01-23-2011 10:50 AM
Hi Experts,
I use Cosco AnyConnect VPN 2.5 client software to connect to my work.
I am on windows 7
I have a networked printer on my local network (192.168.1.x)
When connected to my VPN network (10.x IP with 255.255.224.0 mask) - I lose access to my local network - can't ping even my local router.
I checked the option "Enable Local LAN Access(If configured)" - but luck.
Question - How can I continue to have access to my local network, while I am connected to VPN.
Any help/pointers to help would be greatly appreciated.
Thanks
01-23-2011 11:00 AM
Hi,
How I've done it is like this:
GUI
1.) Set "Split Tunnel Policy = Exclude Network List Below"
2.) Create an ACL to exclude the known local LAN (e.g. 192.168.0.0/16)
3.) Set "Split Tunnel Network =
CLI
group-policy
split-tunnel-policy excludespecified
split-tunnel-network-list value LOCAL_LAN
access-list LOCAL_LAN remark Allow Local LAN Access
access-list LOCAL_LAN standard permit 192.168.0.0 255.255.0.0
Hope it helps.
Federico.
01-23-2011 11:08 AM
hello Federico,
Thanks for the response. I am guessing the information you provided is relevant at the VPN server level. Please note that I am an end-user with no admin privileges. I do not the options being available to me on the VPN Client software.
Thanks again, for your time and help.
01-23-2011 12:11 PM
Hi,
Which traffic to send through the tunnel is handled at the server side.
You can check the following on the client:
AnyConnect - Statistics - Details - Under Route Details you should have the non-secured routes and the secured routes.
The Secured routes is what you're sending through the tunnel and the non-secured routes whatever traffic is exempt from the tunnel (like your local LAN).
If you don't have your LAN in the non-secured routes, it must be configured on the server side.
Federico.
01-23-2011 12:23 PM
Hello Federico,
Thanks for the response. Looks like I am pretty much struck with this issue then, since I am not sure, my work would allow non-secured addresses. I checked the "route details" and see that non-secured routes is blank and no option to update/edit it. Thanks for all your help and time with this... I wish and hope there is some kind of option (like setting up static routes etc) to get over this problem. Any thoughts?
Thanks
01-23-2011 12:41 PM
Try this:
Split-exclude tunneling requires that you enable AllowLocalLanAccess in the AnyConnect Client. All split-exclude tunneling is regarded as local LAN access. In order to use the exclude feature of split-tunneling, you must enable the AllowLocalLanAccess preference in the AnyConnect VPN Client preferences. By default, local LAN access is disabled. This behavior is different from that of AnyConnect Client Release 2.2.
In order to allow local LAN access, and therefore split-exclude tunneling, a network administrator can enable it in the profile, or users can enable it in their preferences settings. In order to allow local LAN access, a user selects the Allow Local LAN access check box if split-tunneling is enabled on the secure gateway and is configured with the split-tunnel-policy exclude specified policy. Refer to Usage Notes for AnyConnect VPN Client Release 2.3 for more information. In addition, you can configure VPN Client Profile if local lan access is allowed with
Got it from this link:
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080702992.shtml#dsfg
Federico.
01-23-2011 01:36 PM
Hello Federico,
From the information you included:
>>>if split-tunneling is enabled on the secure gateway and is configured with the split-tunnel-policy exclude specified policy
As mentioned previously, I enabled the option, but it doesn't make a difference, which makes me believe that at the VPN Server/gateway level, this option is not enabled or how settings in place, which prevents me from connecting to local network. This is really disappoints me.. I will try to contact our help desk to see if they would allow such settings, but I am not really optimistic about this. The problem is, I have to now disconnect and connect from VPN, each time I need to print also, I am not able access my network resources (Shares etc..).
Thanks again,
01-23-2011 02:50 PM
If it does not work it most likely is not enabled on the server side that's correct.
Federico.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide