TLDR: Can split-tunneled VPN traffic not be allowed?
I'm running a ICX6450-24. I followed the directions at Fohdeesha Docs to get everything setup and it has been working fine. Once I connect my computer to our university's Cisco AnyConnect VPN — split-tunneling is allowed — I lose the ability to connect to any local resources (e.g., 10.0.1.0/24). I've confirmed that this IP range is listed in the Cisco Route Details Non-Secured Routes.
Is there anything on the ICX6450-24 that could be interfering with the traffic? I didn't have this issue with my previous switch (Dell PowerConnect 2816). I don't have it hooked up that I can re-test at the moment, which is why I'm reaching out here.
I've posted my config in case I mis-configured something. If you can offer any insight that would be great, thank you!
I'm running a ICX6450-24. I followed the directions at Fohdeesha Docs to get everything setup and it has been working fine. Once I connect my computer to our university's Cisco AnyConnect VPN — split-tunneling is allowed — I lose the ability to connect to any local resources (e.g., 10.0.1.0/24). I've confirmed that this IP range is listed in the Cisco Route Details Non-Secured Routes.
Is there anything on the ICX6450-24 that could be interfering with the traffic? I didn't have this issue with my previous switch (Dell PowerConnect 2816). I don't have it hooked up that I can re-test at the moment, which is why I'm reaching out here.
I've posted my config in case I mis-configured something. If you can offer any insight that would be great, thank you!
Code:
==========================================================================
BEGIN : show running-config
CONTEXT : CONSOLE#0 : CONFIG
TIME STAMP : 10:23:53.535 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
Current configuration:
!
ver 08.0.30uT313
!
stack unit 1
module 1 icx6450-24-port-management-module
module 2 icx6450-sfp-plus-4port-40g-module
!
!
!
!
vlan 1 name DEFAULT-VLAN by port
router-interface ve 1
!
!
!
!
!
aaa authentication web-server default local
aaa authentication login default local
enable telnet authentication
enable aaa console
hostname nitrogen
ip dhcp-client disable
ip dns server-address 10.0.1.1
ip route 0.0.0.0/0 10.0.1.1
!
no telnet server
username root password .....
!
!
clock summer-time
clock timezone us Central
!
!
ntp
disable serve
server 216.239.35.0
server 216.239.35.4
!
!
no web-management http
!
!
!
interface ve 1
ip address 10.0.1.100 255.255.255.0
!
!
!
!
!
!
!
!
!
end
==========================================================================
TIME STAMP : 10:23:53.854 Central Mon Jan 30 2023
END : show running-config
TIME TAKEN : 53134306 ticks (265671530 nsec)
==========================================================================
==========================================================================
BEGIN : show version
CONTEXT : CONSOLE#0 : HW INFO
TIME STAMP : 10:23:53.854 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
Copyright (c) 1996-2016 Brocade Communications Systems, Inc. All rights reserved.
UNIT 1: compiled on Apr 23 2020 at 10:57:06 labeled as ICX64R08030u
(9871112 bytes) from Primary ICX64R08030u.bin
SW: Version 08.0.30uT313
Boot-Monitor Image size = 786944, Version:10.1.05T310 (kxz10105)
HW: Stackable ICX6450-24
==========================================================================
UNIT 1: SL 1: ICX6450-24 24-port Management Module
Serial #: 2ax5o2jk68e
License: ICX6450_PREM_ROUTER_SOFT_PACKAGE (LID: H4CKTH3PLN8)
P-ENGINE 0: type DEF0, rev 01
==========================================================================
UNIT 1: SL 2: ICX6450-SFP-Plus 4port 40G Module
==========================================================================
800 MHz ARM processor ARMv5TE, 400 MHz bus
65536 KB flash memory
512 MB DRAM
STACKID 1 system uptime is 11 day(s) 23 minute(s) 36 second(s)
The system started at 10:00:39 Central Thu Jan 19 2023
The system : started=cold start
==========================================================================
TIME STAMP : 10:23:53.945 Central Mon Jan 30 2023
END : show version
TIME TAKEN : 15086484 ticks (75432420 nsec)
==========================================================================
==========================================================================
BEGIN : show interfaces brief
CONTEXT : CONSOLE#0 : PORT STATUS
TIME STAMP : 10:23:53.963 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
Port Link State Dupl Speed Trunk Tag Pvid Pri MAC Name
1/1/1 Up Forward Full 1G None No 1 0 748e.f8b0.44a0
1/1/2 Down None None None None No 1 0 748e.f8b0.44a0
