Forse in relazione a quel che mi serve, e a quanto mi ha confermato ZOT, la soluzione è nella risposta di questa persona:
VPN users cannot browse the Internet through the VPN. Traffic that enters the PIX on an interface cannot exit on the same interface.
Workaround:setup split-tunneling, so that the VPN user uses their own Internet connection, and only routes traffic destined for the corporate LAN over the VPN.
vpngroup GROUPNAME split-tunnel accesslistname
Where accesslistname is an access-list that defines traffic going from your corporate LAN to the ip pool you have setup for the VPN users.
Keep in mind, this is a security risk, because anything that can touch the VPN users' computer over their Internet connection, now has a link to your corporate network.
HTH.
Ho provato a riscrivere la conf aggiungendo quanto segue, ma nulla
access-list from-outside-coming-in permit ip 10.1.1.0 255.255.255.0 any
access-list from-outside-coming-in permit icmp any any echo-reply
access-list from-outside-coming-in permit icmp any any unreachable
access-list from-outside-coming-in permit icmp any any time-exceeded
access-list from-outside-coming-in deny tcp any any eq 135
access-list from-outside-coming-in deny udp any any eq netbios-ns
access-list from-outside-coming-in deny udp any any eq netbios-dgm
access-list from-outside-coming-in deny tcp any any eq netbios-ssn
access-list from-outside-coming-in deny tcp any any eq 445
access-list from-outside-coming-in permit tcp any interface outside eq smtp
access-list from-outside-coming-in permit tcp any interface outside eq www
access-list from-inside-going-out permit ip 10.1.1.0 255.255.255.0 any
access-list from-inside-going-out deny tcp any any eq 135
access-list from-inside-going-out deny udp any any eq netbios-ns
access-list from-inside-going-out deny udp any any eq netbios-dgm
access-list from-inside-going-out deny tcp any any eq netbios-ssn
access-list from-inside-going-out deny tcp any any eq 445
access-list from-inside-going-out permit ip any any
access-group from-outside-coming-in in interface outside
access-group from-inside-going-out in interface inside
vpngroup gruppoVPN_Home split-tunnel from-inside-going-out
Help me please