<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Force one website through VPN allow others to use home internet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058637#M1068716</link>
    <description>&lt;P&gt;Yes, we are using the any connect client, I will take a look at this article. Thank you.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Apr 2020 18:39:47 GMT</pubDate>
    <dc:creator>meditinst</dc:creator>
    <dc:date>2020-04-03T18:39:47Z</dc:date>
    <item>
      <title>Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058591#M1068706</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an ASA 5515, when our uses use the VPN they can access the local file servers just fine.&amp;nbsp; But when they browse the internet they use their home internet, from what I understand this is split tunneling.&amp;nbsp; Unfortunately, we have a website that uses our public IP to verify us and when users are at home it is using their home IP instead of the work IP.&amp;nbsp; Is there a way to force traffic to this one website to go through the VPN?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 18:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058591#M1068706</guid>
      <dc:creator>meditinst</dc:creator>
      <dc:date>2020-04-03T18:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058603#M1068709</link>
      <description>&lt;P&gt;Are you using cisco any connect client to connect to VPN,&amp;nbsp; then below guide help to buil split tunnel :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/anyconnect-split-tunneling-local-lan-access-split-tunneling/ta-p/4050866" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-documents/anyconnect-split-tunneling-local-lan-access-split-tunneling/ta-p/4050866&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 18:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058603#M1068709</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-04-03T18:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058618#M1068712</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You would need to amend your split tunnel ACL to include the IP address of the website, in order to tunnel this traffic back to the main site. E.g:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;access-list SPLIT_TUNNEL standard permit &lt;STRONG&gt;5.5.5.5&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;You would then need to NAT the outbound traffic for the Remote Access VPN users, e.g:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;object network RAVPN_USERS&lt;BR /&gt;subnet &lt;STRONG&gt;192.168.10.0 255.255.255.0&lt;/STRONG&gt;&lt;BR /&gt;nat (outside,outside) dynamic interface&lt;/PRE&gt;&lt;P&gt;You need to also enable the command below, in order to permit the Remote Access VPN users traffic to be routed back out the outside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;same-security-traffic permit intra-interface&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 18:22:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058618#M1068712</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-04-03T18:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058637#M1068716</link>
      <description>&lt;P&gt;Yes, we are using the any connect client, I will take a look at this article. Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 18:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058637#M1068716</guid>
      <dc:creator>meditinst</dc:creator>
      <dc:date>2020-04-03T18:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058669#M1068719</link>
      <description>&lt;P&gt;So I now have this,&lt;/P&gt;&lt;P&gt;access-list acl-clientvpn extended permit ip object 3.223.182.53 any&lt;BR /&gt;access-list acl-clientvpn extended permit ip object 50.19.8.245 any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried, any, outside and the ip range of the VPN users but now the website just doesn't load at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am guessing that's because I am missing this part,&lt;/P&gt;&lt;PRE&gt;object network RAVPN_USERS&lt;BR /&gt;subnet &lt;STRONG&gt;192.168.10.0 255.255.255.0&lt;/STRONG&gt;&lt;BR /&gt;nat (outside,outside) dynamic interface&lt;/PRE&gt;&lt;P&gt;So I need to create a NAT rule to allow my VPN users ip's to go out?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am also guessing this won't affect the current VPN users or should I wait until tonight to do this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 19:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058669#M1068719</guid>
      <dc:creator>meditinst</dc:creator>
      <dc:date>2020-04-03T19:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058677#M1068720</link>
      <description>Your nat rule will obviously have to reflect your correct VPN IP Pool network (s) AND you will need the command "same-security-traffic permit intra-interface" for the anyconnect users.&lt;BR /&gt;&lt;BR /&gt;You should be able to make these changes now, they would only apply to traffic sourced from the RAVPN Pool network on the outside interface destined to the outside interface.&lt;BR /&gt;&lt;BR /&gt;You should also check your other rules which might conflict.&lt;BR /&gt;&lt;BR /&gt;If this still doesn't work post your configuration and the output of "show nat detail"</description>
      <pubDate>Fri, 03 Apr 2020 19:33:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4058677#M1068720</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-04-03T19:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4092732#M1070504</link>
      <description>Thanks, that worked for me!&lt;BR /&gt;For anyone testing, you need to reconnect to the VPN after making changes.</description>
      <pubDate>Wed, 27 May 2020 10:25:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4092732#M1070504</guid>
      <dc:creator>qwerty321</dc:creator>
      <dc:date>2020-05-27T10:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4121815#M1072137</link>
      <description>&lt;P&gt;I did that piece and I got the website to work.&amp;nbsp; The problem is that when I did that, I broke access to our servers in Azure, which obviously sit outside our internal network.&amp;nbsp; Any help would be appreciated.&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 13:00:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4121815#M1072137</guid>
      <dc:creator>cjones615</dc:creator>
      <dc:date>2020-07-20T13:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4121838#M1072138</link>
      <description>&lt;P&gt;Hi&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1076881"&gt;@cjones615&lt;/a&gt; start a new post, provide your existing configuration and provide information of which command you configured which broke access to Azure.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 13:25:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4121838#M1072138</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-07-20T13:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4121892#M1072141</link>
      <description>&lt;P&gt;done&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/issues-with-vpn-configuration/m-p/4121891#M1072140" target="_blank"&gt;https://community.cisco.com/t5/network-security/issues-with-vpn-configuration/m-p/4121891#M1072140&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 14:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4121892#M1072141</guid>
      <dc:creator>cjones615</dc:creator>
      <dc:date>2020-07-20T14:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4873753#M1102639</link>
      <description>&lt;P&gt;Good afternoon,&lt;BR /&gt;&lt;BR /&gt;I was checking the conversation.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In my case, we are trying to use our VPN to connect to the website. But the website is located behind&amp;nbsp;&lt;SPAN&gt;Cloudflare, and the Website's IP can change.&lt;BR /&gt;&lt;BR /&gt;Is it something that we can implement to help us?&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 16:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4873753#M1102639</guid>
      <dc:creator>joselyngm</dc:creator>
      <dc:date>2023-07-13T16:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4873761#M1102640</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1548958"&gt;@joselyngm&lt;/a&gt; my initial suggestion would be to add all the cloudflare IP addresses to the allow tunnel list - &lt;A href="https://www.cloudflare.com/en-gb/ips/" target="_blank"&gt;https://www.cloudflare.com/en-gb/ips/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Else run a full tunnel but with dynamic split tunnel for intensive applications such as Webex or MS Teams etc.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 17:17:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4873761#M1102640</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-07-13T17:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Force one website through VPN allow others to use home internet</title>
      <link>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4873894#M1102641</link>
      <description>&lt;P&gt;Thank you so much!!&amp;nbsp;&lt;SPAN&gt;That worked.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 21:31:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/force-one-website-through-vpn-allow-others-to-use-home-internet/m-p/4873894#M1102641</guid>
      <dc:creator>joselyngm</dc:creator>
      <dc:date>2023-07-13T21:31:19Z</dc:date>
    </item>
  </channel>
</rss>