1/1/3 Up Forward Full 1G None No 1 0 748e.f8b0.44a0
1/1/4 Up Forward Full 1G None No 1 0 748e.f8b0.44a0
1/1/5 Down None None None None No 1 0 748e.f8b0.44a0
1/1/6 Down None None None None No 1 0 748e.f8b0.44a0
1/1/7 Down None None None None No 1 0 748e.f8b0.44a0
1/1/8 Down None None None None No 1 0 748e.f8b0.44a0
1/1/9 Down None None None None No 1 0 748e.f8b0.44a0
1/1/10 Down None None None None No 1 0 748e.f8b0.44a0
1/1/11 Down None None None None No 1 0 748e.f8b0.44a0
1/1/12 Down None None None None No 1 0 748e.f8b0.44a0
1/1/13 Down None None None None No 1 0 748e.f8b0.44a0
1/1/14 Down None None None None No 1 0 748e.f8b0.44a0
1/1/15 Down None None None None No 1 0 748e.f8b0.44a0
1/1/16 Down None None None None No 1 0 748e.f8b0.44a0
1/1/17 Down None None None None No 1 0 748e.f8b0.44a0
1/1/18 Down None None None None No 1 0 748e.f8b0.44a0
1/1/19 Down None None None None No 1 0 748e.f8b0.44a0
1/1/20 Down None None None None No 1 0 748e.f8b0.44a0
1/1/21 Down None None None None No 1 0 748e.f8b0.44a0
1/1/22 Down None None None None No 1 0 748e.f8b0.44a0
1/1/23 Down None None None None No 1 0 748e.f8b0.44a0
1/1/24 Down None None None None No 1 0 748e.f8b0.44a0
1/2/1 Down None None None None No 1 0 748e.f8b0.44a0
1/2/2 Down None None None None No 1 0 748e.f8b0.44a0
1/2/3 Down None None None None No 1 0 748e.f8b0.44a0
1/2/4 Down None None None None No 1 0 748e.f8b0.44a0
mgmt1 Down None None None None No None 0 748e.f8b0.44a0
ve1 Up N/A N/A N/A None N/A N/A N/A 748e.f8b0.44a0
==========================================================================
TIME STAMP : 10:23:54.084 Central Mon Jan 30 2023
END : show interfaces brief
TIME TAKEN : 20263672 ticks (101318360 nsec)
==========================================================================
==========================================================================
BEGIN : show statistics ethernet
CONTEXT : CONSOLE#0 : PACKET COUNTERS
TIME STAMP : 10:23:54.085 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
Port Link State Dupl Speed Trunk Tag Pvid Pri MAC Name
1/1/1 Up Forward Full 1G None No 1 0 748e.f8b0.44a0
Port 1/1/1 Counters:
InOctets 2529985912 OutOctets 3189571457
InPkts 9739676 OutPkts 3122756
InBroadcastPkts 4886030 OutBroadcastPkts 1144
InMulticastPkts 2440536 OutMulticastPkts 3243
InUnicastPkts 2413110 OutUnicastPkts 3118369
InBadPkts 0
InFragments 0
InDiscards 0 OutErrors 0
CRC 0 Collisions 0
InErrors 1 LateCollisions 0
InGiantPkts 0
InShortPkts 0
InJabber 0
InFlowCtrlPkts 0 OutFlowCtrlPkts 0
InBitsPerSec 80304 OutBitsPerSec 107960
InPktsPerSec 20 OutPktsPerSec 18
InUtilization 0.00% OutUtilization 0.00%
Port Link State Dupl Speed Trunk Tag Pvid Pri MAC Name
1/1/3 Up Forward Full 1G None No 1 0 748e.f8b0.44a0
Port 1/1/3 Counters:
InOctets 3185313043 OutOctets 1576577892
InPkts 3071073 OutPkts 3035191
InBroadcastPkts 625 OutBroadcastPkts 407669
InMulticastPkts 2992 OutMulticastPkts 277541
InUnicastPkts 3067456 OutUnicastPkts 2349981
InBadPkts 0
InFragments 0
InDiscards 0 OutErrors 0
CRC 0 Collisions 0
InErrors 0 LateCollisions 0
InGiantPkts 0
InShortPkts 0
InJabber 0
InFlowCtrlPkts 16 OutFlowCtrlPkts 0
InBitsPerSec 107896 OutBitsPerSec 78096
InPktsPerSec 18 OutPktsPerSec 19
InUtilization 0.00% OutUtilization 0.00%
Port Link State Dupl Speed Trunk Tag Pvid Pri MAC Name
1/1/4 Up Forward Full 1G None No 1 0 748e.f8b0.44a0
Port 1/1/4 Counters:
InOctets 737562 OutOctets 97006566
InPkts 6382 OutPkts 692663
InBroadcastPkts 10 OutBroadcastPkts 406433
InMulticastPkts 251 OutMulticastPkts 279474
InUnicastPkts 6121 OutUnicastPkts 6756
InBadPkts 0
InFragments 0
InDiscards 0 OutErrors 0
CRC 0 Collisions 0
InErrors 0 LateCollisions 0
InGiantPkts 0
InShortPkts 0
InJabber 0
InFlowCtrlPkts 0 OutFlowCtrlPkts 0
InBitsPerSec 16 OutBitsPerSec 6120
InPktsPerSec 0 OutPktsPerSec 5
InUtilization 0.00% OutUtilization 0.00%
==========================================================================
TIME STAMP : 10:23:57.583 Central Mon Jan 30 2023
END : show statistics ethernet
TIME TAKEN : 583156587 ticks (2915782935 nsec)
==========================================================================
==========================================================================
BEGIN : show logging
CONTEXT : CONSOLE#0 : STATIC/DYNAMIC LOG
TIME STAMP : 10:23:57.704 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
Syslog logging: enabled ( 0 messages dropped, 0 flushes, 105 overruns)
Buffer logging: level ACDMEINW, 50 messages logged
level code: A=alert C=critical D=debugging M=emergency E=error
I=informational N=notification W=warning
Dynamic Log Buffer (50 lines):
Jan 30 10:23:30:I:Security: console login by root to PRIVILEGED EXEC mode
