<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split tunnel and full tunnel in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/split-tunnel-and-full-tunnel/m-p/429090#M1654</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Split tunneling means you route only the desired subnet into the tunnel. For example the office subnet is 192.168.1.0/24 and this is routed inside. The firewall can scan this traffic and you can apply rules as such.&lt;/P&gt;&lt;P&gt;The problem here is all other traffic, like general web browsing, is egressing from the endpoint to the ISP and not through the NGFW.&lt;/P&gt;&lt;P&gt;Simple put the endpoint has 2 connections - 1 for the office and the other for everything else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Full tunneling means you route EVERYTHING into the NGFW, via security rules and scanning profiles, just like if the endpoint would be inside the corporate network. Security wise this is the best option.This also means increased traffic through the firewall because ALL browsing from GP connected endpoints passes through the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Shai&lt;/P&gt;</description>
    <pubDate>Wed, 25 Aug 2021 11:55:23 GMT</pubDate>
    <dc:creator>ShaiW</dc:creator>
    <dc:date>2021-08-25T11:55:23Z</dc:date>
    <item>
      <title>Split tunnel and full tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/split-tunnel-and-full-tunnel/m-p/428801#M1650</link>
      <description>&lt;P&gt;Hey guys can anyone tell me the proper definition of split tunnel and full tunnel in Global protect. within proper life example, please.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 15:53:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/split-tunnel-and-full-tunnel/m-p/428801#M1650</guid>
      <dc:creator>FarhanKoujalgi</dc:creator>
      <dc:date>2021-08-24T15:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and full tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/split-tunnel-and-full-tunnel/m-p/429090#M1654</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Split tunneling means you route only the desired subnet into the tunnel. For example the office subnet is 192.168.1.0/24 and this is routed inside. The firewall can scan this traffic and you can apply rules as such.&lt;/P&gt;&lt;P&gt;The problem here is all other traffic, like general web browsing, is egressing from the endpoint to the ISP and not through the NGFW.&lt;/P&gt;&lt;P&gt;Simple put the endpoint has 2 connections - 1 for the office and the other for everything else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Full tunneling means you route EVERYTHING into the NGFW, via security rules and scanning profiles, just like if the endpoint would be inside the corporate network. Security wise this is the best option.This also means increased traffic through the firewall because ALL browsing from GP connected endpoints passes through the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Shai&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 11:55:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/split-tunnel-and-full-tunnel/m-p/429090#M1654</guid>
      <dc:creator>ShaiW</dc:creator>
      <dc:date>2021-08-25T11:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and full tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/split-tunnel-and-full-tunnel/m-p/429922#M1663</link>
      <description>&lt;P&gt;Exactly as per&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36075"&gt;@ShaiW&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;but we have all traffic, office based and internet base tunnelled via GP and only split tunnel local traffic for teams and outlook. &amp;nbsp;Those 2 applications account for approx 80% of user bandwidth so helps to prevent gateway isp links from melting...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 11:26:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/split-tunnel-and-full-tunnel/m-p/429922#M1663</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-08-28T11:26:15Z</dc:date>
    </item>
  </channel>
</rss>

