Tuesday, December 29, 2020

ASA - Dynamic split tunnel + traditional split tunnel

I can't seem to get this working correctly. We already have a traditional split tunnel running with certain networks to be included. I want to apply an anyconnect custom attribute to be used on the vpn group policy so that the tunnel will also include certain URLs. When users connect however, their client is not showing these domains in the inclusion list. I thought perhaps it was because they overlapped with the ip addresses already in the split tunnel, but I tried removing those ip's from the split tunnel, with the dynamic split tunnel custom attribute applied, and this caused them to not be able to reach them at all (access requires vpn, so this proves they are not being tunneled). Any ideas?



No comments:

Post a Comment