cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
859
Views
5
Helpful
2
Replies

ASA Split Tunneling/Dynamic-Attributes

andreasalberti
Level 1
Level 1

Good day,

 

I can't really get any further.

We have set up both an acl and custom attributes for dynamic tunnel exclusions.

In order to reach the local VM on the host, we have stored a private 172 IP range inside our acl for the tunnel exclusion.

Unfortunately, this is only drawn very sporadically.

 

Sometimes i can see the mentioned IP 172.x.x.x in "unsecured routes", but most of the time its not working.

has anyone ever had similar experiences?
could the problem be due to the private ip range?
The public ips are pulled without problems.

 

I would be happy about any ideas.

 

best regards

2 Replies 2

andreasalberti
Level 1
Level 1

Update:

 

if you have similar problems.
It is important to enable local lan access in anyconnect profile. As a result, the IP addresses of the virtual adapters only appear in unsecured routes.

In combination, access to local machines works despite a connected vpn.

 

Review Cisco Networking for a $25 gift card