Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Site-to-site - no split tunnel?

Status
Not open for further replies.

stakano

MIS
May 19, 2002
14
CA
I'm looking to disable split tunnelling when there is a site-to-site tunnel between PIX's.

Is there a command that would not allow split tunnel? Or is it just a matter of applying an access-list on the inside to permit only VPN encrypted traffic to the hub site, and deny the rest?
 
Configuring a site-to-site VPN tunnel on the PIX involves defining what traffic needs to be encrypted, so by it's very nature, it is a split tunnel. I'm not sure if you could define a network 0.0.0.0/0.0.0.0 as interesting traffic, but give it a try.

The other alternative is to configure your VPN device with the EzVPN feature in Network Extension Mode. EzVPN turns the remote endpoint into a VPN hardware client, and NEM still gives you the site-to-site capabilities. Configuring it this way would give you a full tunnel (it can also do split, in case you were wondering).
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top