01-26-2021 09:53 AM - edited 01-26-2021 09:54 AM
I want to configure to ASA 5506-x with two Anyconnect profiles for the user, one with split tunnelling enabled and one without (all traffic had to go through the tunnel and INTERNET connection should go via Tunnel to ASA and from here outside to the Internet. With ikev2 and Anyconnect my first idea was to use two different connection profiles by using each one with a modified default policies. But after some reading, I thing I need two different, a second group policy?
So how do I configure the ASA/Anyconnect client, so that the users can choose to use the profile with split tunnelling or w/o split tunneling (all traffic through to tunnel and back via outside int to the INTERNET?
Is there a link showing how to configure it with asdm (I only found using something changing ASA default no split tunnel to split tunnel by changing the default group policy)
Do I use the default policies with no split tunnel and configure new group policy with split tunneling enabled? So I can connect to the user profile? Can I copy and modify the defgrouppolicy with asdm?
My thx
Pete
01-26-2021 07:01 PM
You need to create Profiles for each
here is example split tunnel :
01-27-2021 02:33 AM
Hi,
thx, yes further investigations shows this. I create one with ASDM and copied it on CLI to modify it.
Peter
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide