<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyconnect Local Lan Access + split tunnel exclude in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4490755#M1084565</link>
    <description>&lt;P&gt;Thank you both for the reply. Unfortunately it was a mistake on my part - I forgot to check if users have the Allow local(LAN) access when using VPN .......they did not and I also did not have it on ( new PC). After checking the box the users were able to connect to the VPN, splt tunnel for zScaler traffic worked as expected and also access their local LAN.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture-Allow Local LAN access.PNG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/135411i3E503C3F73C98A99/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture-Allow Local LAN access.PNG" alt="Capture-Allow Local LAN access.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Oct 2021 15:31:27 GMT</pubDate>
    <dc:creator>buffkata</dc:creator>
    <dc:date>2021-10-22T15:31:27Z</dc:date>
    <item>
      <title>Anyconnect Local Lan Access + split tunnel exclude</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4490204#M1084551</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Recently we added zScaler IPs to our existing Local LAN Access ACL. The idea was that since this ACL is a split tunnel exclude it will exclude the zScaler IPs as well. This way RAVPN users will have their HTTP/s traffic protected by the cloud proxy and this will lower the load on the FTD&amp;nbsp; edge firewall we use to provide Anyconnect VPN to users.&lt;/P&gt;&lt;P&gt;Unfortunately the zScaler traffic was excluded from the tunnel but users lost Local LAN Access - even though the ACL still has the following line and this should be allowed - but all Local traffic is directed to the VPN tunnel. (We tried moving the host 0.0.0.0 on top and bottom of the ACL but nothing changed.)&lt;/P&gt;&lt;P&gt;It would be nice if anyone has an idea if this is not permitted - this way I will stop searching the internet &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 00:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4490204#M1084551</guid>
      <dc:creator>buffkata</dc:creator>
      <dc:date>2021-10-22T00:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect Local Lan Access + split tunnel exclude</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4490293#M1084558</link>
      <description>&lt;P&gt;i would expect on the ASA side the split tunnel ACL to be separate match, (not standard ACL)&lt;/P&gt;
&lt;P&gt;and attach the ACL to any connect config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;example :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;refer below document for example :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/119006-configure-anyconnect-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/119006-configure-anyconnect-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215383-asa-anyconnect-dynamic-split-tunneling.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/215383-asa-anyconnect-dynamic-split-tunneling.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 05:15:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4490293#M1084558</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-10-22T05:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect Local Lan Access + split tunnel exclude</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4490565#M1084561</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Unfortunately the zScaler traffic was excluded from the tunnel but users lost Local LAN Access - even though the ACL still has the following line and this should be allowed - but all Local traffic is directed to the VPN tunnel. (We tried moving the host 0.0.0.0 on top and bottom of the ACL but nothing changed.)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-I have used a standard acl for local lan access several times before so IMO that is not the issue.&amp;nbsp; Have you tested just the all zeros to ensure the local lan access works as expected first?&amp;nbsp; What does AC depict when doing so?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 12:10:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4490565#M1084561</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-10-22T12:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect Local Lan Access + split tunnel exclude</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4490755#M1084565</link>
      <description>&lt;P&gt;Thank you both for the reply. Unfortunately it was a mistake on my part - I forgot to check if users have the Allow local(LAN) access when using VPN .......they did not and I also did not have it on ( new PC). After checking the box the users were able to connect to the VPN, splt tunnel for zScaler traffic worked as expected and also access their local LAN.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture-Allow Local LAN access.PNG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/135411i3E503C3F73C98A99/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture-Allow Local LAN access.PNG" alt="Capture-Allow Local LAN access.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 15:31:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4490755#M1084565</guid>
      <dc:creator>buffkata</dc:creator>
      <dc:date>2021-10-22T15:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect Local Lan Access + split tunnel exclude</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4490797#M1084567</link>
      <description>&lt;P&gt;Good stuff.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 16:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4490797#M1084567</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-10-22T16:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect Local Lan Access + split tunnel exclude</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4578046#M1088605</link>
      <description>&lt;P&gt;I see the same behavior on another FTD - 2130 in ASA mode.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Local Access is not working - but zScaler works. If I remove zScaler and leave only local access - Local Access is still not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;Again this was caused by my mistake - it looks like I had to reboot the test PC - after I made the change on the FTD. It looks like reconnecting to the VPN was not enough. Editing the original post -as I cannot delete the question, and maybe someone will find it useful.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 19:23:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-local-lan-access-split-tunnel-exclude/m-p/4578046#M1088605</guid>
      <dc:creator>buffkata</dc:creator>
      <dc:date>2022-03-24T19:23:48Z</dc:date>
    </item>
  </channel>
</rss>

