Discussion in 'Cisco' started by Jon L. Miller, Feb 7, 2005.

  1. Need to know how to setup a split-tunnel on a 2621 dsl router to allow a cisco
    vpn client user the abuility to retain their local lan access.
    Also need acl to only allow port 3306 and port 4899
    Would it be something to the order of:
    ! Split-tunnel info
    access-list enochlan permit ip
    vpngroup tunnel1 split-tunnel enochlan

    Then do we create extended acls to this tunnel1 and apply the acl group to the
    tunnel1 interface?
    Jon L. Miller, Feb 7, 2005
  2. Jon L. Miller

    Dumbkid Guest

    This is probably what you are looking for:

    Note split-tunnel config:

    crypto isakmp client configuration group hw-client-groupname
    key hw-client-password
    pool dynpool
    acl 150

    "acl 150" is the split-tunnel, and "dynpool" is the ip address the client
    will be assigned.
    Dumbkid, Feb 7, 2005
