Modify Cisco VPN Route at windows client pc to have split tunneling

Ashish kataria

Honorable
Sep 27, 2013
3
0
10,510
Split Tunneling is disabled by admin, that's why i am looking to modify routes, but cisco Anyconnect client is sitting like watchguard over my pc and reconnects itself whenever i modify routes in windows.

Is it possible to modify routes on my ADSL Modem?

Any help would really push me forward.

Thanks.
 
Solution
On that machine you can't that is the purpose of the restriction. Almost all the commercial VPN clients work that way. Working from IT side of this I have tried every hack I know and I have never bypassed these which is good if you are the IT guy.

Your solution is to run a second machine. I am assuming your modem is actually a router so you just plug one in if you have it. Otherwise you get very ambitious and run multiple virtual machines on your real machine. It will be easiest to run the VPN client in the virtual and leave the main machine for your normal use.

Your IT will not likely care since the main purpose of split tunnel is to prevent someone from the outside hacking you machine and then using that to get inside...
On that machine you can't that is the purpose of the restriction. Almost all the commercial VPN clients work that way. Working from IT side of this I have tried every hack I know and I have never bypassed these which is good if you are the IT guy.

Your solution is to run a second machine. I am assuming your modem is actually a router so you just plug one in if you have it. Otherwise you get very ambitious and run multiple virtual machines on your real machine. It will be easiest to run the VPN client in the virtual and leave the main machine for your normal use.

Your IT will not likely care since the main purpose of split tunnel is to prevent someone from the outside hacking you machine and then using that to get inside. When the machine are different even if they are virtual it gets very hard to cross between them.
 
Solution

Ashish kataria

Honorable
Sep 27, 2013
3
0
10,510
Thanks for the answer, Just one doubt..you mean to say it's not possible on the same machine even after adding some static route in my ADSL modem/ router?



 
Nope the VPN client forces ALL traffic into the tunnel. Once it gets to the router all traffic appears to come from the PC and go to the VPN hosting location. Since the traffic is encrypted you will not even see any of the internal IP addresses. Many time the tunnel is turned on so strict you cannot even send data to other devices on the same network..like your printer. It pretty much restricts the data so the only destination address is the VPN server.

The inability of a device in the path to affect the traffic is key to the whole concept of vpn. If you could do it anyone else could too.