<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possbile to use an EDL in GW split tunnel config? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/517589#M3251</link>
    <description>&lt;P&gt;By this "This should be added" I meant that it is not possible in the current software but it seems to me like an easy fix with RFE (&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-to-use-palo-alto-networks-new-feature-request/ba-p/409590" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/blogs/how-to-use-palo-alto-networks-new-feature-request/ba-p/409590&lt;/A&gt; ) to palo alto as Palo Alto has some premade EDL lists and they can feed the data after processing it&amp;nbsp; through their EDL service for Office 365 (&lt;A href="https://docs.paloaltonetworks.com/resources/edl-hosting-service" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/resources/edl-hosting-service&lt;/A&gt; ) as they already do&amp;nbsp; ( &lt;A href="https://live.paloaltonetworks.com/t5/blogs/edl-hosting-service-helps-to-safely-enable-microsoft-365/ba-p/410972" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/blogs/edl-hosting-service-helps-to-safely-enable-microsoft-365/ba-p/410972&lt;/A&gt; ) or as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104490"&gt;@dmuirhead&lt;/a&gt;&amp;nbsp; mentioned to use minemeld or misp as a free solution but as mentioned as of now EDL can't be used for split-tunnel. For Zoom you will need to do this using minemeld/misp as it is not available as EDL in the SaaS EDL service but you can check with Palo Alto.&amp;nbsp; &lt;EM&gt;Sorry for misunderstanding me as I admit I was not very clear&lt;/EM&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For now maybe split-tunnel based on application would have been possible workaround if an agent was installed on the PC but this is not the case with many (maybe a good option for the zoom app but not for web access or office 365) &lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-gateways/split-tunnel-traffic-on-globalprotect-gateways/configure-a-split-tunnel-based-on-the-domain-and-application" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-gateways/split-tunnel-traffic-on-globalprotect-gateways/configure-a-split-tunnel-based-on-the-domain-and-application&lt;/A&gt; . Also using wildcard domains may work but then if the Palo Alto resolves the destination domain to a different ip address using its own DNS resolution than the client DNS resolution as this could happen with modern DNS systems this can be an issue but maybe if the Palo Alto is the DNS proxy for the clients if possible this could make certain that the same DNS will be resolved to the same ip address. I had in one company this issue and this is why we did not use domains with wildcard but we never tested if the DNS proxy feature is used will this issue be seen again, but it could be worth it &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFcCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFcCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still as palo alto's suggestion &lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-optimizing-office-365-traffic/ta-p/319669" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-optimizing-office-365-traffic/ta-p/319669&lt;/A&gt; an automation can be created that updates the firewalls using REST-API or Palo Alto XSOAR could be tested to retrive the list and feed it to the firewalls as an &lt;EM&gt;&lt;STRONG&gt;Address Objec&lt;/STRONG&gt;&lt;/EM&gt;t as there is a trial community edition for XSOAR it could be tested.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/panorama" target="_blank" rel="noopener"&gt;https://xsoar.pan.dev/docs/reference/integrations/panorama&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://start.paloaltonetworks.com/sign-up-for-community-edition.html" target="_blank" rel="noopener"&gt;https://start.paloaltonetworks.com/sign-up-for-community-edition.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XSOAR can fetch the zoom and office 365 lists format them and feed it to the firewalls!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/zoom-feed" target="_blank" rel="noopener"&gt;https://xsoar.pan.dev/docs/reference/integrations/zoom-feed&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/office-365-feed" target="_blank" rel="noopener"&gt;https://xsoar.pan.dev/docs/reference/integrations/office-365-feed&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XSOAR is the next minemeld:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/articles/minemeld-migration" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/articles/minemeld-migration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also Ansible or Terraform can be tested as they are free and much better than a python script as they willl not change the config even when the automation is triggered if there is no real change to the address list but still XSOAR will provide more options expecially for getting the feed lists and feeding them to the Palo Alto firewalls as EDL or Address objects (it can also feed url/fqdn objects but I think even the latest versions of palo alto PAN-OS can't use fqdn objects for split-tunnel):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ansible-pan.readthedocs.io/en/latest/modules/panos_address_object_module.html" target="_blank" rel="noopener"&gt;https://ansible-pan.readthedocs.io/en/latest/modules/panos_address_object_module.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://registry.terraform.io/providers/PaloAltoNetworks/panos/latest/docs/resources/address_object" target="_blank" rel="noopener"&gt;https://registry.terraform.io/providers/PaloAltoNetworks/panos/latest/docs/resources/address_object&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Oct 2022 14:13:33 GMT</pubDate>
    <dc:creator>nikoolayy1</dc:creator>
    <dc:date>2022-10-12T14:13:33Z</dc:date>
    <item>
      <title>Is it possbile to use an EDL in GW split tunnel config?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/334840#M232</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the title suggests; is it possible to use an EDL in split-tunnel config?&amp;nbsp; I'd like to be able to use Minemeld to grab Office 365 IPs &amp;amp; URLs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 16:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/334840#M232</guid>
      <dc:creator>dmuirhead</dc:creator>
      <dc:date>2020-06-23T16:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possbile to use an EDL in GW split tunnel config?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/335354#M237</link>
      <description>&lt;P&gt;Unfortunately, you cannot use EDLs in split tunneling. You can use address objects and address groups.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 16:09:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/335354#M237</guid>
      <dc:creator>domari</dc:creator>
      <dc:date>2020-06-25T16:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possbile to use an EDL in GW split tunnel config?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/472585#M2567</link>
      <description>&lt;P&gt;This should be added as&amp;nbsp; I don't know if anyone has seen that now zoom and office 365 have autodiscover URL for the source ip addresses and maybe Palo Alto may need to include the use of External Dynamic Lists (EDL) in the Globalprotect VPN split tunnel:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://assets.zoom.us/docs/ipranges/Zoom.txt" target="_blank" rel="noopener"&gt;https://assets.zoom.us/docs/ipranges/Zoom.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;A href="https://endpoints.office.com/endpoints/worldwide?clientrequestid=b10c5ed1-bad1-445f-b386-b919946339a7" target="_blank" rel="noopener"&gt;https://endpoints.office.com/endpoints/worldwide?clientrequestid=b10c5ed1-bad1-445f-b386-b919946339a7&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Sun, 13 Mar 2022 09:47:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/472585#M2567</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-03-13T09:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possbile to use an EDL in GW split tunnel config?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/516131#M3196</link>
      <description>&lt;P&gt;were you even able to create an EDL with that zoom link? When I attempt to, I get 1 address of 0.0.0.0/32&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 22:32:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/516131#M3196</guid>
      <dc:creator>PaulArcellx</dc:creator>
      <dc:date>2022-09-27T22:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possbile to use an EDL in GW split tunnel config?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/516391#M3204</link>
      <description>&lt;P&gt;Unfortunately, using EDLs for split tunneling is not supported per previous threads.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/dynamically-update-microsoft-office-urls-and-ips/m-p/514783/highlight/true#M106838" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/dynamically-update-microsoft-office-urls-and-ips/m-p/514783/highlight/true#M106838&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 18:56:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/516391#M3204</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-09-29T18:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possbile to use an EDL in GW split tunnel config?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/517589#M3251</link>
      <description>&lt;P&gt;By this "This should be added" I meant that it is not possible in the current software but it seems to me like an easy fix with RFE (&lt;A href="https://live.paloaltonetworks.com/t5/blogs/how-to-use-palo-alto-networks-new-feature-request/ba-p/409590" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/blogs/how-to-use-palo-alto-networks-new-feature-request/ba-p/409590&lt;/A&gt; ) to palo alto as Palo Alto has some premade EDL lists and they can feed the data after processing it&amp;nbsp; through their EDL service for Office 365 (&lt;A href="https://docs.paloaltonetworks.com/resources/edl-hosting-service" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/resources/edl-hosting-service&lt;/A&gt; ) as they already do&amp;nbsp; ( &lt;A href="https://live.paloaltonetworks.com/t5/blogs/edl-hosting-service-helps-to-safely-enable-microsoft-365/ba-p/410972" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/blogs/edl-hosting-service-helps-to-safely-enable-microsoft-365/ba-p/410972&lt;/A&gt; ) or as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104490"&gt;@dmuirhead&lt;/a&gt;&amp;nbsp; mentioned to use minemeld or misp as a free solution but as mentioned as of now EDL can't be used for split-tunnel. For Zoom you will need to do this using minemeld/misp as it is not available as EDL in the SaaS EDL service but you can check with Palo Alto.