Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSEC configure for no split tunnel?

    Scheduled Pinned Locked Moved 2.1 Snapshot Feedback and Problems - RETIRED
    3 Posts 2 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      daplumber
      last edited by

      So I followed the instructions and I have a working mobile IPSEC (Cisco type) server on my 2.1 box that I can log in two users for an iPhone and MacBook (native support) tested so far.

      What I can't seem to do is remove split tunneling and force all client traffic over the VPN. The "native" default route still remains and takes preference over the IPSEC default route. I've followed various suggestions on the boards here and tried a few things myself, but to no avail. I'm sure it's something simple, what is it?

      (This is a personal use home system, I like having a VPN back to bypass any restrictions and snooping from wherever I happen to be on the road, not to mention access to file and printer sharing. I've used OpenVPN successfully before, but using OS-native IPSEC clients appeals to me.)

      –--------
      This user has been carbon dated to the 8-bit era...

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        With mobile, that is all up to the client side. The client ultimately decides which networks it will send across a tunnel.

        You might try toggling the "provide a list of networks" option but that doesn't seem to have any effect for me.

        My only iOS device, an iPod Touch, does try to tunnel all of its traffic, Internet included, without any intervention from me.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • D
          daplumber
          last edited by

          You're correct about the client control, which is Cisco's pitch for their "enhanced" client software. However it's all about the order of "default" in the routing table. You're also correct that the "provide a list of Networks" checkbox was responsible for the "split_network includes" in the generated racoon.conf.

          Thanks for the reply jimp! It would have saved me some time…  :P  ::)  ;D I did finally solve my own problem before I read the reply here, so herewith the snaps of the settings I used. These work for non-split tunneling in iOS and OS X native clients. (Although both can be monkeyed with from the client end.)

          ![Screen Shot 2012-05-30 at May 30 12.17.19 .jpg](/public/imported_attachments/1/Screen Shot 2012-05-30 at May 30 12.17.19 .jpg)
          ![Screen Shot 2012-05-30 at May 30 12.17.19 .jpg_thumb](/public/imported_attachments/1/Screen Shot 2012-05-30 at May 30 12.17.19 .jpg_thumb)
          ![Screen Shot 2012-05-30 at May 30 12.17.39 .jpg](/public/imported_attachments/1/Screen Shot 2012-05-30 at May 30 12.17.39 .jpg)
          ![Screen Shot 2012-05-30 at May 30 12.17.39 .jpg_thumb](/public/imported_attachments/1/Screen Shot 2012-05-30 at May 30 12.17.39 .jpg_thumb)

          –--------
          This user has been carbon dated to the 8-bit era...

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.