We have a new Cisco ASA 5520 and are trying to setup the VPN with split tunneling. We mostly have clients running XP and the problem is that some of the clients connect (using Cisco Anyconnect 2.5) and the split tunneling works as expected --these clients keep their default gateway-- and then some clients connect and get a default gateway of 192.168.119.1 (our VPN addresses subnet) and of course these users cannot connect to the internet while connected to the VPN.
Here is our config:
ASA Version 9.1(1) ! hostname xxxxxx
names name 18.104.22.168 Deny22.214.171.124 description 126.96.36.199 name 188.8.131.52 Deny184.108.40.206 description 220.127.116.11 name 18.104.22.168 Deny22.214.171.124 description 126.96.36.199 name 188.8.131.52 Deny184.108.40.206 description 220.127.116.11 name 18.104.22.168 Deny22.214.171.124 description 126.96.36.199 name 188.8.131.52 Deny184.108.40.206 description 220.127.116.11 name 18.104.22.168 Deny22.214.171.124 description 126.96.36.199 name 188.8.131.52 Deny184.108.40.206 description 220.127.116.11 name 18.104.22.168 Deny22.214.171.124 description 126.96.36.199 name 188.8.131.52 Deny184.108.40.206 description 220.127.116.11 name 18.104.22.168 Deny22.214.171.124 description 126.96.36.199 ip local pool PAIUSERS 192.168.119.10-192.168.119.100 mask 255.255.255.0 ! interface GigabitEthernet0/0 nameif outside security-level 0 ip address 188.8.131.52 255.255.255.192 ! interface GigabitEthernet0/1 nameif inside security-level 100 ip address 192.168.129.5 255.255.255.192 ! interface GigabitEthernet0/2 nameif dmz security-level 10 ip address 192.168.20.10 255.255.255.0 ! interface GigabitEthernet0/3 nameif vpn_dmz security-level 25 ip address 192.168.30.10 255.255.255.0 ! interface Management0/0 management-only shutdown nameif management security-level 100 ip address 192.168.102.4 255.255.255.0 !
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...