Hello,
I am having a bit of trouble grasping split tunneling in SASE, as I am getting some contradicting information.
Question:
Does "Full Tunnel" still allow access to the local LAN (directly connected network), or will that traffic be routed to the SASE network?
I have spoken to Support about this and received different answers. Yes, and no.
Assuming it's no, I would have to switch to Exclude mode if I want to avoid local traffic to be routed into the SASE network. In that case, how can I establish cross-site communications?
Example:
Site 1: 192.168.0.0/24
Site 2: 10.10.10.0/24
Two IPSec tunnels, connecting each site to Harmony SASE. Split Tunnel configuration set to exclude both networks, so each network can access local ressources without going through the SASE tunnel.
In that scenario, how would 192.168.0.0/24 communicate with 10.10.10.0/24 (and vice versa), given both are now excluded from the tunnel? Would I set up static routes in the SASE network?