Routing Address Override in SSL-VPN Split Tunnel
We have several user groups mapped to separate, corresponding SSL-VPN Portals. Each of these portals has Split Tunnel Enabled Based on Policy Destination. Each of these portals also has Routing Address Override with network addresses that match the same "allowed destination" addresses in their corresponding policies.
Is Routing Address Override even needed?
According to Split Tunnel Enabled Based on Policy Destination, "Only client traffic in which the destination matches the destination of the configured firewall policies will be directed over the SSL-VPN tunnel."
So in an example where the Accounting network is 192.168.0.0/24 and a user is in the Accounting Group, which is assigned to the Accounting Policy (that allows access to the 192.168.0.0/24 network); Would I even need any address in the Routing Address Override for the Accounting SSL-VPN Portal?
From what I understand, any traffic to 192.168.0.0/24 would go over the SSL-VPN with Split Tunnel Enabled Based on Policy Destination. So what is the point of Routing Address Override?
I ask this because this is how all of our SSL-VPN Portals are configured (by an organization that preceded mine), and I'm looking to consolidate all the SSL-VPN Portals to a single one with no Routing Address Override (but with Split Tunnel Enabled Based on Policy Destination).
