cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1361
Views
0
Helpful
7
Replies

AnyConnect SSL VPN Vista split-tunneling

bwallander
Level 1
Level 1

I recently setup an ASA5510 with 8.0fw with the AnyConnect SSL VPN Client.

Connecting to the SSL VPN works perfectly from all the XP computers that I have tested from. No problems there. However when on Vista, split-tunneling does not seem to function properly. Everything connects and works fine, and I can get to the defined secured remote nets, however I can't access anything out my default gateway(un-secured traffic). It seems like it might be a problem with Vista security features. When I try to ping out to any outside host, I get:

PING: transmit failed, error code 1231.

I can actually ping my default gateway, but nothing gets routed past it without the above error. I've also confirmed this several Vista installations, with Administrator + UAC disabled. Anyone else?

7 Replies 7

cassmith
Level 1
Level 1

I have done the same testing, and on both Vista 32bit and 64Bit the split tunneling does not seem to work. Also I found that this is a "known" bug

From the Release Notes::

AnyConnect Split-tunneling Does Not Work on Windows Vista - AnyConnect split-tunneling works correctly with Windows XP and Windows 2000 (CSCsi82315)

I am happy that 64Bit works but will hold off on roll out until split-tunneling is fixed.

Cassidy

Ahh, thank you for pointing that out. I can stop pulling out my hair.

Here is the link to the release notes:

http://www.cisco.com/en/US/products/ps8411/prod_release_note09186a008086536c.html#wp705918

I checked bug tracker but they have not published any updates for this bug yet.

According to my Cisco TAC response, this bug is scheduled to be fixed in 2.1, tentatively scheduled late July or early August.

I even can't get thru anyconnect client hooked with my network. After the client is installed, it always tells me that "vpn client agent SSL engine encountered an error. close all sensitive networked applications"

Dont' know why... Still in research.

cassmith
Level 1
Level 1

I just got an update on the "split tunnel" bug. Supposedly they have resolved it, now we just need to wait for the updated client to show up on the download site.

Yep, I am being told the same thing as of today, almost a month later. Has anyone been able to get a pre-release version of 2.1 yet?