We are running two sa-6000 active/passive and we have disabled split tunneling. I have heard from 3 diffrent users that are able to split tunnel this is out of 30k+ users. Now others could be using it and not notifying us. I can not duplicate this behavior it happens for these users at home and they are not running anything special. Default ip pool 192.168.1.1 / 24. Linksys / Dlink router. some file and database servers. These users can access these file and DB server even after they have established a full tunnel. I have rechecked all my roles and i don't see how is this working. their routing table does not show anything out of the oridinary either. If they do a trace to one of their local comptuers it starts from their computer and than comes into our network and after 4-5th HOP jumps back to their home network and finishes on the server on their local network.
I am running 6.3R2-1
Yes, I can confirm the problem and there should be opened ticked allready at Juniper. I would really clasify this as a serious security issue. To see this, you need this:
Windows Vista - what a surprise :-) and a virtual network inter face such as vmware or bluetooth pan. It was tested on several notebooks with Intel 4965AGN wifi card and on 6.3R2-1