cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
454
Views
0
Helpful
1
Replies

Cisco ASA AnyConnect Split and Tunnel All together

ivan.martin
Level 1
Level 1

Hi

I have a Cisco ASA with vpn ssl anyconnect. We need to do split tunnel and tunnel all in the firewall for the same pool address and for the same interface outside and for the same group-alias.

All is working ok with split tunnel but my issue is for tunnel all. I should redirect  internet traffic for anyconnect client users to another external firewall (Palo Alto)  using another interface in the Cisco ASA. 

I was thinking in PBR. 

Perhaps, someone will have any idea about this case?

Regards, Ivan. 

 

1 Reply 1

@ivan.martin 

You can use a tunneled route for that decrypted VPN traffic (configured in addition to the default route)

 

route <if_name> 0.0.0.0 0.0.0.0 <gateway_ip> tunneled

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: