<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: split tunnel based on remote user location in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/split-tunnel-based-on-remote-user-location/m-p/1501616#M312821</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi their sure you can do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your User conencts you have to assign him a dACL and Shared RAC based on the Network Access Profile and the NAF for your locations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EG:&lt;/P&gt;&lt;P&gt;create a Network Access Filter for Germany with all your german ASAs one for Italy with all your italian ASAs etc.&lt;/P&gt;&lt;P&gt;create a "Germany" Shared RAC with the important german settings (DNS wins etc)&lt;/P&gt;&lt;P&gt;Create a "Italy" Shared RAC with the settings for Italy&lt;/P&gt;&lt;P&gt;create dACL (for each location)&lt;/P&gt;&lt;P&gt;then go and create a Network access Profile for germany and one for italy - apply the network filter and assign&amp;nbsp; under authorization the dACL and sRAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should work without problems&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe have a look here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/sp.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/sp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Jul 2010 07:53:30 GMT</pubDate>
    <dc:creator>Michael Dombek</dc:creator>
    <dc:date>2010-07-01T07:53:30Z</dc:date>
    <item>
      <title>split tunnel based on remote user location</title>
      <link>https://community.cisco.com/t5/network-access-control/split-tunnel-based-on-remote-user-location/m-p/1501615#M312812</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For remote vpn users, I would like to configure a dynamic vpn split tunnel depending where are they connected.&lt;/P&gt;&lt;P&gt;For example if a remote user is connected to ASA from italy, auth via acs radius server, a split tunnel list will be applied allowing user to access local resources, if the same user is connecting from germany, apply a split tunnel list allowing the local resources for germany office...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it possible to achieve this? any link or documentation related?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your support&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:13:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/split-tunnel-based-on-remote-user-location/m-p/1501615#M312812</guid>
      <dc:creator>franpena2008</dc:creator>
      <dc:date>2019-03-11T00:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: split tunnel based on remote user location</title>
      <link>https://community.cisco.com/t5/network-access-control/split-tunnel-based-on-remote-user-location/m-p/1501616#M312821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi their sure you can do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your User conencts you have to assign him a dACL and Shared RAC based on the Network Access Profile and the NAF for your locations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EG:&lt;/P&gt;&lt;P&gt;create a Network Access Filter for Germany with all your german ASAs one for Italy with all your italian ASAs etc.&lt;/P&gt;&lt;P&gt;create a "Germany" Shared RAC with the important german settings (DNS wins etc)&lt;/P&gt;&lt;P&gt;Create a "Italy" Shared RAC with the settings for Italy&lt;/P&gt;&lt;P&gt;create dACL (for each location)&lt;/P&gt;&lt;P&gt;then go and create a Network access Profile for germany and one for italy - apply the network filter and assign&amp;nbsp; under authorization the dACL and sRAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should work without problems&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe have a look here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/sp.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/sp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jul 2010 07:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/split-tunnel-based-on-remote-user-location/m-p/1501616#M312821</guid>
      <dc:creator>Michael Dombek</dc:creator>
      <dc:date>2010-07-01T07:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: split tunnel based on remote user location</title>
      <link>https://community.cisco.com/t5/network-access-control/split-tunnel-based-on-remote-user-location/m-p/1501617#M312832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am working with ACS appliance v 5.1 for radius authentication&lt;SPAN style="background-color: #f8fafd;"&gt;/authorization&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;All clients are connecting to the same central ASA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I have found in ACS Policy Elements - End station filters - Where I think I can diffrentiate where are the clients located.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Anybody knows if end station filters refer to the clients network or to the asa?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thnks and best regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Fran&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jul 2010 13:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/split-tunnel-based-on-remote-user-location/m-p/1501617#M312832</guid>
      <dc:creator>franpena2008</dc:creator>
      <dc:date>2010-07-01T13:13:54Z</dc:date>
    </item>
  </channel>
</rss>

