<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyconnect + ASA split tunneling limitation [information request] in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638549#M1091254</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1171234"&gt;@Amen&lt;/a&gt; I've seen no documentation on the limits or recommendations of the number of split-tunnel routes. Can you not summarise the network routes, that would be more efficient than defining 100s of routes in the split tunnel ACL.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jun 2022 15:22:47 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-06-24T15:22:47Z</dc:date>
    <item>
      <title>Anyconnect + ASA split tunneling limitation [information request]</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638492#M1091248</link>
      <description>&lt;P&gt;&lt;SPAN class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" data-header-only="false" data-section-id="8793d5ff0a0a3c08548b83ca00e3bc1a" aria-hidden="false" aria-labelledby="section_tab.8793d5ff0a0a3c08548b83ca00e3bc1a"&gt;&lt;SPAN class="section " data-header-only="false"&gt;&lt;SPAN&gt;We have the following devices for our company VPNs:&lt;BR /&gt;&lt;BR /&gt;* Concentrator: Cisco Adaptive Security Appliance Software Version&lt;BR /&gt;9.8(4)40,&lt;BR /&gt;* Client: Cisco Anyconnect version 4.9.00086&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;We have already implemented split tunneling with a couple of subnets that &lt;BR /&gt;go through the tunnel and a default route 0/0 that goes to the internet &lt;BR /&gt;directly.&lt;BR /&gt;&lt;BR /&gt;We wanted to know if there’s a limitation regarding the number of subnets &lt;BR /&gt;that we can configure on the split tunneling policy to go through the VPN. &lt;BR /&gt;Nowadays we have only 5 routes but we’ll have to configure about 150 &lt;BR /&gt;subnets (or more).&lt;BR /&gt;&lt;BR /&gt;We have not found any official documentation regarding this information.&lt;BR /&gt;&lt;BR /&gt;Is there any limitation? If yes, could you please tell us what’s the limit? or if there are any documents in the cisco Portal?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" data-header-only="false" data-section-id="8793d5ff0a0a3c08548b83ca00e3bc1a" aria-hidden="false" aria-labelledby="section_tab.8793d5ff0a0a3c08548b83ca00e3bc1a"&gt;&lt;SPAN class="section " data-header-only="false"&gt;&lt;SPAN&gt;Thanks &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 13:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638492#M1091248</guid>
      <dc:creator>Amen</dc:creator>
      <dc:date>2022-06-24T13:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect + ASA split tunneling limitation [information request]</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638496#M1091249</link>
      <description>&lt;P&gt;i do not see any Limitation as per i know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but look at the thread :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/vpn/asa-anyconnect-restrictions-for-split-tunneling-network-list/td-p/2328881" target="_blank"&gt;https://community.cisco.com/t5/vpn/asa-anyconnect-restrictions-for-split-tunneling-network-list/td-p/2328881&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 14:03:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638496#M1091249</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-06-24T14:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect + ASA split tunneling limitation [information request]</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638503#M1091250</link>
      <description>&lt;P&gt;Thanks, but I see it's quite old,((&amp;nbsp; &lt;SPAN&gt;ASA 5520 firmware version 9.1.1 with setting up SSL VPN Anyconnect(Anyconnect client version 2.5.605)))) but mine are ASA &lt;SPAN class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" data-header-only="false" data-section-id="8793d5ff0a0a3c08548b83ca00e3bc1a" aria-hidden="false" aria-labelledby="section_tab.8793d5ff0a0a3c08548b83ca00e3bc1a"&gt;&lt;SPAN class="section " data-header-only="false"&gt;9.8(4)40,&amp;nbsp; and Anyconnect 4.9.+.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;there must be a change now. do you have some links or formal resources?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 14:20:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638503#M1091250</guid>
      <dc:creator>Amen</dc:creator>
      <dc:date>2022-06-24T14:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect + ASA split tunneling limitation [information request]</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638511#M1091251</link>
      <description>&lt;P&gt;Not that i can direct you, i use latest 9.14.X we have many ACL(like 100+)&amp;nbsp; not see that issue, that is the reason posted that URL for reference.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 14:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638511#M1091251</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-06-24T14:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect + ASA split tunneling limitation [information request]</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638527#M1091252</link>
      <description>&lt;P&gt;&lt;SPAN class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" data-header-only="false" data-section-id="8793d5ff0a0a3c08548b83ca00e3bc1a" aria-hidden="false" aria-labelledby="section_tab.8793d5ff0a0a3c08548b83ca00e3bc1a"&gt;&lt;SPAN class="section " data-header-only="false"&gt;&lt;SPAN&gt;Thanks for your reply. Did you mean 100 routes/subnets/lines maybe? The question is not how many tunnels we can configure but how many lines in the ACL (routes or subnets to be sent to the VPN connection) can be supported by the client + firewall. I suppose the limitation will come from the client, not the concentrator.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 14:45:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638527#M1091252</guid>
      <dc:creator>Amen</dc:creator>
      <dc:date>2022-06-24T14:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect + ASA split tunneling limitation [information request]</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638549#M1091254</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1171234"&gt;@Amen&lt;/a&gt; I've seen no documentation on the limits or recommendations of the number of split-tunnel routes. Can you not summarise the network routes, that would be more efficient than defining 100s of routes in the split tunnel ACL.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 15:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4638549#M1091254</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-06-24T15:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect + ASA split tunneling limitation [information request]</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4649403#M1091802</link>
      <description>&lt;P&gt;there are no limitations,&lt;/P&gt;
&lt;P&gt;Subnets or prefixes are represented as objects. You can have over 500 objects created&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 09:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-asa-split-tunneling-limitation-information-request/m-p/4649403#M1091802</guid>
      <dc:creator>Amen</dc:creator>
      <dc:date>2022-07-13T09:18:50Z</dc:date>
    </item>
  </channel>
</rss>

