<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with remote access object-groups/split-tunneling comman in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-with-remote-access-object-groups-split-tunneling-commands/m-p/1237659#M875424</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;object-groups ????? &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;ip local pool uservpnpool 172.30.0.1-172.30.0.254 mask 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip local pool engvpnpool 172.30.1.1-172.30.1.254 mask 255.255.255.0 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;access-lists split_tunnel_list1 standard permit x.x.x.x 255.x.x.x &lt;/P&gt;&lt;P&gt;access-lists split_tunnel_listx ???? &lt;/P&gt;&lt;P&gt;access-lists nonat extended permit ip any 192.168.x.x 255.255.255.x &lt;/P&gt;&lt;P&gt;access-lists nonat extended permit ip any 192.168.x.x 255.255.255.x &lt;/P&gt;&lt;P&gt;access-lists nonat extended permit ip any 192.168.252.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-lists ????? &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;global (Airband) 1 interface &lt;/P&gt;&lt;P&gt;nat (Inside) 0 access-list nonat &lt;/P&gt;&lt;P&gt;nat (Inside) 1 192.168.0.0 255.255.0.0 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;webvpn &lt;/P&gt;&lt;P&gt;enable XO &lt;/P&gt;&lt;P&gt;enable Airband &lt;/P&gt;&lt;P&gt;svc image disk0:/ anyconnect-win-2.2.pkg 1 &lt;/P&gt;&lt;P&gt;svc image disk0:/ anyconnect-linux...pkg2 &lt;/P&gt;&lt;P&gt;svc image disk0:/ anyconnect-mac.....pkg3 &lt;/P&gt;&lt;P&gt;svc enable &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;crypto isakmp policy 1 authentication pre-share &lt;/P&gt;&lt;P&gt;crypto isakmp policy 1 encryption aes-256 &lt;/P&gt;&lt;P&gt;crypto isakmp policy 1 hash sha &lt;/P&gt;&lt;P&gt;crypto isakmp policy 1 group 2 &lt;/P&gt;&lt;P&gt;crypto isakmp policy 1 lifetime 86400 &lt;/P&gt;&lt;P&gt;crypto isakmp enable ISP1 &lt;/P&gt;&lt;P&gt;crypto isakmp enable ISP2 &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set transform_set_namex esp-aes-256 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map dyn_map_nameX set transform-set transform_set_nameX &lt;/P&gt;&lt;P&gt;crypto dynamic-map dyn_map_nameX set pfs group2 &lt;/P&gt;&lt;P&gt;crypto map map_namex 65534 ipsec-isakmp dynamic dyn_map_nameX &lt;/P&gt;&lt;P&gt;crypto map map_namex interface ISP2_interface &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;username ???? (in a couple of weeks, I will add an ACS server and start using ldap authentication) &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;group-policy uservpn_policy1 internal &lt;/P&gt;&lt;P&gt;group-policy uservpn_policy1 attributes &lt;/P&gt;&lt;P&gt;banner value xxxxxxxx &lt;/P&gt;&lt;P&gt;banner value Autorized Persons Only! &lt;/P&gt;&lt;P&gt;dns-server value 192.168.x.x 192.168.x.x &lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol webvpn &lt;/P&gt;&lt;P&gt;vpn-idle-timeout 30 &lt;/P&gt;&lt;P&gt;vpn-session-timeout 30 &lt;/P&gt;&lt;P&gt;split-tunnel-policy tunnelspecified &lt;/P&gt;&lt;P&gt;split-network-list value split_tunnel_list1 &lt;/P&gt;&lt;P&gt;default-domain value domain_name &lt;/P&gt;&lt;P&gt;webvpn &lt;/P&gt;&lt;P&gt;default-domain value domain_name &lt;/P&gt;&lt;P&gt;split-dns value ???? &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;group-policy engvpn_policy1 internal &lt;/P&gt;&lt;P&gt;group-policy engvpn_policy1 attributes &lt;/P&gt;&lt;P&gt;banner value xxxxxxxxx &lt;/P&gt;&lt;P&gt;banner value Autorized Persons Only! &lt;/P&gt;&lt;P&gt;dns-server value 192.168.x.x 192.168.x.x &lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol webvpn &lt;/P&gt;&lt;P&gt;vpn-idle-timeout 30 &lt;/P&gt;&lt;P&gt;vpn-session-timeout 30 &lt;/P&gt;&lt;P&gt;split-tunnel-policy tunnelspecified &lt;/P&gt;&lt;P&gt;split-network-list value split_tunnel_list1 &lt;/P&gt;&lt;P&gt;default-domain value domain_name &lt;/P&gt;&lt;P&gt;webvpn &lt;/P&gt;&lt;P&gt;default-domain value domain_name &lt;/P&gt;&lt;P&gt;split-dns value ?????? &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;group-policy ssl_policy internal &lt;/P&gt;&lt;P&gt;group-policy ssl_policy attributes &lt;/P&gt;&lt;P&gt;banner value xxxxxxxx &lt;/P&gt;&lt;P&gt;banner value Autorized Persons Only! &lt;/P&gt;&lt;P&gt;dns-server value 192.168.x.x 192.168.x.x &lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol webvpn &lt;/P&gt;&lt;P&gt;vpn-idle-timeout 30 &lt;/P&gt;&lt;P&gt;vpn-session-timeout 30 &lt;/P&gt;&lt;P&gt;split-tunnel-policy tunnelspecified &lt;/P&gt;&lt;P&gt;split-network-list value split_tunnel_list1 &lt;/P&gt;&lt;P&gt;default-domain value domain_name &lt;/P&gt;&lt;P&gt;webvpn &lt;/P&gt;&lt;P&gt;url-list havent read documentation yet &lt;/P&gt;&lt;P&gt;svc keep-installer &lt;/P&gt;&lt;P&gt;svc keepalive &lt;/P&gt;&lt;P&gt;svc rekey &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;tunnel-group uservpn_tunnel type remote-access &lt;/P&gt;&lt;P&gt;tunnel-group uservpn_tunnel general-attributes &lt;/P&gt;&lt;P&gt;address-pool uservpnpool &lt;/P&gt;&lt;P&gt;default-group-policy uservpn_policy1 &lt;/P&gt;&lt;P&gt;tunnel-group uservpn_tunnel webvpn-attributes &lt;/P&gt;&lt;P&gt;tunnel-group uservpn_tunnel ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key XXXXXXXX &lt;/P&gt;&lt;P&gt;isakmp keepalive threshold 360 retry 10 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;tunnel-group engvpn_tunnel type remote-access &lt;/P&gt;&lt;P&gt;tunnel-group engvpn_tunnel general-attributes &lt;/P&gt;&lt;P&gt;address-pool engvpnpool &lt;/P&gt;&lt;P&gt;default-group-policy engvpn_policy1 &lt;/P&gt;&lt;P&gt;tunnel-group engvpn_tunnel webvpn-attributes &lt;/P&gt;&lt;P&gt;tunnel-group engvpn_tunnel ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key XXXXXXXX &lt;/P&gt;&lt;P&gt;isakmp keepalive threshold 360 retry 10 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;tunnel-group ssl_tunnel type remote-access &lt;/P&gt;&lt;P&gt;tunnel-group ssl_tunnel general-attributes &lt;/P&gt;&lt;P&gt;address-pool engvpnpool &lt;/P&gt;&lt;P&gt;default-group-policy ssl_policy &lt;/P&gt;&lt;P&gt;tunnel-group ssl_tunnel webvpn-attributes &lt;/P&gt;&lt;P&gt;tunnel-group ssl_tunnel ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key XXXXXXXX &lt;/P&gt;&lt;P&gt;isakmp keepalive threshold 360 retry 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Mar 2009 18:13:05 GMT</pubDate>
    <dc:creator>billy_anonymous</dc:creator>
    <dc:date>2009-03-03T18:13:05Z</dc:date>
    <item>
      <title>Help with remote access object-groups/split-tunneling commands</title>
      <link>https://community.cisco.com/t5/network-security/help-with-remote-access-object-groups-split-tunneling-commands/m-p/1237658#M875423</link>
      <description>&lt;P&gt;I'm tasked with designing a remote access solution through an ASA v8.0 and I started by creating a text file with configuration details like group-policy, tunnel-groups, crypto (the text file looks as if you typed show run)â&amp;#128;¦ I'm tasked with only the remote access portion of solution, not the full ACL, NAT statements. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone please proof-read what I have so far? Attached is a basic net diagram that will be the completed project. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have questions on the following: &lt;/P&gt;&lt;P&gt;1. What should the object-groups be if this firewall configured for remote-access? &lt;/P&gt;&lt;P&gt;2. How do I configure the split-tunneling portion? &lt;/P&gt;&lt;P&gt;3. Do I need more or less group-policies and tunnel-groups? &lt;/P&gt;&lt;P&gt;a. There is very little difference between the uservpn and engvpn groups &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone can help, I will be most appreciative. Keep in mind I'm still working on which commands to use so some of the config commands are missing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BillyBob &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:00:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-remote-access-object-groups-split-tunneling-commands/m-p/1237658#M875423</guid>
