Hi Everyone,

We are looking to use vMX as our main host to remotely connect (using anyconnect) to our corporate resources yet still be able to selectively reach public internet (split-tunnel) via vMX's public ip interface (NAT).

We are using this document as our guide and to understand it's operation

In passthrough mode, vpn clients are able to reach our corporate network but can't hit any public internet. (google, yahoo..etc).

In Routed (NAT) mode, vpn clients is able to reach the internet through vMX's public internet interface but it can't reach the corporate network anymore. Also, all the subnets in the VPN topology can no longer reach vMX's downsteam (local) subnet. From what we have observe, this is "maybe" because vMX stopped advertising it's subnet in the VPN topology if set to Routed mode.


The vMX is in AWS public subnet

Need idea how to get these vpn clients be able to reach the internet yet still be able to reach it's corporate network and vMX subnet is still available from the rest of the VPN topology

Have you tried changing the client routing?




yes, we already played around that settings. With MX, Passthrough and Routed is working as expected but not in vMX

