Bypass VPN for certain apps

18

8

I connect to my company VPN for email, intranet, fileshare etc, but when I'm working I also like to listen to Spotify which is blocked through the company network, so I have to disconnect to the VPN to use it. Is there anything I can do which will enable me to remain connected to the VPN but bypass it for Spotify? I use the Cisco VPN client.

Charlie

Posted 2009-08-04T10:57:25.820

Reputation: 475

Wondering the same thing, specifically for built in VPN client in OSX 10.6 (Snow Leopard). Posted here: http://superuser.com/questions/4904/how-to-selectively-route-network-traffic-through-vpn-on-mac-os-x-leopard/131396#131396

– Josh Newman – 2010-04-15T18:01:33.860

1Potential ServerFault Question? – BinaryMisfit – 2009-08-04T11:16:17.773

Answers

2

This article mentions a method where in the Windows Networking you change the Networking Settings to not use the Remote Default Gateway. I am not sure if this will work for the Cisco VPN Client however.

If I remember correctly there is an option to allow local network traffic in the Advanced Settings of the Cisco VPN Client.

BinaryMisfit

Posted 2009-08-04T10:57:25.820

Reputation: 19 955

1I've tried this settings (not using remote default gateway) and it doesn't give a per application solution. – mindless.panda – 2010-09-22T14:08:25.273

2

The cisco VPN software supports a "split" tunnel right out of the box. The split tunnel will allow you to keep your internet traffic separate from the VPN traffic. This is exactly what you want to do and should get your spotify program working.

Open up your vpn connection and select the modify option. Once in the modify dialog box click on the second tab. At the top of the screen there is a check box "enable transparent tunneling" Check this box and try it again.

Axxmasterr

Posted 2009-08-04T10:57:25.820

Reputation: 7 584

Split Routine has to be enabled on the VPN Server for your user profile before using it on the Client side. – user3767013 – 2014-11-02T20:53:08.880

1I've been using a Cisco VPN client, with this checkbox enabled, but for me, the Internet access is still unavailable :( – Sathyajith Bhat – 2009-08-04T14:36:57.233

I would try configuring a static route to capture all internet traffic. I would force it to the default gateway interface for your local router. – Axxmasterr – 2009-08-04T14:41:05.993

1Any links for the same will be appreciated! – Sathyajith Bhat – 2009-08-04T14:46:05.890

1http://www.mydigitallife.info/2008/12/25/how-to-add-route-to-tcpip-routing-table-with-windows-routing-and-remote-access-console-or-dos-prompt/ You might try "route print" from a dos box to get started. – Axxmasterr – 2009-08-04T15:11:58.687

2

Latest versions of Cisco VPN Client don't allow you to override the routing if your network admin has disabled local lan access.

Even logging as admin on your local machine and modifying the routing table will not change anything as the VPN Client still blocks it.

vpn_dude

Posted 2009-08-04T10:57:25.820

Reputation: 21

Any creative ways around this? Multiple network adapters? Third party or open source VPN clients compatible with Cisco hardware? Connecting to the VPN from a router?

The Cisco client is basically deprecated anyhow, isn't it? – ShadowChaser – 2012-11-29T01:51:04.683

1

Can you change your default gateway so it uses your internet connection instead of the VPN? This will mean that only things not on the general internet (such as your intranet and fileshare) go over the VPN.

Alternatively, you should be able to setup a static route so that connections to 10...* (i.e. your companies VPN range) go over the VPN and everything else goes to your internet connection. This setup will differ depending on your OS.

Of course, if your company is using "public IP space" (i.e. outside the 10.* and 192.168.* ranges) then it's going to start getting very tricky.

Richy B.

Posted 2009-08-04T10:57:25.820

Reputation: 133

1

If you go to the Cisco VPN client preferences. Uncheck "Enable local LAN access (if configured". For myself, I am using a remote desktop connection to a remote location and my local browser resolves to my local IP.

amkread

Posted 2009-08-04T10:57:25.820

Reputation: 11