Activate Splite tunneling in Cisco ASA for VPN IOS ?

Hello Community,
I need your help,  I have cisco ASR 5500, we are using for VPN client For IOS device, and i need to activate split tunneling,
Someone can help al all ready do this operation,
Thank you b yadvance for your help
Alain VOUCHEAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
Use Cisco ASDM GUI to manage this.
0
Pete LongTechnical ConsultantCommented:
You mean ASA? (ASR is something very different!)

Anyway see the following;

Cisco ASA – Enable Split Tunnel for IPSEC / SSLVPN / AnyConnect Clients

Pete
0
Mark BillExchange, AD, SQL, VMware, HPE, 3PAR, FUD, Anti MS Tekhnet, Pro EE, #1Commented:
of course he meant asa ;O definetly not an ASR :)
0
Scott TownsendIT DirectorCommented:
Without knowing what you already have in-place I'm Guessing that VPN Connections from iOS are already working though you are only able to access the Networks on the other side of the firewall while connected to VPN.

Sample Network Object Used in ACL
object network NETWORK-SSLVPN-POOL
 subnet 10.245.245.0 255.255.255.0 
object network NETWORK-OLIVET
 subnet 10.111.0.0 255.255.0.0

object-group network LOCAL_NETWORK_REMOTE_VPN
 network-object object NETWORK-HBG
 network-object object NETWORK-SF
 network-object object NETWORK-TRAINING

object-group network REMOTE_NETWORK
network-object object NETWORK-MEINZ
 network-object object NETWORK-WATERCOURSE
 network-object object NETWORK-HA
 network-object object NETWORK-FITCH

Open in new window


Define your Access Control Lists
Define your Split Tunnel Access Control Lists for the Traffic you want to have Split off to the ASA.
I typically do both Directions and use object-groups, and objects in the ACL.

access-list SSLVPN-SplitTunnel extended permit ip object-group LOCAL_NETWORK_REMOTE_VPN object NETWORK-SSLVPN-POOL 
access-list SSLVPN-SplitTunnel extended permit ip object NETWORK-SSLVPN-POOL object-group LOCAL_NETWORK_REMOTE_VPN 
access-list SSLVPN-SplitTunnel extended permit ip object NETWORK-SSLVPN-POOL object-group REMOTE_NETWORK 
access-list SSLVPN-SplitTunnel extended permit ip object-group REMOTE_NETWORK object NETWORK-SSLVPN-POOL 
access-list SSLVPN-SplitTunnel extended permit ip object NETWORK-SSLVPN-POOL object NETWORK-OLIVET 
access-list SSLVPN-SplitTunnel extended permit ip object NETWORK-OLIVET object NETWORK-SSLVPN-POOL 

Open in new window


Group-Policy
Setup the Group-Policy to specify the Split Tunnel and the Split Tunnel ACL
group-policy SSLVPNGrpPolicy internal
group-policy SSLVPNGrpPolicy attributes
 vpn-tunnel-protocol ssl-client 
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value SSLVPN-SplitTunnel
 split-dns value domain1.com domain2.com <local Domains to use VPN Provided DNS  domain>
 webvpn
  anyconnect profiles value SSLVPNProfile type user

Open in new window


Tunnel-Group
Make sure your Tunnel-Group Specifies your Group-Policy
tunnel-group SSL-VPN type remote-access
tunnel-group SSL-VPN general-attributes
 address-pool SSLVPN-IP-POOL
 authentication-server-group <RADIUS Server>
 default-group-policy SSLVPNGrpPolicy
tunnel-group SSL-VPN webvpn-attributes
 group-alias sslvpn enable
 group-url https://<Pub IP>/sslvpn enable
 group-url https://<Pub FQDN>/sslvpn enable

Open in new window

0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Scott TownsendIT DirectorCommented:
I have this setup working on a few ASA units...
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
iOS

From novice to tech pro — start learning today.