      <dc:creator>billy_anonymous</dc:creator>
      <dc:date>2019-03-11T15:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Help with remote access object-groups/split-tunneling comman</title>
      <link>https://community.cisco.com/t5/network-security/help-with-remote-access-object-groups-split-tunneling-commands/m-p/1237659#M875424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;object-groups ????? &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;ip local pool uservpnpool 172.30.0.1-172.30.0.254 mask 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip local pool engvpnpool 172.30.1.1-172.30.1.254 mask 255.255.255.0 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;access-lists split_tunnel_list1 standard permit x.x.x.x 255.x.x.x &lt;/P&gt;&lt;P&gt;access-lists split_tunnel_listx ???? &lt;/P&gt;&lt;P&gt;access-lists nonat extended permit ip any 192.168.x.x 255.255.255.x &lt;/P&gt;&lt;P&gt;access-lists nonat extended permit ip any 192.168.x.x 255.255.255.x &lt;/P&gt;&lt;P&gt;access-lists nonat extended permit ip any 192.168.252.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-lists ????? &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;global (Airband) 1 interface &lt;/P&gt;&lt;P&gt;nat (Inside) 0 access-list nonat &lt;/P&gt;&lt;P&gt;nat (Inside) 1 192.168.0.0 255.255.0.0 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;webvpn &lt;/P&gt;&lt;P&gt;enable XO &lt;/P&gt;&lt;P&gt;enable Airband &lt;/P&gt;&lt;P&gt;svc image disk0:/ anyconnect-win-2.2.pkg 1 &lt;/P&gt;&lt;P&gt;svc image disk0:/ anyconnect-linux...pkg2 &lt;/P&gt;&lt;P&gt;svc image disk0:/ anyconnect-mac.....pkg3 &lt;/P&gt;&lt;P&gt;svc enable &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;crypto isakmp policy 1 authentication pre-share &lt;/P&gt;&lt;P&gt;crypto isakmp policy 1 encryption aes-256 &lt;/P&gt;&lt;P&gt;crypto isakmp policy 1 hash sha &lt;/P&gt;&lt;P&gt;crypto isakmp policy 1 group 2 &lt;/P&gt;&lt;P&gt;crypto isakmp policy 1 lifetime 86400 &lt;/P&gt;&lt;P&gt;crypto isakmp enable ISP1 &lt;/P&gt;&lt;P&gt;crypto isakmp enable ISP2 &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set transform_set_namex esp-aes-256 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map dyn_map_nameX set transform-set transform_set_nameX &lt;/P&gt;&lt;P&gt;crypto dynamic-map dyn_map_nameX set pfs group2 &lt;/P&gt;&lt;P&gt;crypto map map_namex 65534 ipsec-isakmp dynamic dyn_map_nameX &lt;/P&gt;&lt;P&gt;crypto map map_namex interface ISP2_interface &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;username ???? (in a couple of weeks, I will add an ACS server and start using ldap authentication) &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;group-policy uservpn_policy1 internal &lt;/P&gt;&lt;P&gt;group-policy uservpn_policy1 attributes &lt;/P&gt;&lt;P&gt;banner value xxxxxxxx &lt;/P&gt;&lt;P&gt;banner value Autorized Persons Only! &lt;/P&gt;&lt;P&gt;dns-server value 192.168.x.x 192.168.x.x &lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol webvpn &lt;/P&gt;&lt;P&gt;vpn-idle-timeout 30 &lt;/P&gt;&lt;P&gt;vpn-session-timeout 30 &lt;/P&gt;&lt;P&gt;split-tunnel-policy tunnelspecified &lt;/P&gt;&lt;P&gt;split-network-list value split_tunnel_list1 &lt;/P&gt;&lt;P&gt;default-domain value domain_name &lt;/P&gt;&lt;P&gt;webvpn &lt;/P&gt;&lt;P&gt;default-domain value domain_name &lt;/P&gt;&lt;P&gt;split-dns value ???? &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;group-policy engvpn_policy1 