the picture: PIX has one External interface to the ISP
PIX has one Inside interface to the network
PIX has 3rd interface direct to the network core
What I've been asked to do: (Don't blame me for the current setup, I would have set the ISP connection up as a trunk with VPN on a different VLAN if I had been involved in building this).
VPN users coming in via the ISP need to be routed to the 3rd interface, so that their internet-connection attempts can be routed via the web-filtering thingie, before coming back to the PIX on the Inside interface. At this stage, traffic that is Source:VPN_Subnets/Dest:Internet BUT coming in on Inside interface, needs to just use the normal default route.
I haven't played with PIXs much, and I would never set this up this way in the first place (had I been asked) but apparently they are no longer talking to their ISP, or willing to change anything else, so I'm stuck crossing my fingers that PBR can do this.
Can it?
If so, can you give me some rough (or even detailed!) hints?