We have an Anyconnect VPN which is using an external group-policy located on our ISE 2.0 appliance. All works except for the split-tunneling policy.. even the RADIUS debugs show the various attributes being used. But for some reason no matter what I do it wont split tunnel
Access Type = ACCESS_ACCEPT
DACL = ISE_VPN_2
Class = ISE_VPN
CVPN3000/ASA/PIX7x-Client-Type = 2
CVPN3000/ASA/PIX7x-IPSec-Split-Tunneling-Policy = 1
CVPN3000/ASA/PIX7x-IPSec-Split-Tunnel-List = ISE_VPN_2_SPLIT
CVPN3000/ASA/PIX7x-Address-Pools = VPN_IPPOOL