Step 3 – Traffic Steering (Split Tunnel)
For Traffic Steering (Split Tunnel), you can configure a machine tunnel to maintain a full tunnel connection to Secure Access, or configure it to use a split tunnel connection to direct traffic through the VPN only if necessary.
-
For Tunnel Mode, choose either:
-
Connect to Secure Access to direct all traffic through the tunnel; or,
-
Bypass Secure Access to direct all traffic outside the tunnel.
-
-
Depending on your selection, you can Add Exceptions to steer traffic inside or outside the tunnel. You can enter comma-separated IPs, domains, and network spaces.
- For DNS Mode, you can accept the default mode or, depending on your selection, choose to Tunnel all DNS traffic or Split DNS traffic.
When Split DNS is chosen, DNS names matching the configured DNS Names will be routed over the encrypted Secure Client connection for resolution. Any that do not match the configured DNS Names are routed via the local physical interface for the resolution.
At this time, Split DNS is only available for Bypass Secure Access tunnel mode.
- Click Next to configure the Cisco Secure Client.