We are currently using a VPN Concentrator 3030 for remote access VPN tunnels. We plan on migrating to the ASA 5520 series for IPSec client connectivity. We'd like to be able to download RADIUS attributes from ACS 4.0 so we do not have to maintain a ton of different groups locally on the ASA. Has anyone tested split-tunnel lists, downloadable ACLs, etc. with ACS 4.0 and the ASAs?
Re: Can ASA download split tunnel list from ACS 4.0
In basic VPN Client to ASA scenario, all traffic from the VPN Client is encrypted and sent to the ASA no matter what its destination is. Based on your configuration and the number of users supported, such a set up can become bandwidth intensive. Split tunneling can work to alleviate this problem since it allows users to send only that traffic which is destined for the corporate network across the tunnel. All other traffic such as instant messaging, email, or casual browsing is sent out to the Internet via the local LAN of the VPN Client.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...