through my research, we need to create a new Group policy with same existing Group policy and config Split Tunneling, Create and define the ACL to the local LAN of the client, Are there other configuration to be made?
thats right the new group policy will call the existing pre-configured tunnel-group. try to keep the split tunneling access-list seprate from both group.(I mean create a new access-list for split tunneling).
ASA can grab from the source of authentication (NPS) a specific attribute such as user group membership?
I am not sure i dont not think unless if you look at the LDAP authentication.
please do not forget to rate.