Done a bit more playing this morning and something is definitely not playing nicely crossing my VLANs/subnets. My main LAN is untagged as is my main/trusted WIFi network. Main WiFi is where I connect our trusted devices. VLAN 20 is my IoT network (it also has a dedicated SSID) and this is where my ATV devices are located. My Primary controller was on my main WIFi (changed to IoT WiFi during my tests) and has been since I set it up 18 months ago. With my Roomie clients all on my main WiFi, I am able to auto discover the Apple TV Companions but when I try to control, I get a momentary pop up with a pairing pin on the ATV that quickly disappears and no corresponding pop up on my Roomie client.
First, I moved my iPhone to my IoT SSID from the main WIFi. Then I went to the Devices tab and pressed + and selected the same ATV Companion that I had already setup. I clicked Test and when the remote screen came up I got the pairing pin prompt as well as a pairing pin on the ATV which stayed up for entry. After successfully pairing, I am able to control the ATV.
Next, I tried using my Primary controller, but the results were unchanged. I then moved the Primary controller to the IoT SSID and had the same pairing/control success as with my iPhone.
When I put either device back on the main SSID, the behavior reverted to the original state (brief pin, unable to pair).
So something is amiss with my network that is causing this to not behave correctly. My firewall settings drop the IoT network from reaching my main LAN but allows established/related connections. I also have a rule that allows traffic from the IoT network to my Primary controller's IP address on the main LAN (IP changes when it connects to the IoT SSID).
Would you consider allowing Apple TV Companion connections to be relayed through the Primary controller? I can have the Primary controller live on the IoT network but my clients need to be on the main LAN. If control works from the Primary controller and it could relay from clients that would put this in a usable state for me.
https://youtu.be/vz3u6E3Fxi8 - this YouTube incorporates many of the principles for my network segregation and firewall rules as an illustration.