In order to escape AnyConnect for work, I am now running a Docker container with stunnel proxy on a local Mac mini server and tunneling my main other machine's traffic through it. PITA to set up, but so much easier to use day to day.

