VPN Clients are treated as a seperate Network Entity by ISA Server. You have to create a new firewall rule as recommended above to give VPN Clients' network access to HTTP and HTTPS.
Also make sure you have a Network Rule in place doing NAT between VPN Clients network and the Internet.
Raj
Main Topics
Browse All Topics





by: What90Posted on 2009-03-11 at 01:17:20ID: 23854784
Hello there,
Split tunneling is considered a security issue as an attacker can bounce through your VPN connection into the corporate network. Not good.
What you may consider doing is creating a rule to allow the VPN clients to have web access on the ISA. Create a rule for the VPN clients object to have HTTP and HTTPS access to the external network. This lets you monitor and secure the web sites your VPN machines are going to. It may slow down the browsing experience of the users, but in my option, is the better way to go.
Otherwise...
Should you have a very good firewall and AV on the client machines, split tunneling is enabled on the Microsoft VPN client by removing the checkmark in the VPN clients Networking Properties dialog box for the Use default gateway on remote network setting.