Is there a way to give IPsec clients a list of subnets that should be routed through the tunnel?
For instance, can I have IPsec clients route the LAN subnet, DMZ subnet, and a few other custom subnets through the tunnel, while everything else would exit through their regular Internet connection?
How would I do that?
Is this generally considered bad practice?
I know this doesn't answer your question, but pushing routes is trivial in openvpn.
Bart...
Right, I will try OpenVPN in the future.
Does anybody know if it can be done in IPsec, and how?