Forum Discussion
VPN - Disallow networks accessible via access policy "exclude" or via APM ACL instead?
- Jan 26, 2021
IMHO, ACLs are the safest way. Excluded networks setting is part of the split tunneling configuration so it is strictly related to routes pushed to the client. With ACL, you are actually controlling what is allowed or not in the BIG-IP side. The difference may not seem important, but recently I was able to trick my windows host to change the routing entries of my machine in order to bypass the split tunneling configuration pushed to the client VPN, though it was with another -so popular- vendor VPN client that claims its global protection features ;p
IMHO, ACLs are the safest way. Excluded networks setting is part of the split tunneling configuration so it is strictly related to routes pushed to the client. With ACL, you are actually controlling what is allowed or not in the BIG-IP side. The difference may not seem important, but recently I was able to trick my windows host to change the routing entries of my machine in order to bypass the split tunneling configuration pushed to the client VPN, though it was with another -so popular- vendor VPN client that claims its global protection features ;p
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com