Jan 30 10:23:27:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 10:23:27:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 10:23:27:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 10:23:27:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 10:23:25:I:Security: console login by root to USER EXEC mode
Jan 30 10:16:14:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 10:16:14:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 10:16:14:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 10:16:12:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 10:16:12:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 10:16:12:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 10:09:56:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 10:09:56:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 10:09:56:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 10:09:56:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 10:03:31:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 10:03:31:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 10:03:31:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 10:03:29:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 10:03:29:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 10:03:29:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:56:25:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:56:25:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:56:25:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:56:25:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:50:49:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:50:49:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:50:49:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:50:47:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:50:47:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:50:47:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:42:55:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:42:55:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:42:55:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:42:55:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:38:06:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:38:06:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:38:06:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:38:04:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:38:04:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:38:04:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:29:25:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:29:25:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:29:25:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:29:25:I:SNMP: Auth. failure, intruder IP: 10.0.1.1
Jan 30 09:25:24:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:25:24:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:25:24:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
Jan 30 09:25:22:I:SNMP: Auth. failure, intruder IP: 10.0.1.103
==========================================================================
TIME STAMP : 10:23:57.954 Central Mon Jan 30 2023
END : show logging
TIME TAKEN : 41739781 ticks (208698905 nsec)
==========================================================================
==========================================================================
BEGIN : dm statistics
CONTEXT : CONSOLE#0 : DIAGONSTIC RELATED STATISTICS
TIME STAMP : 10:23:57.959 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
real_transition-transit-sw_reset-discards:
3-0-0-0(1/1/1) 0-0-0-0(1/1/2) 229-0-0-0(1/1/3) 5-0-0-0(1/1/4)
0-0-0-0(1/1/5) 0-0-0-0(1/1/6) 0-0-0-0(1/1/7) 0-0-0-0(1/1/8)
0-0-0-0(1/1/9) 0-0-0-0(1/1/10) 0-0-0-0(1/1/11) 0-0-0-0(1/1/12)
0-0-0-0(1/1/13) 0-0-0-0(1/1/14) 0-0-0-0(1/1/15) 0-0-0-0(1/1/16)
0-0-0-0(1/1/17) 0-0-0-0(1/1/18) 0-0-0-0(1/1/19) 0-0-0-0(1/1/20)
0-0-0-0(1/1/21) 0-0-0-0(1/1/22) 0-0-0-0(1/1/23) 0-0-0-0(1/1/24)
0-0-0-0(1/2/1) 0-0-0-0(1/2/2) 0-0-0-0(1/2/3) 0-0-0-0(1/2/4)
==========================================================================
TIME STAMP : 10:23:57.959 Central Mon Jan 30 2023
END : dm statistics
TIME TAKEN : 90010 ticks (450050 nsec)
==========================================================================
==========================================================================
BEGIN : show media
CONTEXT : CONSOLE#0 : OPTICS TYPE
TIME STAMP : 10:23:58.084 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
Port 1/1/1: Type : 1G M-C (Gig-Copper)
Port 1/1/2: Type : 1G M-C (Gig-Copper)
Port 1/1/3: Type : 1G M-C (Gig-Copper)
Port 1/1/4: Type : 1G M-C (Gig-Copper)
