cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
396
Views
10
Helpful
2
Replies

ASA- Split-Tunnel ACL enough, or must I adjust Inteface ACL's also?

Hello.

When routing split tunnel traffic inside the Anyconnect VPN-- in addition to the split-tunnel ACL, must I also create a standard ACL "permit" statement for this newly authorized traffic on the existing ACLs on the inside and outside interfaces?

Thank you.

2 Accepted Solutions

Accepted Solutions

@jmaxwellUSAF as default VPN traffic is permitted with the pre-configured command "sysopt connection permit-vpn" configured, thus the interface ACL is ignored. So no you don't need to explictly permit this traffic, unless you've unconfigured the default command.

View solution in original post

friend 
I know the name confuse you but split-acl is not ACL and not apply to any interface in ASA, 
it called split-acl but it actually is route add to client. 

for ACL you need for VPN it depend 
1- sysop connection permit-vpn 
2- you apply any ACL IN to INside interface 

View solution in original post

2 Replies 2

@jmaxwellUSAF as default VPN traffic is permitted with the pre-configured command "sysopt connection permit-vpn" configured, thus the interface ACL is ignored. So no you don't need to explictly permit this traffic, unless you've unconfigured the default command.

friend 
I know the name confuse you but split-acl is not ACL and not apply to any interface in ASA, 
it called split-acl but it actually is route add to client. 

for ACL you need for VPN it depend 
1- sysop connection permit-vpn 
2- you apply any ACL IN to INside interface