Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Remote Access VPN - split tunnel configuration


I have a need to setup split tunneling where by 99.9% of the traffic needs to go through the tunnel and the other 0.1% can not. Therefore I created a group policy and under Advanced -> Split Tunneling I set

          Policy: Exclude Network List Below

          Network List: split_tunnel_exclusion

I then created the split_tunnel_exclusion ACL and added one entry to it for testing (, which happens to be a Google IP). However, when I connect via AnyConnect all traffic is still routed through the tunnel (looking at the route map on the system the default gateway is the tunnel IP, there is no network or host specific route for what I defined in the ACL). I tried setting the action on the ACE in the ACL to permit or deny but neither had any affect.

If I switch the policy to Tunnel Network List below then only that entry ( is tunnel (host route entry added to route table) whereas all other traffic doesn't go through the tunnel.

So what I need is for it to work the other way, which I thought should just be changing the Policy as I originally did.


Everyone's tags (4)
New Member

Remote Access VPN - split tunnel configuration

Well upon further research it looks like the exclude option for split-tunnel-policy is only applicable to the VPN client. Doesn't work with AnyConnect.

Is there a way to get the same sort of functionality when using AnyConnect?

CreatePlease login to create content