cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
447
Views
5
Helpful
1
Replies

Please confirm: ASA Anyconnect split-tunnel access list extended...

"access-list Split-Tunnel extended permit ip host 1.1.1.1 object VPN-Pool"...

My understanding is that it is best practice to make the ASA split-tunnel access list a STANDARD access list, because the destination element in this EXTENDED version of the access list is never queried (it is irrelevant). If this is true, then when troubleshooting I will always ignore the data in the destination element.

Is the destination element in this EXTENDED version of the access list never queried (it is irrelevant)? Please don't confirm if you are not certain. Please also reply with any related relevant thoughts.

Thank you!

 

1 Accepted Solution
1 Reply 1