<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Split Tunneling with multiple network adapters in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunneling-with-multiple-network-adapters/m-p/998955#M6268</link>
    <description>&lt;P&gt;Thank you BPry for you reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you would run a f.e. powershell script as post-vpn-command to set routes to certain networks?&lt;/P&gt;&lt;P&gt;I don't think this will solve our problem, we connect sometimes to private networks and don't know the networks. Would it even work if the pan adapter uses metric 1?&lt;/P&gt;</description>
    <pubDate>Thu, 19 Dec 2024 14:20:13 GMT</pubDate>
    <dc:creator>PeterKeller</dc:creator>
    <dc:date>2024-12-19T14:20:13Z</dc:date>
    <item>
      <title>Global Protect Split Tunneling with multiple network adapters</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunneling-with-multiple-network-adapters/m-p/998264#M6238</link>
      <description>&lt;P&gt;Hey community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are struggling with a certain case for many of our customers.&lt;/P&gt;
&lt;P&gt;We have many users working in service who connect to #GlobalProtect with their Windows notebooks via mobile data to #Prisma Cloud. From there, they access the internet or internal resources. We have some bypassed decryption rules.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;For their work, they need to connect via Ethernet to a second network, but they cannot reach it with an established tunnel. I think Split Tunneling would be the right solution.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;However, even if I don't disable access to the local network and exclude the traffic (10.3.33.0/24) for the second network, it is still not reachable. Traceroute shows that it is trying to route the packets through the tunnel.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Does split tunneling in GlobalProtect only bypass traffic from the VPN tunnel and not use another adapter?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;For more explanation, I have added a drawing.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Any ideas or experiences?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance, Peter&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 14:03:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunneling-with-multiple-network-adapters/m-p/998264#M6238</guid>
      <dc:creator>Peter_Keller</dc:creator>
      <dc:date>2024-12-13T14:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Split Tunneling with multiple network adapters</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunneling-with-multiple-network-adapters/m-p/998689#M6262</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/292312"&gt;@Peter_Keller&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I think what you would have to do here going forward is setup a GlobalProtect login script on the machines to properly update the routes to get this to function properly. You'll have to do some testing to ensure that the routes you install are properly removed upon a disconnect.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 21:42:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunneling-with-multiple-network-adapters/m-p/998689#M6262</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-12-17T21:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Split Tunneling with multiple network adapters</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunneling-with-multiple-network-adapters/m-p/998955#M6268</link>
      <description>&lt;P&gt;Thank you BPry for you reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you would run a f.e. powershell script as post-vpn-command to set routes to certain networks?&lt;/P&gt;&lt;P&gt;I don't think this will solve our problem, we connect sometimes to private networks and don't know the networks. Would it even work if the pan adapter uses metric 1?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 14:20:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunneling-with-multiple-network-adapters/m-p/998955#M6268</guid>
      <dc:creator>PeterKeller</dc:creator>
      <dc:date>2024-12-19T14:20:13Z</dc:date>
    </item>
  </channel>
</rss>

