<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Implications of &amp;quot;No direct Access to Local Network&amp;quot; toggle in Global protect client settings? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/implications-of-quot-no-direct-access-to-local-network-quot/m-p/430008#M1664</link>
    <description>&lt;P&gt;Hey folks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I, like probably a lot of us these days, use Global protect for the major percentage of the company's workforce. I run split tunneling - internal resources go over the tunnel, anything else just uses the local internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently, I have had the need thrown at me the requirement to provide split tunneling for a set of addresses which are a dynamic DNS entry rather than&amp;nbsp; fixed IP or subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems to be perfect for adding into the "Domains and Applications' section of the client configuration - but after researching, I find this won't work without ticking the "No Direct access to Local Network" toggle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone tell me the implications of doing this? Is it &lt;STRONG&gt;just&lt;/STRONG&gt; the local interface network which can't be accessed while Global protect is running - or does this effectively make split tunneling useless by locking out anything except the tunnel?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't seem to find a definitive answer - it &lt;STRONG&gt;should&lt;/STRONG&gt; just be what the wording says - lockout of the local LAN used to get internet access - but I've had situations where the logical interpretation of Palo Alto speak turns out to be not so logical before!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any input&lt;/P&gt;</description>
    <pubDate>Sun, 29 Aug 2021 23:49:42 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2021-08-29T23:49:42Z</dc:date>
    <item>
      <title>Implications of "No direct Access to Local Network" toggle in Global protect client settings?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/implications-of-quot-no-direct-access-to-local-network-quot/m-p/430008#M1664</link>
      <description>&lt;P&gt;Hey folks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I, like probably a lot of us these days, use Global protect for the major percentage of the company's workforce. I run split tunneling - internal resources go over the tunnel, anything else just uses the local internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently, I have had the need thrown at me the requirement to provide split tunneling for a set of addresses which are a dynamic DNS entry rather than&amp;nbsp; fixed IP or subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems to be perfect for adding into the "Domains and Applications' section of the client configuration - but after researching, I find this won't work without ticking the "No Direct access to Local Network" toggle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone tell me the implications of doing this? Is it &lt;STRONG&gt;just&lt;/STRONG&gt; the local interface network which can't be accessed while Global protect is running - or does this effectively make split tunneling useless by locking out anything except the tunnel?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't seem to find a definitive answer - it &lt;STRONG&gt;should&lt;/STRONG&gt; just be what the wording says - lockout of the local LAN used to get internet access - but I've had situations where the logical interpretation of Palo Alto speak turns out to be not so logical before!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for any input&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 23:49:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/implications-of-quot-no-direct-access-to-local-network-quot/m-p/430008#M1664</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2021-08-29T23:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Implications of "No direct Access to Local Network" toggle in Global protect client settings?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/implications-of-quot-no-direct-access-to-local-network-quot/m-p/430042#M1666</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please point out where you read the constraints of "No direct access to Local Networks" in relation with "Domains and Applications".&lt;/P&gt;&lt;P&gt;On our systems "No direct access to Local Networks" is NOT ticked, but access to domain based destinations is configured (and it seems to work fine).&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 06:17:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/implications-of-quot-no-direct-access-to-local-network-quot/m-p/430042#M1666</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2021-08-30T06:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: Implications of "No direct Access to Local Network" toggle in Global protect client settings?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/implications-of-quot-no-direct-access-to-local-network-quot/m-p/430046#M1667</link>
      <description>&lt;P&gt;The 'domains and apps' section in split tunnelling does require a license, but the access to local network does not need to be enabled&lt;/P&gt;&lt;P&gt;The latter option prevents access to resources on the client's local interface subnet (home printers/Nas device,...) But local internet breakout and tunneled subnets will still be accessible&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 06:40:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/implications-of-quot-no-direct-access-to-local-network-quot/m-p/430046#M1667</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-08-30T06:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: Implications of "No direct Access to Local Network" toggle in Global protect client settings?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/implications-of-quot-no-direct-access-to-local-network-quot/m-p/430255#M1668</link>
      <description>&lt;P&gt;It was a discussion or article I found on here (live community), from memory - I didn't save it, but if I can find it again, I will.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if I simply add the domains I want into the domain based destinations, it should just work? Are the ports optional? or do I have to add them?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 00:27:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/implications-of-quot-no-direct-access-to-local-network-quot/m-p/430255#M1668</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2021-08-31T00:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Implications of "No direct Access to Local Network" toggle in Global protect client settings?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/implications-of-quot-no-direct-access-to-local-network-quot/m-p/430257#M1669</link>
      <description>&lt;P&gt;I do have the Global protect license on the firewall, so that's not an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess I'll just add the domains into the configuration and see what happens. Do you know if the port are optional, or if I have to include them?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 00:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/implications-of-quot-no-direct-access-to-local-network-quot/m-p/430257#M1669</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2021-08-31T00:34:57Z</dc:date>
    </item>
  </channel>
</rss>

