<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do tha in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/366438#M628</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AccessroutePIC.png" style="width: 798px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28877iC556DD33F35FB276/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="AccessroutePIC.png" alt="AccessroutePIC.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Dec 2020 11:23:32 GMT</pubDate>
    <dc:creator>axelrafaeltadoy</dc:creator>
    <dc:date>2020-12-01T11:23:32Z</dc:date>
    <item>
      <title>Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do that</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/364552#M586</link>
      <description>&lt;DIV class="_3xX726aBn29LDbsDtzr_6E _1Ap4F5maDtT1E1YuCiaO0r D3IL3FD0RFy_mkKLPwL4"&gt;&lt;DIV class="_292iotee39Lmt0MkQZ2hPV RichTextJSON-root"&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Hello masters,&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I need your help on how to troubleshoot an issue related to global protect.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;On our Access routes, no &lt;A href="https://0.0.0.0" target="_blank" rel="noopener nofollow ugc"&gt;0.0.0.0&lt;/A&gt; are configured.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;We wanted to let users use their local gateway for any traffic destined to the internet.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;But they are receiving the 0.0.0.0 in their RoutePrint resulting to traversing their any traffic to the VPN.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;This is clogging our network.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;I already engaged 3 TAC on this but could not find the issue.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Details:&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Software Version8.1.9-h4&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;GlobalProtect Agent4.1.10&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;RoutePrint:&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Active Routes:&lt;BR /&gt;Network Destination Netmask Gateway Interface Metric&lt;BR /&gt;0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.199 35&lt;BR /&gt;0.0.0.0 0.0.0.0 On-link 10.0.0.201 50&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 20 Nov 2020 17:58:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/364552#M586</guid>
      <dc:creator>axelrafaeltadoy</dc:creator>
      <dc:date>2020-11-20T17:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do tha</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/364645#M587</link>
      <description>&lt;P&gt;Please post a picture or details of your split tunnel configuration on your gateway.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Nov 2020 03:55:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/364645#M587</guid>
      <dc:creator>staustin</dc:creator>
      <dc:date>2020-11-21T03:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do tha</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/366438#M628</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AccessroutePIC.png" style="width: 798px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28877iC556DD33F35FB276/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="AccessroutePIC.png" alt="AccessroutePIC.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 11:23:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/366438#M628</guid>
      <dc:creator>axelrafaeltadoy</dc:creator>
      <dc:date>2020-12-01T11:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do tha</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/366440#M629</link>
      <description>&lt;P&gt;Please see below access route&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AccessroutePIC.png" style="width: 798px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28878i46F616A52A769EED/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="AccessroutePIC.png" alt="AccessroutePIC.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 11:25:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/366440#M629</guid>
      <dc:creator>axelrafaeltadoy</dc:creator>
      <dc:date>2020-12-01T11:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do tha</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/366604#M635</link>
      <description>&lt;P&gt;default routes 0.0.0/0 always apply whether using split tunnel or not.&lt;/P&gt;&lt;P&gt;your more specific routes /32 /24/23 etc will take precedence over /0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any more information in your route print or have you just left it out.....&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 17:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/366604#M635</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-01T17:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do tha</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/366737#M643</link>
      <description>&lt;P&gt;We have had a similar issue, the workaround for us was to exclude the default route from the split tunnel.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 13:03:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/366737#M643</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2020-12-02T13:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do tha</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/366763#M644</link>
      <description>&lt;P&gt;Hmmm there must be something odd with your settings if thats the case...&lt;/P&gt;&lt;P&gt;I have a test gateway that only includes 10.0.0.0/8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;route print below...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1606918760207.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28928i598470AD52BAC284/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1606918760207.png" alt="MickBall_0-1606918760207.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;so any unknown traffic such as 8.8.8.8 has 2 default routes but the local interface has a lower metric (35) so no traffic goes down the tunnel unless its within 10.0.0.0/8.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perhaps your metric is the other way round for some odd reason, i would only think this would happen if you had just exclude routes in your settings.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 14:24:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/366763#M644</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-02T14:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do tha</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/374582#M704</link>
      <description>&lt;P&gt;We have done this but still the 0.0.0.0/0 is still there in the route print&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 20:52:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/374582#M704</guid>
      <dc:creator>axelrafaeltadoy</dc:creator>
      <dc:date>2020-12-15T20:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do tha</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/374660#M708</link>
      <description>&lt;P&gt;I have to agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;the 0.0.0.0/0 route will still be in the routing table but the host will see this as a backup route, the 0.0.0.0/0 route that is via your home network gateway will be used as its metric is takes precedence over the one through the Global protect tunnel, if you were, for instance, to configure the Global Protect to tunnel all traffic then the metrics would be the other way around.&lt;/P&gt;&lt;P&gt;As it is your include routes are tunnelled and the host will only use the GP default route should the 192 gateway become unavailable, however that would also cut off your connectivity so you would have bigger issues!&lt;/P&gt;&lt;P&gt;My logic behind excluding the 0.0.0.0/0 route was simply that by actively excluding it, it may not find it's way into the routing table at all.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 08:54:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/374660#M708</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2020-12-16T08:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do that</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/553294#M4274</link>
      <description>&lt;P&gt;was there a solution to this problem?&amp;nbsp; apparently, I have run into the same problem where GP installs a default route albeit with a higher metric in the route table. What's weird is this behavior is seen on Windows and a Mac system but not on an Ubuntu OS.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 15:47:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/553294#M4274</guid>
      <dc:creator>szaidi110</dc:creator>
      <dc:date>2023-08-10T15:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do that</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/553918#M4288</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280770"&gt;@szaidi110&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you tried excluding the route as mentioned in earlier replies ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please also clarify which GP version you're experiencing this with.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 07:34:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/553918#M4288</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-08-16T07:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do that</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/553971#M4289</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Excluding the route doesn't work. Evidently, if you have any values configured under the&amp;nbsp;&lt;EM&gt;domain and application o&lt;/EM&gt;ption (which we did), PAN GP &lt;STRONG&gt;will&lt;/STRONG&gt; install a default route for it even if you've excluded it from the&amp;nbsp;&lt;EM&gt;access routes.&amp;nbsp;&lt;/EM&gt;No other way around it.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2023 12:41:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/553971#M4289</guid>
      <dc:creator>szaidi110</dc:creator>
      <dc:date>2023-08-16T12:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do that</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/1232193#M6858</link>
      <description>&lt;P&gt;Is there any way to avoid/deleted default route when you add any domain in split tunneling?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 07:18:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/1232193#M6858</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2025-06-20T07:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Globalprotect end users are receiving default route (0.0.0.0) but it is not configured to do that</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/1233547#M6887</link>
      <description>&lt;P&gt;I worked around it by adding:&lt;/P&gt;
&lt;P&gt;0.0.0.0/1&lt;/P&gt;
&lt;P&gt;128.0.0.0/1&lt;/P&gt;
&lt;P&gt;as exclude routes.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jul 2025 13:02:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-end-users-are-receiving-default-route-0-0-0-0-but/m-p/1233547#M6887</guid>
      <dc:creator>PDossett</dc:creator>
      <dc:date>2025-07-08T13:02:37Z</dc:date>
    </item>
  </channel>
</rss>

