04-03-2012 09:06 AM
Hi all,
I need to create a VPN and have split tunneling disabled, so that all traffic including internet traffic goes over the vpn back to the headquators and out that internet pipe or to the network. I will be using the Cisco VPN client software and connecting to a 2811 router running IOS ver 12.3(8r)T7. I am pretty new when it comes to these configurations so any help will be greatly helpful. Ive tryed looking for articles on how to do this and have come up pretty short. Thanks for the help!!
04-03-2012 11:36 AM
Hello Jeremy,
You should not worry that much for this as by default with a VPN client all traffic is going to be tunnel ( tunnel all) .
If you need to configure split tunnel policies there is where you need to make changes to the group-policies.
Regards,
Julio
Do rate all the helpful posts
08-09-2013 08:49 AM
Hi,
In regards to split tunnel, I am also having a dilema on how to configure the policy, so the local LAN access is permitted, while all other traffic, corporate and Internet, still goes through the tunnel.
Reading about it, I found this:
"In a remote access VPN deployment, split tunneling gives the user direct access to a public network and VPN access to a private network simultaneously. The end user's computer becomes an extended Internet entry point to the corporate network. If no proper security measures are in place on the end user's computer, attackers have opportunities to compromise the computer from the Internet and gain access to the internal network through the VPN tunnel. For this reason, many organizations choose to disable split tunneling in their remote access VPN deployment.
When split tunneling is disabled, one common issue is that users can no longer access the local LAN for tasks such as printing. The solution is to disable split tunneling but enable local LAN access. This way, the local LAN traffic will not be tunneled to the head-end SSL VPN gateway."
As different users have difefrent local subnets and we don't know them, I configured the policy like this:
Where the SPLIT network list is 0.0.0.0
would this also send the Internet traffic through the local LAN gateway or tunneled (preferred).
A whireshark capture on the Cisco Anyconnect interface while sending ICMP traffic to a host on the Internet, shows so, but still not sure.
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide