cstosgale,
Thanks for the post, and I apologize for not getting back into this sooner; other issues took precedence to this one.
You are correct in that a user can use the URL entry bar to browse any URL, including internet URLs. However, this behavior is still controlled by the ACLs which define what traffic is being sent across the tunnel.
I was able to achieve what I wanted to by creating a new group and not configuring split-tunneling.
Thanks, anyway.
Main Topics
Browse All Topics





by: cstosgalePosted on 2009-03-16 at 15:23:37ID: 23903080
Without using the SSL VPN client, you could simply use the URL entry bar in the portal to allow the user to enter any URL, including internet URLs. This will allow the ASA to proxy traffic destined for the internet. Alternatively, you could even set up google as the home page for the VPN group (via group policy) and then anything they browse to via google would be going through the SSL VPN.
As an alternative you could create a smart tunnel for internet explorer but this would require and activex download I believe.
One question, why do you want to do this? They may be a more elegant way of achieving this.