Split-Tunneling on a PIX LAN-to-LAN Ipsec Tunnel

Dec 07, 2006 4 Replies

I've set up split-tunneling on a PIX for VPN clients but this is the first for PIX-to-PIX tunnel. Is there a way of setting up the spoke PIX in a LAN-to-LAN Ipsec Tunnel to do split-tunneling?

Is this done through a access-list instead of a command? I've set up split-tunneling on a PIX for VPN clients but this is the first for PIX-to-PIX tunnel.

I've set up split-tunneling on a PIX for VPN clients but this is the first for PIX-to-PIX tunnel. Is there a way of setting up the spoke PIX in a LAN-to-LAN Ipsec Tunnel to do split-tunneling?



Is this done through a access-list instead of a command? I've set up split-tunneling on a PIX for VPN clients but this is the first for PIX-to-PIX tunnel.



Your LAN-to-LAN tunnel will be written in terms of crypto map policy, one item of which will be a "match address" clause that indicates an ACL name. Anything matched by that ACL *after all relevant translations* if sent through the VPN. So if you want the effect of split-tunnel, make the ACL match only that which you want to send over.

Note: the match address ACL should be written as for what you would expect for data from the interior out of the PIX; the ACL will automatically be read "backwards" for incoming traffic.

So it IS done through access-list.

Thanks!

Walter Robers> >

So it IS done through access-list.

Thanks!

Walter Robers> >

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required