Split Tunneling Before and After

Before split tunneling

Before split tunneling

Encrypted _Client

After split tunneling

After split tunneling

Client

© 2003, Cisco Systems, Inc. All rights reserved.

Split tunneling enables remote users to access Internet networks without requiring them to tunnel through the corporate network. Before split tunneling is enabled, all traffic originating from the Software Client is encrypted and routed through the secure tunnel. This traffic includes both secure and Internet browsing traffic. The secure traffic is terminated, while Internet traffic is routed back out to the Internet. A large percentage of the corporate backbone bandwidth is used for redirected web browsing traffic from remote users.

Split tunneling addresses the redirect issue, because split tunneling routes secure, encrypted traffic through the tunnel. Nonsecure traffic (for example, web browsing) is sent in the clear. The ISP can route the traffic accordingly (for example, secure traffic goes to the corporate network, and web browsing goes to the ISP).

© 2003, Cisco Systems, Inc. All rights reserved.

© 2003, Cisco Systems, Inc. All rights reserved.

The Concentrator pushes specific IP addresses to the Software Client to implement split tunneling. Traffic bound for one of these addresses is encrypted and sent to the Concentrator. If the IP address is different from the pushed addresses, the message is sent in the clear and, therefore, is routable by the ISP.

Configuring split tunneling requires two steps:

Step 1 Enable split tunneling by clicking the Only tunnel networks in list radio button within the Split Tunneling Policy row.

Step 2 Choose the appropriate list from the Split Tunneling Network List drop-down menu. This menu presents a predefined list of secure network addresses.

Split Tunneling—Network List

© 2003, Cisco Systems, Inc. All rights reserved.

© 2003, Cisco Systems, Inc. All rights reserved.

The Concentrator pushes specific IP addresses to the Cisco VPN Client. Traffic bound for one of these addresses is encrypted and sent to the Concentrator. These addresses are defined under Configuration>Policy Management>Traffic Management-Network Lists. In the List Name field, enter a name for the list. In the Network List field, supply the network and wildcard mask. In the example in the figure, the administrator wants to send clear text to the Internet and local printer. The administrator also wants to send encrypted traffic to the headquarters: the 10.0.1.0 network. In the Network List field, the administrator defines a network list name (Pod 1 network list) and configures the private network IP address and wildcard mask (10.0.1.0/0.0.0.255). As a result, any traffic bound for a host on the 10.0.1.0 network is encrypted and sent down the IPSec tunnel. All other traffic is sent in plain text.

No match

No match

server

server

© 2003, Cisco Systems, Inc. All rights reserved.

Split DNS is used in split-tunneling connections. The Software Client will resolve whether a DNS query packet is to be sent in clear text or is to be encrypted and sent down the tunnel. If the packet is encrypted and sent down the tunnel, a corporate DNS server resolves the DNS query. Clear text DNS requests are resolved by ISP-assigned DNS servers.

The client will receive a comma-delimited list of split-DNS names from the Concentrator via mode configuration. When the Software Client receives a DNS query packet, the domain name is compared and sequentially checked against the split-DNS names. Case-insensitive domain name comparison will start at the end of each domain name string and continue toward the beginning of each string, resulting in a match or no match. Query packets passing the comparison will have their destination IP address rewritten and tunneled using the primary DNS IP address configured on the concentrator. As an example, the query bob.cisco.com is compared against the split-DNS name of cisco.com and results in a match. The cisco.com portion of bob.cisco.com matches the split-DNS string of cisco.com. The bob.cisco.com DNS query is encrypted and sent to the primary DNS server. The primary DNS server will resolve the IP address of bob.cisco.com. Failover in the case of an unreachable primary split-DNS server will result in the secondary split-DNS server being used to resolve further queries. Packets not matching the split-DNS list will pass through the client untouched and transmitted in clear text. As an example, the query news.com, when compared against the split-DNS name cisco.com, results in a mismatch. The news.com DNS query is sent in clear text. The ISP-assigned DNS servers will resolve the IP address.

Split DNS Configuration

^-Cisco.com

Common Client Parameteis

Split Tunneling Policy

C Tunnel eveiything

I- Allow the networks in list to bypass the

1» Only tunnel networks in the list

Select the method and network list to be used for Split Tunneling. Ttutnel Everything: Send all traffic through the tunnel. Allow the networks in the list to Ijjpass the tunnel: The VPN Client may choose to send traffic to addresses in this list to the client's LAN. Send all other traffic through the tunnel. NOTE: This setting only applies to the Cisco VPN Client.

Tunnel networks the in list: Send traffic to addresses in this Est through the tunnel. Send all other traffic to the client's LAN.

Split Tunneling Network List

| pod 1 network list *• |

Default Domain

F

Enter the default domain name given to users of this group.

Split DNS Names

cisco.com

Enter the set of domains, separated by commas without spaces, to be resolved through the Split Tunnel.

| Apply | Cancel |

© 2003, Cisco Systems, Inc. All rights reserved. CSVPN 4.0—5-44

© 2003, Cisco Systems, Inc. All rights reserved. CSVPN 4.0—5-44

In the figure, the corporate DNS server will resolve all cisco.com DNS name requests. The ISP-assigned DNS server resolves all clear text DNS requests. Complete the following five-step process to configure split DNS:

Step 1 Define a list of secure networks. The network list is defined under Configuration>Traffic Management>Policy Management>Network Lists.

Step 2 Configure the Concentrator for split tunneling from the Configuration>User Management> Groups>Client Config tab. Click the Only tunnel networks in the list radio button to enable split tunneling.

Step 3 From the Configuration>User Management>Groups>Client Config tab, select the newly defined network list from the Split Tunneling Network List drop-down menu.

Step 4 From the Configuration>User Management>Groups>Client Config tab, enter the names of the corporate DNS servers in the Split DNS Names field (for example, cisco.com). Use commas, without spaces, to separate the names for multiple entries.

Step 5 From the Configuration>User Management>Groups>General tab, define the primary and secondary DNS server IP addresses. The primary and secondary DNS servers resolve the encrypted DNS queries.

Continue reading here: Setting Up Group Attributes

Was this article helpful?

0 0