Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Internet connectivity wihtout Split Tunneling on 3005

I am running a 3005 and would like VPN clients to not use split tunneling and run all traffic, local LAN and Internet, through the VPN tunnel. Currently, I can get the local LAN traffic to work, but no Internet traffic is passing.

On the 3005 I have a default route pointing to the next hop of the outside interface, and I have a TDR pointing to the internal router. The route from the internal router to the Internet take a path out a different connection.

Can anyone help me with a configuration to make Internet connectivity work over non-split-tunnelling?

Cisco Employee

Re: Internet connectivity wihtout Split Tunneling on 3005

Does the internal router and the "other-path-to-the-Internet" device have a route for the VPN pool of addresses, that evenatually points back to the inside interface of the concentrator? If your VPN pool of addresses is a private subnet, are these packets being NAT'd thru the "other-path-to-the-Internet" device as they go out, otherwise they won't be able to be routed back.

I presume when you mention a TDR you're referring ot the Tunnel Default Gateway parameter in the concentrator, this should be pointing to the next hop on the inside network or straight to your "other-path-to-the-Internet" devices IP address if it's on the same inside subnet. You can then just add a static route for your whole inside network that points to the inside router.

New Member

Re: Internet connectivity wihtout Split Tunneling on 3005

The subnet for the VPN clients is private address space. The VPN concentrator has a direct connection to the internal router, and the inside interface is in the subnet of the client address space. The internal router shows the "client addresses" as "connected". The "other-path-to-the-Internet" device has a route back to the internal router, and is NAT'ing all traffic going out through it. However, it still does not work. Any further suggestions?

New Member

Re: Internet connectivity wihtout Split Tunneling on 3005

I'm beginning to wonder if the static default route on the 3005 pointing to the outside interface is what is causing my problem. I am thinking that the client machine looks up the address, the attempts to reach it, the 3005 decrypts the traffic and sends it along based on its routing information, which tells it to go right back out the outside interface.

But, if I point the static default route to the internal router would that cause another problem?