Port 1/1/5: Type : 1G M-C (Gig-Copper)
Port 1/1/6: Type : 1G M-C (Gig-Copper)
Port 1/1/7: Type : 1G M-C (Gig-Copper)
Port 1/1/8: Type : 1G M-C (Gig-Copper)
Port 1/1/9: Type : 1G M-C (Gig-Copper)
Port 1/1/10: Type : 1G M-C (Gig-Copper)
Port 1/1/11: Type : 1G M-C (Gig-Copper)
Port 1/1/12: Type : 1G M-C (Gig-Copper)
Port 1/1/13: Type : 1G M-C (Gig-Copper)
Port 1/1/14: Type : 1G M-C (Gig-Copper)
Port 1/1/15: Type : 1G M-C (Gig-Copper)
Port 1/1/16: Type : 1G M-C (Gig-Copper)
Port 1/1/17: Type : 1G M-C (Gig-Copper)
Port 1/1/18: Type : 1G M-C (Gig-Copper)
Port 1/1/19: Type : 1G M-C (Gig-Copper)
Port 1/1/20: Type : 1G M-C (Gig-Copper)
Port 1/1/21: Type : 1G M-C (Gig-Copper)
Port 1/1/22: Type : 1G M-C (Gig-Copper)
Port 1/1/23: Type : 1G M-C (Gig-Copper)
Port 1/1/24: Type : 1G M-C (Gig-Copper)
Port 1/2/1: Type : EMPTY
Port 1/2/2: Type : EMPTY
Port 1/2/3: Type : EMPTY
Port 1/2/4: Type : EMPTY
==========================================================================
TIME STAMP : 10:23:58.353 Central Mon Jan 30 2023
END : show media
TIME TAKEN : 44928833 ticks (224644165 nsec)
==========================================================================
==========================================================================
BEGIN : dm save-area
CONTEXT : CONSOLE#0 : REGISTER INFO
TIME STAMP : 10:23:58.355 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
[Empty]
==========================================================================
TIME STAMP : 10:23:58.484 Central Mon Jan 30 2023
END : dm save_area
TIME TAKEN : 21479460 ticks (107397300 nsec)
==========================================================================
==========================================================================
BEGIN : show license
CONTEXT : CONSOLE#0 : LICENSE
TIME STAMP : 10:23:58.734 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
License Information
===================
Index Lic Mode Lic Name Lid/Serial No Lic Type Status Lic Period Lic Capacity
Stack unit 1:
1 Node Lock ICX6450-PREM-LIC-SW H4CKTH3PLN8 Normal Active Unlimited 1
2 Node Lock ICX6450-10G-LIC-POD H4CKTH3PLN8 Normal Active Unlimited 2
==========================================================================
TIME STAMP : 10:23:58.740 Central Mon Jan 30 2023
END : show license
TIME TAKEN : 1073960 ticks (5369800 nsec)
==========================================================================
==========================================================================
BEGIN : show stack
CONTEXT : CONSOLE#0 : STACK DETAILS
TIME STAMP : 10:23:58.854 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
Stack Details
=============
T=11d23m41.3: alone: standalone, D: dynamic cfg, S: static
ID Type Role Mac Address Pri State Comment
1 S ICX6450-24 alone 748e.f8b0.44a0 0 local None:0
+---+
2/1| 1 |2/3
+---+
Current stack management MAC is 748e.f8b0.44a0
Image-Auto-Copy is Enabled.
Stack Port Status Neighbors
Unit# Stack-port1 Stack-port2 Stack-port1 Stack-port2
1 none none none none
==========================================================================
TIME STAMP : 10:23:58.855 Central Mon Jan 30 2023
END : show stack
TIME TAKEN : 226154 ticks (1130770 nsec)
==========================================================================
==========================================================================
BEGIN : hw bc
CONTEXT : CONSOLE#0 : HW BUFFER COUNT
TIME STAMP : 10:23:58.855 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
==========================================================================
TIME STAMP : 10:23:58.855 Central Mon Jan 30 2023
END : hw bc
TIME TAKEN : 23845 ticks (119225 nsec)
==========================================================================
==========================================================================
BEGIN : de
CONTEXT : CONSOLE#0 : DUMP EXTRA SYSTEM COUNTERS
TIME STAMP : 10:23:59.103 Central Mon Jan 30 2023
HW/SW INFO : ICX6450-24/ICX64R08030u
==========================================================================
GADDR = 03193020 Dram Buf = 2720
CPU_R = 4284349 Buf Msgs = 0
SNOOP_TX = 2683783 SNOOP_DP = 105715
GET_B = 4318229 FREE_B = 8631931
Sw_Mode = 0 New_Addr = 1905
NA_Learn = 1905 NA_Age = 1768
NA_Update = 0 NA_Hash_Full = 0
NA_Hash_Del = 0 SFLOW_sample = 0
Buf_G_Msgs = 0 Buf_F_Msgs = 0
Buf_Count = 0
CPU_XR[TC0-3 [5435][0][0][0]
CPU_XR[TC4-7 [3747443][99773][0][431698]
==========================================================================
TIME STAMP : 10:23:59.104 Central Mon Jan 30 2023
END : de
TIME TAKEN : 64650 ticks (323250 nsec)
==========================================================================