<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WebVPN (Split Tunnel w/ extended ACL) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/webvpn-split-tunnel-w-extended-acl/m-p/1009202#M918781</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I found a fix....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to define and match on a standard wide open network and or host acl and then use the 'vpn-filter value' command to get granular on the standard one you created. If that doesn't make sense here's the config....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA# sh run | begin group-policy Company-ABC-WebVPN internal&lt;/P&gt;&lt;P&gt;group-policy Company-ABC-WebVPN internal&lt;/P&gt;&lt;P&gt;group-policy Company-ABC-WebVPN attributes&lt;/P&gt;&lt;P&gt; dns-server value 192.168.0.21 192.168.0.11&lt;/P&gt;&lt;P&gt; vpn-access-hours none&lt;/P&gt;&lt;P&gt; vpn-simultaneous-logins 10&lt;/P&gt;&lt;P&gt; vpn-filter value Company-ABC-Access-VPN-Network-List&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol webvpn&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Company-ABC-NONSPECIFIC-Access-VPN-Network-List&lt;/P&gt;&lt;P&gt; address-pools value Remote-Access-VPN-Pool&lt;/P&gt;&lt;P&gt; webvpn&lt;/P&gt;&lt;P&gt;  functions url-entry file-access file-entry file-browsing port-forward auto-download&lt;/P&gt;&lt;P&gt;  url-list value Company-ABC&lt;/P&gt;&lt;P&gt;  port-forward value Company-ABC-Access&lt;/P&gt;&lt;P&gt;  port-forward-name value Application Access&lt;/P&gt;&lt;P&gt;  svc enable&lt;/P&gt;&lt;P&gt;  svc keep-installer installed&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List remark Allow VPN Access to Demo-DMZ&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.145 eq 5802&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.145 eq 5902&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.145 eq 8080&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.145 eq ssh&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.147 eq 5802&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.147 eq 5902&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.147 eq 8080&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.147 eq ssh&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.148 eq 3389&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.131 eq 3389&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.135 eq 3389&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 192.168.0.11 eq domain&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 192.168.0.21 eq domain&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit udp any host 192.168.0.11 eq domain&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit udp any host 192.168.0.21 eq domain&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list Company-ABC-NONSPECIFIC-Access-VPN-Network-List remark Allow VPN Access to Demo-DMZ&lt;/P&gt;&lt;P&gt;access-list Company-ABC-NONSPECIFIC-Access-VPN-Network-List standard permit 1.1.1.128 255.255.255.224&lt;/P&gt;&lt;P&gt;access-list Company-ABC-NONSPECIFIC-Access-VPN-Network-List standard permit host 192.168.0.21&lt;/P&gt;&lt;P&gt;access-list Company-ABC-NONSPECIFIC-Access-VPN-Network-List standard permit host 192.168.0.11&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 07 Jun 2008 17:28:26 GMT</pubDate>
    <dc:creator>scottlivingston</dc:creator>
    <dc:date>2008-06-07T17:28:26Z</dc:date>
    <item>
      <title>WebVPN (Split Tunnel w/ extended ACL)</title>
      <link>https://community.cisco.com/t5/network-security/webvpn-split-tunnel-w-extended-acl/m-p/1009201#M918780</link>
      <description>&lt;P&gt;ASA 7.2.3 code / ASDM 5.2&lt;/P&gt;&lt;P&gt;Yesterday I converted a customer from the WebVPN portal to the SVC client (sslclient-win-1.1.4.179).  I must of spent 2hrs trying to figure out why the split tunneling wasn't working. I had the acl configured for the tunnel networks and had it tied to the group policy - nothing I tried seemed to fix this problem!  The SVC client said that split tunneling was NOT enabled and I confirmed that all client traffic was in fact being tunneled via this VPN policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It wasn't until someone pointed out to me that they remember a problem w/ matching on extended acl's vs just a standard network acl.  I converted the extended acl to a standard and WOLA it worked!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, now I'm at a standstill I do not want to configure it this way as I want to be very granular in what is allowed to specific machines - rather than just opening up specific host(s) and or network(s).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a bug? How can I configure this so that I'm only allowing specific protocols to specific hosts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW: the only reason I converted this customer over was the fact that DEP in SP2 Windows was jacking up their connectivity. There is a bug out there on this w/ CSD 3.1.1.45.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:56:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webvpn-split-tunnel-w-extended-acl/m-p/1009201#M918780</guid>
