<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GPVPN Split tunnel issue in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gpvpn-split-tunnel-issue/m-p/401271#M1215</link>
    <description>&lt;P&gt;can you send screen dump of both split tunnel access route and split tunnel domain and application&lt;/P&gt;</description>
    <pubDate>Thu, 22 Apr 2021 14:03:25 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2021-04-22T14:03:25Z</dc:date>
    <item>
      <title>GPVPN Split tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gpvpn-split-tunnel-issue/m-p/400443#M1181</link>
      <description>&lt;P&gt;Hi We had recently configured split tunneling on our firewall and had allowed certain subnets via access routes and domains on include domain list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For security purpose changing the domain names:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had added *.google.com on our domain include list to allow access of sites under that domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the end user connects to GPVPN and accesses the google.com it is going through GP-VPN--&amp;gt;F/W--&amp;gt;ISP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we try to access subdomains like admin-dashboard.google.com the traffic is routed through the end user Local ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had configured Internal IP address on Agent DNS IP Setting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here the DNS Query to admin-dashboard.google.com is send to tunnel but the HTTPS traffic to&amp;nbsp;admin-dashboard.google.com is going through end user local ISP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;LI-MESSAGE title="Global VPN" uid="181006" url="https://live.paloaltonetworks.com/t5/general-topics/global-vpn/m-p/181006#U181006" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-forum-thread lia-fa-icon lia-fa-forum lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;LI-MESSAGE title="GlobalProtect: Implement Split Tunnel Domain and Applications" uid="316929" url="https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-implement-split-tunnel-domain-and-applications/m-p/316929#U316929" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-tkb-thread lia-fa-icon lia-fa-tkb lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;LI-MESSAGE title="DNS issue over Global Protect split tunnel" uid="356028" url="https://live.paloaltonetworks.com/t5/general-topics/dns-issue-over-global-protect-split-tunnel/m-p/356028#U356028" discussion_style_icon_css="lia-mention-container-editor-message lia-img-icon-forum-thread lia-fa-icon lia-fa-forum lia-fa-thread lia-fa"&gt;&lt;/LI-MESSAGE&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 10:27:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gpvpn-split-tunnel-issue/m-p/400443#M1181</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-04-22T10:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: GPVPN Split tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gpvpn-split-tunnel-issue/m-p/401052#M1202</link>
      <description>&lt;P&gt;First issue...&lt;/P&gt;&lt;P&gt;The wildcard is working as expected. &amp;nbsp;It means anything before .google.com so this will not include google.com so just add both to the split domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second issue.&lt;/P&gt;&lt;P&gt;nslookup and similar apps will not use the same engine as your browser so the split domain settings will not work for them. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I usually add to browser and wireshark on port 53 to test DNS resolution.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 05:05:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gpvpn-split-tunnel-issue/m-p/401052#M1202</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-04-22T05:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: GPVPN Split tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gpvpn-split-tunnel-issue/m-p/401227#M1212</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp; Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue 1: we had added both google.com and admin-dashobard.google.com to the include domain in the split tunnel but still the traffic is going via end user local nw for the admin-dashboard.google.com site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we need to uninstall and reinstall the GP Client for the settings to get reflected at endpoints.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue 2: We had configured an internal DNS for querying of GP users. Had checked with Wireshark by doing packet capture of GP tunnel could see DNS traffic is successfully send via GP Tunnel but the traffic for&amp;nbsp;admin-dashobard.google.com is still going through local ethernet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All the GP client are Mac OS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts on this on how to proceed further.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 10:23:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gpvpn-split-tunnel-issue/m-p/401227#M1212</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-04-22T10:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: GPVPN Split tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gpvpn-split-tunnel-issue/m-p/401271#M1215</link>
      <description>&lt;P&gt;can you send screen dump of both split tunnel access route and split tunnel domain and application&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 14:03:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gpvpn-split-tunnel-issue/m-p/401271#M1215</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-04-22T14:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: GPVPN Split tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gpvpn-split-tunnel-issue/m-p/403713#M1248</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;I would not be able to share the screenshot of the access routes and domain/application tab as it contains sensitive datas. But now the traffic to that particular sub-domain is passing thru split tunnel but after some time it is being routed thru end-user network.&amp;nbsp; The subdomain is having dynamic IP and it is deployed in AWS. The DNS name resolution is done using internal private DNS server.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 06:14:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gpvpn-split-tunnel-issue/m-p/403713#M1248</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-04-29T06:14:38Z</dc:date>
    </item>
  </channel>
</rss>

