The choice is all yours. It sounds like you have split tunneling disabled and an ACL of *:* which would enforce any traffic filters you have on your network. You can modify your ACL if you want to set only specific devices/services. Unfortunately the best practice is site-by-site, role-by-role for policies you want to use or not use. Sorry :(
... View more