james.bastnagel Mon, 01/25/2010 - 08:38

There are 2 ways to do this.

You can set up split tunneling in which will define the list of networks to

be tunneled in the connection profile/group policy -- I cant remember which

one off the top of my head. Internet access will be local to the remote


Or you can set up a nat translation for your remote vpn segment on the

outside interface of the device that will let them access the internet

through the ASA.

On Mon, Jan 25, 2010 at 3:46 AM, webluca1977 <


