01-22-2025 08:58 AM - edited 01-22-2025 10:13 AM
We are running Cisco 1140 FTDs and recently updated to version 7.4.2.1. I noticed that while going back through configs, that in the remote access configuration, if you go to edit the group policy, there is now a red exclamation point for the split tunnel configuration and that you now cannot provide a standard access list as the network list type. However, if I make a change in the standard access list for the split tunnel, it still works and goes through. Do I need to make a new extended ACL? I cannot find any documentation that this has been changed.
To clarify, We are using a standard ACL to denote what traffic uses the split tunnel. When it was originally configured, the pictured settings allowed me to select standard ACL and select our standard ACL that we use. However, since updating to the new version, it now will not accept a standard ACL, it wants me to select an extended ACL. However, when I make changes to the standard ACL, it still works and does as configured. So obviously, it is using a standard ACL, even though in the settings it shows that it is no longer going to accept a standard ACL. What I really want to know is if I make a change to our Remote Access settings, will this take my existing split tunnel down?
Solved! Go to Solution.
01-24-2025 02:36 AM
You have to change IPv6 Split Tunneling to "Allow all traffic over tunnel".
Afterwards you´re able to use Standard ACL as well:
01-22-2025 09:05 AM
Split tunnel making anyconnect use it ISP to access internet'
So when you do standard ACL sure it work.
MHM
01-22-2025 10:07 AM
Thank you, but that was not my question. I already have a standard ACL identifying the traffic I want to use the split tunnel. My question is that in the new version it seems that it no longer allows you to use a standard ACL, only an extended ACL and that does not seem right. I am trying to find out why.
01-22-2025 10:24 AM
Red mark appear since you use extended ACL and you dont specify extended ACL
But why fmc not allow to select standard ACL that need to open TAC.
MHM
01-24-2025 02:36 AM
You have to change IPv6 Split Tunneling to "Allow all traffic over tunnel".
Afterwards you´re able to use Standard ACL as well:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide