
MischkaP.72923 (Customer) asked a question.
Hello we have a split tunnel VPN and I am getting interdicted with off netowork MFA that I set up even though we have implemented the instructions to push okta traffic over the VPN. Why are the apps still interdicting as if I am off network even when I am connected to the VPN. We are using Cisco ASA. We have already explored:
https://help.okta.com/en/prod/Content/Topics/Apps/Apps_VPN_Notification.htm
https://help.okta.com/en/prod/Content/Topics/Security/Firewall_Whitelisting.htm

Use the Okta system log to view your IP address when you connect to Okta, to determine if your connection is going out through the VPN connection. If it is AND if that IP address is in your "on network" list AND that list is used in a sign-in rule to control the MFA requirement, then it should work.
We also have Cisco ASA, and I have several app-level sign-in rules that prompt the user for MFA when they're off network. It's not a split-tunnel configuration, but that's really irrelevant. All that matters is the IP address that Okta sees when you sign-in.
Mike thank you - our engineerts determined that there was another layer to this: