Page 1 of 1

Split tunnel support for RA VPN?

Posted: Tue Mar 04, 2014 7:15 am
by benitton
Hi,

I would like to replace an ASA5505 due to license limitations with an RB2011UiAS-2HnD, and I need to configure remote access (roadwarrior) clients to access this box from the outside. I got the L2TP/IPSec VPN to work, but now I need to implement split tunneling, so that users can access different local subnets at the remote site, but still access some servers connected behind the ASA. Is this possible? I have tried configuring the Shrew VPN client, but we have MAC and Windows 8 clients, and the Shrew client does not seem to work very well on either.

I looked for this over the internet, I found bits and pieces (mode-cfg configs) but nothing that worked, or was clearly explained for me to test (I am still quite new to the RouterOS environment).

Any help will be more than appreciated. Thanks in advance!

Re: Split tunnel support for RA VPN?

Posted: Fri Mar 14, 2014 5:20 am
by benitton
I discovered that for both OS X and Windows 8/8.1, there is a setting in the VPN connection that allows all the traffic to be sent using the VPN tunnel established. If this option is not used, only the local traffic for the VPN is sent.

In my case I wanted all internet traffic to go through the VPN tunnel, and only "enterprise" traffic to avoid being sent through the tunnel. For this I ended up using static routes to all the subnets in the "enterprise".

If anybody needs more clarification on this send me a private message.
:)