cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
786
Views
10
Helpful
4
Replies

Specific sites through tunnel

Hello, 

 

I have an HA pair of 2120 and I have configured RA VPN.

There is split tunnel so the users use their local internet. 

 

I would like to ask if there is a configuration where I have the split tunnel in place and I only allow a couple of sites to go through the internet form the company. 

 

Thanks and regards, 

Konstantinos

1 Accepted Solution

Accepted Solutions

@kostasthedelegate 

I assume you are running FTD image?

 

You can use split tunnel and use "dynamic-split-include-domains" attribute to define domains to include in the VPN tunnel.

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/config_examples/advanced-anyconnect-ftd-fmc/advanced-anyconnect-vpn-ftd-fmc.html#Cisco_Concept.dita_213e916f-a1d4-468d-953d-e50f80980d52

 

View solution in original post

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

Personally if you looking local breakout, split tunnel, Only allow Corporate IP address via VPN, rest go directly to internet to save HQ Internet Bandwidth, again business requirement. (how you like to control user)

 

full Cone tunnel vs split tunnel.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

What I want is for a public IP to go through the tunnel and be routed to the internet through the company's public IP

yes you create ACL and what to allow via VPN or go direct internet.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

@kostasthedelegate 

I assume you are running FTD image?

 

You can use split tunnel and use "dynamic-split-include-domains" attribute to define domains to include in the VPN tunnel.

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/config_examples/advanced-anyconnect-ftd-fmc/advanced-anyconnect-vpn-ftd-fmc.html#Cisco_Concept.dita_213e916f-a1d4-468d-953d-e50f80980d52