<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: traffic not following the route in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/traffic-not-following-the-route/m-p/389660#M995</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/156069"&gt;@Pawel_G&lt;/a&gt;&amp;nbsp;group mapping is not controlled through the User-ID agent, so losing connection can't impact group mapping&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83320"&gt;@JoergSchuetter&lt;/a&gt;&amp;nbsp;have you tried reinstalling+upgrading to 5.1.8 the GP agent on one of the affected devices? I've seen something similar both with a bug in the GP agent, and an install that somehow failed to properly bind the gp virtual interface&lt;/P&gt;</description>
    <pubDate>Mon, 08 Mar 2021 06:43:27 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2021-03-08T06:43:27Z</dc:date>
    <item>
      <title>traffic not following the route</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/traffic-not-following-the-route/m-p/389379#M989</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have set split tunnel for our Win10 clients, GP is version 5.1.6 and 5.2.5. PAN-OS is 9.1.7.&lt;/P&gt;&lt;P&gt;- default route to firewall&lt;/P&gt;&lt;P&gt;- bypass tunnel for some network ranges (e.g. MS-Teams)&lt;/P&gt;&lt;P&gt;- bypass tunnel for some URLs (e.g. MS-Teams)&lt;/P&gt;&lt;P&gt;- enable DNS-Split&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For a small fractions of the users I see the MS-Teams traffic sent back to the firewall (expected was it is bypassing the tunnel).&lt;/P&gt;&lt;P&gt;The routing table on the client looks correct. Based on the routes the traffic should never be sent via the tunnel.&lt;/P&gt;&lt;P&gt;We tried to remedy a potential issue with the network interface with "netsh int ip reset" as administrator, same result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea what could cause such a strange behavior?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 14:27:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/traffic-not-following-the-route/m-p/389379#M989</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2021-03-05T14:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not following the route</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/traffic-not-following-the-route/m-p/389442#M990</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would recommend to you to take logs from the Global Protect Client at the time when user is trying to connect to Teams.&lt;/P&gt;&lt;P&gt;I would also collect logs from FW from user IP to see what is destination of Teams Server that user is trying to connect. Microsoft is adding IP ranges all the time for different servers around the world. How many Agents Portals, Gateways did you create?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 16:57:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/traffic-not-following-the-route/m-p/389442#M990</guid>
      <dc:creator>Pawel_G</dc:creator>
      <dc:date>2021-03-05T16:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not following the route</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/traffic-not-following-the-route/m-p/389559#M993</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/156069"&gt;@Pawel_G&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately there is nothing in the logs which raises my attention.&lt;/P&gt;&lt;P&gt;The traffic seen on the firewal is sent to an IP address which is covered by split tunnel.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Mar 2021 19:21:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/traffic-not-following-the-route/m-p/389559#M993</guid>
      <dc:creator>JoergSchuetter</dc:creator>
      <dc:date>2021-03-06T19:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not following the route</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/traffic-not-following-the-route/m-p/389649#M994</link>
      <description>&lt;P&gt;Hello Joerg,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would also check your User ID Agent for logs. Sometimes when User ID loose connection to Agent, GP will not pickup Group that you specify.&lt;/P&gt;&lt;P&gt;Also I would&amp;nbsp; collect packet captures.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 04:59:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/traffic-not-following-the-route/m-p/389649#M994</guid>
      <dc:creator>Pawel_G</dc:creator>
      <dc:date>2021-03-08T04:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: traffic not following the route</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/traffic-not-following-the-route/m-p/389660#M995</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/156069"&gt;@Pawel_G&lt;/a&gt;&amp;nbsp;group mapping is not controlled through the User-ID agent, so losing connection can't impact group mapping&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83320"&gt;@JoergSchuetter&lt;/a&gt;&amp;nbsp;have you tried reinstalling+upgrading to 5.1.8 the GP agent on one of the affected devices? I've seen something similar both with a bug in the GP agent, and an install that somehow failed to properly bind the gp virtual interface&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 06:43:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/traffic-not-following-the-route/m-p/389660#M995</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-03-08T06:43:27Z</dc:date>
    </item>
  </channel>
</rss>

