We have an Anyconnect VPN which is using an external group-policy located on our ISE 2.0 appliance. All works except for the split-tunneling policy.. even the RADIUS debugs show the various attributes being used. But for some reason no matter what ...