      <dc:creator>scottlivingston</dc:creator>
      <dc:date>2019-03-11T12:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN (Split Tunnel w/ extended ACL)</title>
      <link>https://community.cisco.com/t5/network-security/webvpn-split-tunnel-w-extended-acl/m-p/1009202#M918781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I found a fix....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to define and match on a standard wide open network and or host acl and then use the 'vpn-filter value' command to get granular on the standard one you created. If that doesn't make sense here's the config....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA# sh run | begin group-policy Company-ABC-WebVPN internal&lt;/P&gt;&lt;P&gt;group-policy Company-ABC-WebVPN internal&lt;/P&gt;&lt;P&gt;group-policy Company-ABC-WebVPN attributes&lt;/P&gt;&lt;P&gt; dns-server value 192.168.0.21 192.168.0.11&lt;/P&gt;&lt;P&gt; vpn-access-hours none&lt;/P&gt;&lt;P&gt; vpn-simultaneous-logins 10&lt;/P&gt;&lt;P&gt; vpn-filter value Company-ABC-Access-VPN-Network-List&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol webvpn&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Company-ABC-NONSPECIFIC-Access-VPN-Network-List&lt;/P&gt;&lt;P&gt; address-pools value Remote-Access-VPN-Pool&lt;/P&gt;&lt;P&gt; webvpn&lt;/P&gt;&lt;P&gt;  functions url-entry file-access file-entry file-browsing port-forward auto-download&lt;/P&gt;&lt;P&gt;  url-list value Company-ABC&lt;/P&gt;&lt;P&gt;  port-forward value Company-ABC-Access&lt;/P&gt;&lt;P&gt;  port-forward-name value Application Access&lt;/P&gt;&lt;P&gt;  svc enable&lt;/P&gt;&lt;P&gt;  svc keep-installer installed&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List remark Allow VPN Access to Demo-DMZ&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.145 eq 5802&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.145 eq 5902&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.145 eq 8080&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.145 eq ssh&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.147 eq 5802&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.147 eq 5902&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.147 eq 8080&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.147 eq ssh&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.148 eq 3389&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.131 eq 3389&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 1.1.1.135 eq 3389&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 192.168.0.11 eq domain&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit tcp any host 192.168.0.21 eq domain&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit udp any host 192.168.0.11 eq domain&lt;/P&gt;&lt;P&gt;access-list Company-ABC-Access-VPN-Network-List extended permit udp any host 192.168.0.21 eq domain&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list Company-ABC-NONSPECIFIC-Access-VPN-Network-List remark Allow VPN Access to Demo-DMZ&lt;/P&gt;&lt;P&gt;access-list Company-ABC-NONSPECIFIC-Access-VPN-Network-List standard permit 1.1.1.128 255.255.255.224&lt;/P&gt;&lt;P&gt;access-list Company-ABC-NONSPECIFIC-Access-VPN-Network-List standard permit host 192.168.0.21&lt;/P&gt;&lt;P&gt;access-list Company-ABC-NONSPECIFIC-Access-VPN-Network-List standard permit host 192.168.0.11&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jun 2008 17:28:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webvpn-split-tunnel-w-extended-acl/m-p/1009202#M918781</guid>
      <dc:creator>scottlivingston</dc:creator>
      <dc:date>2008-06-07T17:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN (Split Tunnel w/ extended ACL)</title>
      <link>https://community.cisco.com/t5/network-security/webvpn-split-tunnel-w-extended-acl/m-p/1009203#M918784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was having the exact same problem.  So glad I found your post.  Works great!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2008 16:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webvpn-split-tunnel-w-extended-acl/m-p/1009203#M918784</guid>
      <dc:creator>kristyorr</dc:creator>
      <dc:date>2008-07-31T16:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: WebVPN (Split Tunnel w/ extended ACL)</title>
      <link>https://community.cisco.com/t5/network-security/webvpn-split-tunnel-w-extended-acl/m-p/1009204#M918786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome - glad it helped. We have tied this to others and it's still a solid solution for us as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2008 16:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webvpn-split-tunnel-w-extended-acl/m-p/1009204#M918786</guid>
      <dc:creator>scottlivingston</dc:creator>
      <dc:date>2008-07-31T16:14:44Z</dc:date>
    </item>
  </channel>
</rss>

