cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2879
Views
0
Helpful
2
Replies

IPSec Client split tunnel doesn resolve external DNS; AnyConnect does

elpollodiablo
Level 1
Level 1

So I'm banging my head on this one.

I have both an IPSec and AnyConnect profile on a single ASA.  Both are set to use the DfltGrpPolicy, which defines some of our internal DNS domains, and is set to tunnel a network list.  I created an Extended ACL to define which networks I wanted to allow to the clients.  Users can log in using the IPSec client or the AnyConnect client and are authenticated against the ACS server properly.  I do not use downloadable ACLs, Network Access Filtering, or Network Access Restrictions.

When I connect with the AnyConnect client, everything works as desired.  The VPN tunnels the DNS domains I specify, allows access to only the networks I specify, and sends everything else out of the local connection. 

However, when I use the IPSec client, ONLY the networks/domains in the DNS domains and tunnel list are accessible.  If I do an nslookup (which hits our internal DNS server), I can only get answers for domains in the domain list.  As far as I can tell, I have the settings for each connection profile (AnyConnect and IPSec) identical.  I even create a new Group Policy and then set it to just inherit the defaults and I get the same results. 

Am I able to add wildcard domains in the DNS suffix list?  I'm so confused as to why the same group policy works differently for the two profiles.  Any help is appreciated.

2 Replies 2

Atul Singh
Level 1
Level 1

Hi,

Is it a Windows machine or MAC? And is a dns server configured on physical adapter also? Is split dns being used here?

DNS settings are per-interface in Windows. So if split-tunneling is used, DNS should fall back to physical adapter's DNS servers. Also try checking the "Allow Local LAN Access" in IPSec VPN Client in Transport tab.

-Atul

It doesn't matter what platform the client uses.  (At least it is universal, so I know it's not a problem with any one particular platform.)

I'll try the allow local lan access option and see what happens.