Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Split Tunnel somehow not working

Hello,

At our client I configured Split Tunneling on an ASA but somehow it doesn't seem to function.

I have the feeling I'm missing something but I don't see what.

Situation as followed:

Network: 10.38.11.192 255.255.255.224

group-policy VPNCLIENTS attributes

dns-server value 10.38.11.203

split-tunnel-policy tunnelspecified

split-tunnel-network-list value Split_Tunnel_VDDnew

access-list Split_Tunnel_VDD standard permit 10.38.11.192 255.255.255.224

ip local pool VPNDHCP 10.38.12.1-10.38.12.100

I don't see what is wrong here since the same setup is used at other clients.

Hope someone can help.

Greetings Jesse

11 REPLIES
New Member

Split Tunnel somehow not working

Please verify your ACL name.

Andrea

New Member

Split Tunnel somehow not working

Woops, copied an old ACL, correct split-tunnel list:

access-list Split_Tunnel_VDDnew extended permit ip 10.38.11.192 255.255.255.224 10.38.12.0 255.255.255.0

New Member

Split Tunnel somehow not working

Hello Jesse.

You can use the standard ACL to specify the network behind the ASA.

Can you remove the NAT statement, please?

New Member

Split Tunnel somehow not working

Sorry, should have mentioned it before but I'm fairly new to this.

Isn't the NAT statement mandatory since my external adres is bound to it?

Also what do you mean with standard ACL, or does NAT look at the standard ACL once you remove it?

Again sorry, I started doing ASA's and PIX's recently and find them awefully cryptic sometimes.

New Member

Split Tunnel somehow not working

New Member

Split Tunnel somehow not working

Hi Andrea,

That's the ironic part, I followed that manual exactly. I even had our Senior Network Engineer take a loot at it and also said "Weird... it should work".

Therefor I have the feeling I'm missing something.

New Member

Split Tunnel somehow not working

Can you provide all VPN configuration?

Have you set the default group policy when define the tunnel-group?

tunnel-group XXXXXXX general-attributes

default-group-policy VPNCLIENTS

New Member

Split Tunnel somehow not working

Ok, thanks for the response, I am currently unable to log onto the ASA. I'll get back to you once I'm able to.

Split Tunnel somehow not working

Hello Jesse,

Andrea advise ( Default-group-policy) should do it.

If that does not make a difference please post entire configuration.

Regards,

Looking for some Networking Assistance? Contact me directly at jcarvaja@laguiadelnetworking.com I will fix your problem ASAP. Cheers, Julio Carvajal Segura http://laguiadelnetworking.com

Split Tunnel somehow not working

Hi Jesse,

The config looks fine. When you say it is not working - what exctly the issue? VPN clients unable to access the internal network? Few things you need to check...

1. nat 0 access-list for internal network to remote von client subnet.

2. same security traffic permit intra/inter interface allowed. (check the syntax for this command).

3. Route on internal routers that points the traffic to VPN subnets to ASA inside interface. (default should do as well).

hth

MS

New Member

Split Tunnel somehow not working

Sorry for the long response, I'm at a different client today and not able to provide answers untill tomorrow.

437
Views
0
Helpful
11
Replies