Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

enabling certain VPN groups to have internet access on 506e

Status
Not open for further replies.

caswcu

Technical User
Feb 16, 2005
93
0
0
US
Not internal ip of the pix but internal network range of the hosts you want vpn users to access.

The split tunnel command basically tells the client if it isnt heading for a subnet in the 101 address dont encrypt and send out to the merry old internet.
 
Hello NetworkGhost,

This means that the permit rule tells the pix which traffic should be encrypted? right.

This means
acesslist splittunnel permit ip 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0
all traffic is encrypted -> no spilt tunnel allowed

accesslist splittunel permit ip central network remote vpn network

only traffic remote -> central is encrypted -> split tunnel allowed for all other traffic.

But what can I do If I only like access to on or to internet IP addresses?

Best Regards,
Marcus

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top