Hi!
I've setup VPN on the FMC to use our AD to grant access. Users use anyconnect to connect and I have setup so that split tunneling is enabled. As it is now we have two different groups of users, Administrators and Employees. I've setup an access policy so that Employees can only access Network B, and Administrators can access network A & B. The problem I have is that if the employees check the route information in anyconnect they can see network A as a secure route. So I tried creating two different group policies for the different user groups. So employees choose another profile when connecting with anyconnect and they are only given their correct route but they still can choose the "Administrator" profile and connect fine via the VPN they just cant access anything.
Is there a way I can fix this? or I have setup it completly wrong?
Employees should only access network B and should only see network B as a route in anyconnect
Administrators should access to both Network A & B and see both networks in anyconnect.
Any tips / help would be appreciated