We currently are using a Cisco Pix 515 firewall as a end point for our vpn solution. We currently use Windows VPN connecting through the Pix and authenticating with an ACS. We do not use a Proxy server for internal Internet access. Our corporate security policy requires that we disable split tunnelling.
One of our senior managers is requesting that we find a way to allow vpn clients to use the corporate Internet connection while connected via VPN. My initial research indicates that this isn’t easily done. From what I understand, VPN traffic cannot go out the same interface is comes in on, which would make this impossible considering all outbound Internet traffic goes out the Pix interface.
Any thoughts would be greatly appreciated.