5. CISCO ASA 5520 9.1(7)9 AnyConnect Split Tunneling

Опубликовано: 04 Октябрь 2024
на канале: Donghowa Network
189
0

Local Traffics are forward to VPN Gateway. I need to exclude local network for VPN

https://www.cisco.com/c/en/us/support...

Remote Access VPN - Group Policies - Edit - Advanced - Split Tunneling
Uncheck Inherit - Exclude Network List Below
Uncheck Network List - Manage - Standard ACL
192.168.0.0/16

#on Client
In client, go to Anyconnect settings and check "Allow local(LAN) access when using VPN (if configured)"

#on AnyConnect Client Profile
Check Local Lan Access

*If "Allow local(LAN) access when using VPN (if configured)" is not checked, Split Tunneling route is not applied on client.

https://www.cisco.com/c/en/us/support...
In order to use the exclude feature of split-tunneling, you must enable the AllowLocalLanAccess preference in the AnyConnect VPN Client preferences. By default, local LAN access is disabled

*If If "Allow local(LAN) access when using VPN (if configured)" is check, but, Split Tunneling is not configured on ASA, Local Network doesn't work