pwindell -> RE: VPN to External (9.Jun.2009 11:49:50 AM)
|
That has nothing to do with ISA. That is within the behavor of the Cisco VPN Client. By the nature of VPN,...once activated,...becomes the Default Gateway of the machine and over-rides the original Default Gateway. So any traffic not destined for the local LAN is automatically passed through the VPN Client whether it is the right place to go or not. Web Proxy Clients can typically use the ISA in spite of this because the redirection to the proxy happens at the Application Layer and so avoids the problem. SecureNAT Clients are in big trouble. Firewall Clients also use the Application Layer and would get around this, but unfortuneately the FWC is usually disabled to allow the Cisco VPN Client to function so you are back to being a SecureNAT Client. The place to correct this (if it is possible to correct) is in the Cisco VPN Client itself. I believe the term you might be looking for is Split Tunneling,...you need to "split-tunnel" the traffic to get it to work right. I do not know if Cisco uses that terminology or not.
|
|
|
|