cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


167
Views
0
Helpful
2
Replies
Enthusiast

ASA split tunnel

Hi I want to do split tunnel in anyconnect vpn. All traffic should go via tunnel except zoom meeting and it should go via local internet 

2 REPLIES 2
Beginner

Re: ASA split tunnel

@Pawan Raut 

I think you are doint the same traditional split tunelling where RA users can access corporate network and internet. This involves the below stage ,

  • defining your ACL
  • associating the ACL with tunnel group policy

Please remember the ACL should specify the traffic to be protected . Please follow this link :

 

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/70847-local-lan-pix-asa.html#anc8

 

NOTE : you can either excludespecified or tunnelspecified

 

Please rank this post .

Participant

Re: ASA split tunnel

Here is the config:

This will encrypt traffic & send over vpn to that destinsation, everything else will be routed locally.

In your scenario, you could try try permit any over the tunnel & deny the zoom meeting IP addresses - not sure if that would work but might be worth a try.

Regards, mk

 

access-list split-tunnel standard permit 192.168.1.0 255.255.255.0
group-policy TELECOMM attributes
split-tunnel-policy tunnelspecified
split-tunnel-network-list value split-tunnel