cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
426
Views
0
Helpful
1
Replies

Separate VPN traffic on ASA

manglen32
Level 1
Level 1

Hi,

I'm hoping someone can help.  I'm trying to see if there is a way on the ASA (non-CX) to separate the SSLVPN traffic from the rest of the firewall traffic.  Both sets of traffic would ultimately go to the same switch, but I was hoping I could split them into different VLANs or more specifically different internal ports.  I'm implementing ISE (IPEP) inline and would like to not have non-VPN traffic flow through the ipep device. 

I know PBR and source-based routing are not supported (at least I didn't think they were), but was hoping there was an obscure solution that I may be missing.

Thanks,

Mike

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

I think for now you'll have to push it all through your IPEP.

Rumor is that CoA will be natvely in ASA 9.2, so that will provide relief in the longer term.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: