Cisco PIX 501 VPN Keep local internet

Posted on 2006-06-26
Medium Priority
Last Modified: 2010-04-12
Hi Everyone.  I have a running Cisco PIX 501 with VPN connections using Windows built in VPN client.  Works fine.  But I want the users who are in on the VPN to be able to use their local internet while connected.  How do I set this up?

Question by:bobbydall2000
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 19

Accepted Solution

nodisco earned 2000 total points
ID: 16988113
Hi Mark

Go into the properties of the PPTP VPN connection on your PC
Click on Networking>  Internet Protocol TCP/IP and click on properties
Click the advanced tab
Untick the box that says "Use default gateway of remote network"

All internet traffic will then go out over your local circuit - not the VPN gateway.

hope this helps
LVL 79

Expert Comment

ID: 16988361
This is a challenge given the typical config with a separate IP subnet assigned to the VPN clients and the internal LAN...
It is not an easy one to resolve. Some have created scripts that change a user's route table after they log on
Depending on your LAN IP subnet class (A B or C) you may have some easy options.
Some have used a sub-set of the LAN IP's for the VPN clients..

Author Comment

ID: 16993932
Hi.  The checkbox in the Windows connection worked fine.  Thanks.  I also discovered that if you are usiong the Cisco VPN client software you could setup split tunneling in the PIX.  But that only works with thier client.


Featured Post

Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

One of the Top 10  common Cisco VPN problems are not-matching shared keys. This is an easy one to fix, but not always easy to notice, see the case below. A simple IPsec tunnel between fast Ethernet interfaces of routers SW1 (f1/1) and R1(f0/0). …
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses
Course of the Month11 days, 1 hour left to enroll

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question