<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Split Tunnelling on Domains - client version issue? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/443301#M1929</link>
    <description>&lt;P&gt;Not sure if you are aware but to use DNS based split tunnelling you have to have a gateway subscription on your firewall also&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-overview/about-globalprotect-licenses.html" target="_blank"&gt;About GlobalProtect Licenses (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Oct 2021 01:03:20 GMT</pubDate>
    <dc:creator>rajjair</dc:creator>
    <dc:date>2021-10-26T01:03:20Z</dc:date>
    <item>
      <title>Global Protect Split Tunnelling on Domains - client version issue?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/359452#M535</link>
      <description>&lt;P&gt;Hey folks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're planning in implementing MFA for Office 365, and as part of that I want to add the Microsoft office domains into our Global protect split tunnels - since almost everyone is working from home, I want to whitelist our "corporate" IP addresses and have people who are connected from company PC's on the VPN not be bothered by MFA requests.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is relatively easy in the configuration, but I've come across an issue which is perplexing me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I run my personal machine on a fairly recent VPN client to check for issues before pushing it out to the main portal for users to upgrade - and when I implemented this split tunnel on the portal, it didn't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A colleague who is running the "production" release I have on the portal. So I downgraded tot hat version - and the split tunnelled domains work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know if there's something extra in the later clients which needs to be done to make this work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Working client version - 5.0.8&lt;/P&gt;&lt;P&gt;Failed client version - 5.2.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 23:24:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/359452#M535</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2020-10-28T23:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Split Tunnelling on Domains - client version issue?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/387707#M949</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2280"&gt;@darren_g&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am running GP version 5.2.4 and split tunnel is working fine.&lt;/P&gt;
&lt;P&gt;We have configured all Microsoft domains and IP to bypass the tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try to upgrade to 5.2.4.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 03:38:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/387707#M949</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-02-25T03:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Split Tunnelling on Domains - client version issue?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/387743#M951</link>
      <description>&lt;P&gt;I've just typed a lot at&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-office-365-split-tunnel/m-p/387607/highlight/false#M946" target="_blank"&gt;LIVEcommunity - Global Protect Office 365 Split Tunnel - LIVEcommunity - 387607 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had it all working on 5.1.8 / 8.1.X&lt;/P&gt;&lt;P&gt;Since moving to virtual Azure appliances 5.2.X/9.1.6 we've had all kinds of issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's a setting for GP to do split only for network or for both network &amp;amp; dns.&lt;/P&gt;&lt;P&gt;Not sure if that will solve things as we are in the middle of investigating with TAC&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 08:20:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/387743#M951</guid>
      <dc:creator>sebastianvd</dc:creator>
      <dc:date>2021-02-25T08:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Split Tunnelling on Domains - client version issue?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/388502#M964</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3467"&gt;@sebastianvd&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to use split tunnel based on network then it is good practice to also use split tunnel based on DNS.&lt;/P&gt;
&lt;P&gt;That way GP agent will not contact the configured GP DNS server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should use the split tunnel based on the DNS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 02:16:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/388502#M964</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-03-02T02:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Split Tunnelling on Domains - client version issue?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/397947#M1161</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/3467"&gt;@sebastianvd&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I've just typed a lot at&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-office-365-split-tunnel/m-p/387607/highlight/false#M946" target="_blank" rel="noopener"&gt;LIVEcommunity - Global Protect Office 365 Split Tunnel - LIVEcommunity - 387607 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had it all working on 5.1.8 / 8.1.X&lt;/P&gt;&lt;P&gt;Since moving to virtual Azure appliances 5.2.X/9.1.6 we've had all kinds of issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's a setting for GP to do split only for network or for both network &amp;amp; dns.&lt;/P&gt;&lt;P&gt;Not sure if that will solve things as we are in the middle of investigating with TAC&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I wasn't able to get it working on DNS-based names,but fortunately, Microsoft has a list of IP's you need to add into the tunnel, so I just added a whole bunch of route/groups and made it work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's a pity, because it'd be such a great feature - for anything "xx.microsoft.com", send the traffic over the tunnel - but instead it's all based on IP ranges now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Made it work, but it wasn;t as easy as it should have been.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 23:23:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/397947#M1161</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2021-04-13T23:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Split Tunnelling on Domains - client version issue?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/443301#M1929</link>
      <description>&lt;P&gt;Not sure if you are aware but to use DNS based split tunnelling you have to have a gateway subscription on your firewall also&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-overview/about-globalprotect-licenses.html" target="_blank"&gt;About GlobalProtect Licenses (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 01:03:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnelling-on-domains-client-version-issue/m-p/443301#M1929</guid>
      <dc:creator>rajjair</dc:creator>
      <dc:date>2021-10-26T01:03:20Z</dc:date>
    </item>
  </channel>
</rss>