internal &lt;/P&gt;&lt;P&gt;group-policy engvpn_policy1 attributes &lt;/P&gt;&lt;P&gt;banner value xxxxxxxxx &lt;/P&gt;&lt;P&gt;banner value Autorized Persons Only! &lt;/P&gt;&lt;P&gt;dns-server value 192.168.x.x 192.168.x.x &lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol webvpn &lt;/P&gt;&lt;P&gt;vpn-idle-timeout 30 &lt;/P&gt;&lt;P&gt;vpn-session-timeout 30 &lt;/P&gt;&lt;P&gt;split-tunnel-policy tunnelspecified &lt;/P&gt;&lt;P&gt;split-network-list value split_tunnel_list1 &lt;/P&gt;&lt;P&gt;default-domain value domain_name &lt;/P&gt;&lt;P&gt;webvpn &lt;/P&gt;&lt;P&gt;default-domain value domain_name &lt;/P&gt;&lt;P&gt;split-dns value ?????? &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;group-policy ssl_policy internal &lt;/P&gt;&lt;P&gt;group-policy ssl_policy attributes &lt;/P&gt;&lt;P&gt;banner value xxxxxxxx &lt;/P&gt;&lt;P&gt;banner value Autorized Persons Only! &lt;/P&gt;&lt;P&gt;dns-server value 192.168.x.x 192.168.x.x &lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol webvpn &lt;/P&gt;&lt;P&gt;vpn-idle-timeout 30 &lt;/P&gt;&lt;P&gt;vpn-session-timeout 30 &lt;/P&gt;&lt;P&gt;split-tunnel-policy tunnelspecified &lt;/P&gt;&lt;P&gt;split-network-list value split_tunnel_list1 &lt;/P&gt;&lt;P&gt;default-domain value domain_name &lt;/P&gt;&lt;P&gt;webvpn &lt;/P&gt;&lt;P&gt;url-list havent read documentation yet &lt;/P&gt;&lt;P&gt;svc keep-installer &lt;/P&gt;&lt;P&gt;svc keepalive &lt;/P&gt;&lt;P&gt;svc rekey &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;tunnel-group uservpn_tunnel type remote-access &lt;/P&gt;&lt;P&gt;tunnel-group uservpn_tunnel general-attributes &lt;/P&gt;&lt;P&gt;address-pool uservpnpool &lt;/P&gt;&lt;P&gt;default-group-policy uservpn_policy1 &lt;/P&gt;&lt;P&gt;tunnel-group uservpn_tunnel webvpn-attributes &lt;/P&gt;&lt;P&gt;tunnel-group uservpn_tunnel ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key XXXXXXXX &lt;/P&gt;&lt;P&gt;isakmp keepalive threshold 360 retry 10 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;tunnel-group engvpn_tunnel type remote-access &lt;/P&gt;&lt;P&gt;tunnel-group engvpn_tunnel general-attributes &lt;/P&gt;&lt;P&gt;address-pool engvpnpool &lt;/P&gt;&lt;P&gt;default-group-policy engvpn_policy1 &lt;/P&gt;&lt;P&gt;tunnel-group engvpn_tunnel webvpn-attributes &lt;/P&gt;&lt;P&gt;tunnel-group engvpn_tunnel ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key XXXXXXXX &lt;/P&gt;&lt;P&gt;isakmp keepalive threshold 360 retry 10 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;tunnel-group ssl_tunnel type remote-access &lt;/P&gt;&lt;P&gt;tunnel-group ssl_tunnel general-attributes &lt;/P&gt;&lt;P&gt;address-pool engvpnpool &lt;/P&gt;&lt;P&gt;default-group-policy ssl_policy &lt;/P&gt;&lt;P&gt;tunnel-group ssl_tunnel webvpn-attributes &lt;/P&gt;&lt;P&gt;tunnel-group ssl_tunnel ipsec-attributes &lt;/P&gt;&lt;P&gt;pre-shared-key XXXXXXXX &lt;/P&gt;&lt;P&gt;isakmp keepalive threshold 360 retry 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Mar 2009 18:13:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-remote-access-object-groups-split-tunneling-commands/m-p/1237659#M875424</guid>
      <dc:creator>billy_anonymous</dc:creator>
      <dc:date>2009-03-03T18:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Help with remote access object-groups/split-tunneling comman</title>
      <link>https://community.cisco.com/t5/network-security/help-with-remote-access-object-groups-split-tunneling-commands/m-p/1237660#M875426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;bump&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Mar 2009 14:29:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-with-remote-access-object-groups-split-tunneling-commands/m-p/1237660#M875426</guid>
      <dc:creator>billy_anonymous</dc:creator>
      <dc:date>2009-03-04T14:29:51Z</dc:date>
    </item>
  </channel>
</rss>

