not change routes over your only remote connection. Check the version, free space and installed package manager. Do not infer these from a Kwrt or vendor version number alone:
Systemcat /etc/openwrt_release
Package managercommand -v apk; command -v opkg
Resources and clockdf -h; free; date
2

Install the required packages

Use only the set matching this firmware and its repositories. If both managers are present, or neither is available, consult the firmware instructions first:
opkgopkg update && opkg install openconnect luci-proto-openconnect ca-bundle
apkapk update && apk add openconnect luci-proto-openconnect ca-bundle
Do not mix repositories from other releases or bulk-upgrade system packages. Check the clock and keep certificate verification enabled. If LuCI does not show the protocol after installation, follow the firmware instructions to refresh the page or reload rpcd.
3

Create the connection in LuCI

Under Network → Interfaces, create an unused interface named occ and select the OpenConnect / AnyConnect protocol. Leave automatic startup off for now. Enter the complete address shown for Cisco / openconnect on Connection Info, your email and your connection password — not your website password. Preserve the port, path and query; add https:// only once. Leave certificate-login fields empty and do not enter an unknown fingerprint to bypass verification. Do not overwrite an existing interface. Review pending changes before saving and applying, but do not start it yet. Keep passwords out of shell history and support messages.
4

Select the actual uplink

Find the logical uplink interface in LuCI: it may be wan, wwan or another name, not the physical device name. If the form lacks this option, use SSH. These commands apply only after verifying occ and wan:
Check protocol and pending changes firstuci get network.occ.proto; uci changes network
Disable automatic startupuci set network.occ.auto='0'
Set the verified uplinkuci set network.occ.interface='wan'
Saveuci commit network
The protocol must be openconnect, with no unrelated pending changes. The uplink dependency is intended to keep the connection server reachable over WAN. Check it together with the full URI, then verify the active route.
5

Check LAN forwarding and the exit path

Check the actual firewall zones in Network → Firewall. A common setup adds occ to the existing WAN outbound zone; verify LAN forwarding, IPv4 masquerading and MSS settings. A separate zone needs these checked too. Do not rename zones by index, disable the firewall or expose management services on WAN. Review changes before applying and keep local recovery access. MSS adjustment does not replace checking the actual MTU. This is not a kill-switch configuration: disconnection may return traffic to your broadband connection.
6

Connect manually and verify each layer

Start only the verified interface:
Connectifup occ
Statusubus call network.interface.occ status
Loglogread -e openconnect
Policy rulesip -4 rule show
Active routesip -4 route show table all
Check in order: tunnel transmit/receive → DNS and HTTPS on the router → browsing and exit path on a LAN device. Connected status or a successful ping is not enough. Connect the test phone only to this router’s Wi-Fi; turn off mobile data and its own proxy. An upstream management computer retaining its broadband exit is expected. Check IPv4 and IPv6 separately; do not assume every flow is handled. Enable automatic startup only after verification. To stop, use ifdown occ.
7

Connected, but nothing loads?

Show troubleshooting: no receive traffic, LAN failures or stalled pages

No receive traffic and the router is offline: check the full https:// URI, the actual uplink and the server route over WAN. An empty hostname in adding host dependency for at ... is a clue to URI parsing, not proof of an authentication error. Check policy routing too; do not delete the WAN gateway or permanently pin the server IP.

The router works, but LAN devices do not: check their gateway and DNS, then the loaded forwarding / NAT rules, guest networks and other routing tools. On fw4 firmware, nft list ruleset is a read-only check. A page setting does not prove the rule is loaded.

Ping or chat works, but HTTPS stalls: first rule out certificate, destination and DNS problems, then check the runtime device MTU. The form’s 1406 may only be a placeholder; --mtu requests a value from the server, not proof that the device uses it. Find the actual l3_device in interface status, refresh its device page or run ip -s link show dev "ACTUAL-DEVICE".

Comparing MTU values: record the original settings and change one thing at a time. If the runtime value still differs after saving the interface MTU and reconnecting, configure that same device only if the firmware supports it. Do not change WAN/LAN or create a new bridge. 1406 worked in the supplied Kwrt case; it is not a universal recommendation. If the old process keeps reporting Failed to write incoming packet: I/O error after applying the change, stop with ifdown occ and start with ifup occ. Recheck MTU and HTTPS on both router and LAN. If it does not help, restore the original values; remove a device entry only if this experiment created it and nothing else uses it.

Authentication, certificate or transport errors: stop repeated authentication attempts and check the connection password, plan and session allowance. For certificate errors, check the clock, address and trust store; do not bypass verification. Compare no_dtls separately only after routing, DNS and MTU checks, and restore its original state. Plain TCP is not guaranteed to be more reliable.

The member Docs Center’s “OpenWrt router guide” has the full steps and recovery instructions. Redact email, complete connection addresses and credentials before sharing logs; do not send a full configuration containing passwords.
⚠️ Advanced, self-service router setup
This uses community packages, not our own router firmware. We have referenced one Kwrt 25.12 snapshot case; this does not validate all models or long-term reconnection.
These steps troubleshoot a global IPv4 connection. PAC / return routing, IPv6 and DNS paths depend on firmware and local policy. A website switch does not prove split routing is active on the router.
Username and connection password are recommended. Certificate setup requires separate expiry and renewal management. Verify connection status, router access and LAN access separately.

One account for your devices

On Windows, macOS and Android, sign in to Yunoc with your website account, sync your lines and connect. For other clients, open "Connection Info" for setup instructions. Contact support if you need help.

Sign In / Register