05-24-2025 11:01 PM
I want to know that is it possible to change the Split Tunnel access-list using ISE ?
I mean the remote client first connect with a limited split tunnel access list and after successful authentication and authorization in ISE, new split tunnel set.
05-24-2025 11:08 PM - edited 05-24-2025 11:20 PM
@imanv yes, from ISE you can dynamically apply a group policy to the user, the group policy would define the split-tunnel.
The name defined in ISE must match the name of the group policy on the ASA.
group-policy GP-1 attributes split-tunnel-network-list value SPLIT_ACL
Or you can use the "CVPN3000-IPSec-Split-Tunnel-List " and "CVPN3000-IPSec-Split-Tunneling-Policy" attribute value pairs. Reference:- https://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/3.3/user/guide/ad.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide
Log in to Community