&amp;nbsp; &lt;EM&gt;Sorry for misunderstanding me as I admit I was not very clear&lt;/EM&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For now maybe split-tunnel based on application would have been possible workaround if an agent was installed on the PC but this is not the case with many (maybe a good option for the zoom app but not for web access or office 365) &lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-gateways/split-tunnel-traffic-on-globalprotect-gateways/configure-a-split-tunnel-based-on-the-domain-and-application" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-gateways/split-tunnel-traffic-on-globalprotect-gateways/configure-a-split-tunnel-based-on-the-domain-and-application&lt;/A&gt; . Also using wildcard domains may work but then if the Palo Alto resolves the destination domain to a different ip address using its own DNS resolution than the client DNS resolution as this could happen with modern DNS systems this can be an issue but maybe if the Palo Alto is the DNS proxy for the clients if possible this could make certain that the same DNS will be resolved to the same ip address. I had in one company this issue and this is why we did not use domains with wildcard but we never tested if the DNS proxy feature is used will this issue be seen again, but it could be worth it &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFcCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFcCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still as palo alto's suggestion &lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-optimizing-office-365-traffic/ta-p/319669" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/globalprotect-articles/globalprotect-optimizing-office-365-traffic/ta-p/319669&lt;/A&gt; an automation can be created that updates the firewalls using REST-API or Palo Alto XSOAR could be tested to retrive the list and feed it to the firewalls as an &lt;EM&gt;&lt;STRONG&gt;Address Objec&lt;/STRONG&gt;&lt;/EM&gt;t as there is a trial community edition for XSOAR it could be tested.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-panorama-api/get-started-with-the-pan-os-rest-api/work-with-address-objects-rest-api&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/panorama" target="_blank" rel="noopener"&gt;https://xsoar.pan.dev/docs/reference/integrations/panorama&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://start.paloaltonetworks.com/sign-up-for-community-edition.html" target="_blank" rel="noopener"&gt;https://start.paloaltonetworks.com/sign-up-for-community-edition.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XSOAR can fetch the zoom and office 365 lists format them and feed it to the firewalls!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/zoom-feed" target="_blank" rel="noopener"&gt;https://xsoar.pan.dev/docs/reference/integrations/zoom-feed&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/office-365-feed" target="_blank" rel="noopener"&gt;https://xsoar.pan.dev/docs/reference/integrations/office-365-feed&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XSOAR is the next minemeld:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://xsoar.pan.dev/docs/reference/articles/minemeld-migration" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/articles/minemeld-migration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also Ansible or Terraform can be tested as they are free and much better than a python script as they willl not change the config even when the automation is triggered if there is no real change to the address list but still XSOAR will provide more options expecially for getting the feed lists and feeding them to the Palo Alto firewalls as EDL or Address objects (it can also feed url/fqdn objects but I think even the latest versions of palo alto PAN-OS can't use fqdn objects for split-tunnel):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ansible-pan.readthedocs.io/en/latest/modules/panos_address_object_module.html" target="_blank" rel="noopener"&gt;https://ansible-pan.readthedocs.io/en/latest/modules/panos_address_object_module.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://registry.terraform.io/providers/PaloAltoNetworks/panos/latest/docs/resources/address_object" target="_blank" rel="noopener"&gt;https://registry.terraform.io/providers/PaloAltoNetworks/panos/latest/docs/resources/address_object&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 14:13:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/517589#M3251</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-10-12T14:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possbile to use an EDL in GW split tunnel config?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/581906#M5192</link>
      <description>&lt;P&gt;EDL is not supported for GlobalProtect users, however we can create an external resource stored on a web-server to make the end user globalprotect to download it and manage it such as an EDL,&amp;nbsp; here's the documentation:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-gateways/host-a-split-tunnel-configuration-file-on-a-web-server" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-gateways/host-a-split-tunnel-configuration-file-on-a-web-server&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 16:14:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possbile-to-use-an-edl-in-gw-split-tunnel-config/m-p/581906#M5192</guid>
      <dc:creator>jfernandez1</dc:creator>
      <dc:date>2024-03-27T16:14:42Z</dc:date>
    </item>
  </channel>
</rss>

