split-tunnel-policy and multicast: tunnelspecified vs. excludespecified
We have users on an isolated network that connect to our main office using VPN client 5.0.07.0290. Main office is currently running ASA 8.2(2)17. They also have a multicast source on their local LAN (vbrick video streamer).
When we configure their group policy to use a split-tunnel-policy with "tunnelspecified" and associated with an ACL that enumerates the networks at our home office, they can access the main office resources just fine, and also connect to the multicast stream on their local LAN.
However, when we change this around and use split-tunnel-policy with excludespecified to enumerate the local subnet they are permitted to access (everything else is tunneled in this scenario) multicast breaks.
What I noted with Wireshark is that when using excludespecified some IGMP traffic tries to go down the tunnel adapter (incorrect behavior), and some is going out the ethernet adapter to the local LAN (correct behavior).
We have to use excludespecified because we only permit split tunnel from a very specific subnet.
Hi Team, I have one exclusion provided by internal team which is Is it right way to exclude ? *\Program Files\XYZ\* , as per Cisco Docs i see its not recommended because it will create performance issue when we use * at starting , So...
Central Log Management using Cisco Security Analytics and Logging, December 2nd at 8am-9:30am PT
Cisco Security Analytics and Logging is Cisco’s Central Log Management solution for Network Operations and Security Outcomes. It is delivered both as a c...
Cyberattacks are more sophisticated than ever and your online presence has never been more critical to the success of your business. Cisco, through its OEM partnership with Radware, can help secure your digital future by continuously monitoring...
We have a filter that blocks incoming messages with credit card numbers. But it won't pick up on messages with 4 digit blocks on separate lines. Example:1234567890123456 Any suggestion on how to detect this pattern?