• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IPSEC configure for no split tunnel?

Scheduled Pinned Locked Moved 2.1 Snapshot Feedback and Problems - RETIRED
3 Posts 2 Posters 3.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    daplumber
    last edited by May 28, 2012, 7:11 PM

    So I followed the instructions and I have a working mobile IPSEC (Cisco type) server on my 2.1 box that I can log in two users for an iPhone and MacBook (native support) tested so far.

    What I can't seem to do is remove split tunneling and force all client traffic over the VPN. The "native" default route still remains and takes preference over the IPSEC default route. I've followed various suggestions on the boards here and tried a few things myself, but to no avail. I'm sure it's something simple, what is it?

    (This is a personal use home system, I like having a VPN back to bypass any restrictions and snooping from wherever I happen to be on the road, not to mention access to file and printer sharing. I've used OpenVPN successfully before, but using OS-native IPSEC clients appeals to me.)

    –--------
    This user has been carbon dated to the 8-bit era...

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by May 30, 2012, 3:07 PM

      With mobile, that is all up to the client side. The client ultimately decides which networks it will send across a tunnel.

      You might try toggling the "provide a list of networks" option but that doesn't seem to have any effect for me.

      My only iOS device, an iPod Touch, does try to tunnel all of its traffic, Internet included, without any intervention from me.

      Remember: Upvote with the πŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • D
        daplumber
        last edited by May 30, 2012, 8:40 PM

        You're correct about the client control, which is Cisco's pitch for their "enhanced" client software. However it's all about the order of "default" in the routing table. You're also correct that the "provide a list of Networks" checkbox was responsible for the "split_network includes" in the generated racoon.conf.

        Thanks for the reply jimp! It would have saved me some time…  :P  ::)  ;D I did finally solve my own problem before I read the reply here, so herewith the snaps of the settings I used. These work for non-split tunneling in iOS and OS X native clients. (Although both can be monkeyed with from the client end.)

        ![Screen Shot 2012-05-30 at May 30 12.17.19 .jpg](/public/imported_attachments/1/Screen Shot 2012-05-30 at May 30 12.17.19 .jpg)
        ![Screen Shot 2012-05-30 at May 30 12.17.19 .jpg_thumb](/public/imported_attachments/1/Screen Shot 2012-05-30 at May 30 12.17.19 .jpg_thumb)
        ![Screen Shot 2012-05-30 at May 30 12.17.39 .jpg](/public/imported_attachments/1/Screen Shot 2012-05-30 at May 30 12.17.39 .jpg)
        ![Screen Shot 2012-05-30 at May 30 12.17.39 .jpg_thumb](/public/imported_attachments/1/Screen Shot 2012-05-30 at May 30 12.17.39 .jpg_thumb)

        –--------
        This user has been carbon dated to the 8-bit era...

        1 Reply Last reply Reply Quote 0
        1 out of 3
        • First post
          1/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received