This message was deleted.
# citrix-netscaler
s
This message was deleted.
j
As far as I recall, ACL is the way
k
uhm, ok... so for the pooled IPs just a deny rule for the whole pool as destination?
if I have pools like 10.0.0.0/24 10.0.1.0/24 ... in the range if 10.0.0.0/16, I would just block that whole /16 as destination?
Finally found some time to check this; apparently we have this problem (with split tunnel at least) only if we include the IP pool ranges in the intranet applications (if the network is not included in the split tunnel, the client tries to route the packet from it's default gateway rather than to the tunnel. I think we'll just configure the intranet apps so that the pool range is not included and this should circumvent the issue.