cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
502
Views
0
Helpful
1
Replies

Cisco ASA AnyConnect Split and Tunnel All together

ivan.martin
Level 1
Level 1

Hi

I have a Cisco ASA with vpn ssl anyconnect. We need to do split tunnel and tunnel all in the firewall for the same pool address and for the same interface outside and for the same group-alias.

All is working ok with split tunnel but my issue is for tunnel all. I should redirect  internet traffic for anyconnect client users to another external firewall (Palo Alto)  using another interface in the Cisco ASA. 

I was thinking in PBR. 

Perhaps, someone will have any idea about this case?

Regards, Ivan. 

 

1 Reply 1

@ivan.martin 

You can use a tunneled route for that decrypted VPN traffic (configured in addition to the default route)

 

route <if_name> 0.0.0.0 0.0.0.0 <gateway_ip> tunneled