Does IKEv2 support for split tunnel?
In my scenario, the clients establishes IKEv2 VPN tunnel to device for reaching internal servers.
But in the same time, all of clinet's traffic will pass through to VPN tunnel.
How to separate client’s Internet from VPN tunnel?(Internet traffic will not pass through to VPN tunnel)
In the current design, Windows native VPN interface can't separate Internet traffic from VPN tunnel.
The only way to fulfillit is to create an additional routing on your PC. .
Disable PC default gateway from your VPN interface:
a. Navigate to Control Panel > Network and Sharing Center > Change Adapter Settings
b, Right click on the VPN connection, then choose Properties
c. Select the Networking tab
d. Select Internet Protocol Version 4 (TCP/IPv4) and click Properties
e. Click Advanced
f. Deselect the box for "Use default gateway on remote network"
g. Click OK to apply the changes to the interface
After these steps, all of your PC traffic will pass through to the Internet. So you need to add an additional routing for your VPN traffic.
Create additional routing for your VPN traffic
C:\Windows\system32>route.Add 192.168.1.0 mask 255.255.255.0 100.100.100.1
After you complete the steps above, Windows client is able to connect to the Internet and VPN subnet.
- 6K All Categories
- 1.2K Nebula
- 16 Nebula Ideas
- 13 Nebula Status and Incidents
- 3.4K Security
- 186 Security Ideas
- 597 Switch
- 24 Switch Ideas
- 427 WirelessLAN
- 6 WLAN Ideas
- 4.2K Consumer Product
- 56 Service & License
- 191 New and Release
- 46 Stories
- 24 Security Advisories
- 452 FAQ
- 209 Nebula FAQ
- 99 Security FAQ
- 65 Switch FAQ
- 63 WirelessLAN FAQ
- 20 Nebula Monthly Express
- 32 About Community
- 20 Security Highlight