I need to configure our SA4500 to permit vpn access to a remote site only - however I also need to permit them to get to the internet through the main site Websense.
I have configured a Network Connect Access Policy to permit 10.100.10.0/24 under resources
However I am not sure how to deny all other internal networks but allow access to the internet
Split tunnelling is not allowed traffic has to go back through main site.
Under resources tab:
10.100.10.0/24
Then I need to have a deny 10.0.0.0/8
permit anything else?
I have found the answer - Detailed Rules!
Allow - site subnet
Allow - site DNS servers
Deny - all other inernal networks
Allow - *
Works a treat