<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rewrite Exclude domain list in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/rewrite-exclude-domain-list/m-p/1219840#M1079</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1155637765"&gt;@FarrasErdiansyah&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P data-unlink="true"&gt;Hi, Tried to rewrite internal domain on clientless vpn prisma SASE, but i cant access it. if didnt rewrite the domain i can access it through clientless vpn. for example i have domain&amp;nbsp;https://trulymagical.com/https/halo.deer.com&amp;nbsp;&amp;nbsp; but i want to rewrite and exclude domain list to be&amp;nbsp;https://halo.deer.com&amp;nbsp;&amp;nbsp;&amp;nbsp;only without the gp portal name in front of it. but i got an error i cant access it anymore if i rewrite it. please help me if anyone knows.&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1155637765"&gt;@FarrasErdiansyah&lt;/a&gt;&amp;nbsp;, I understand you are trying to rewrite an Internal domain for your clientless VPN in Prisma Access SASE, I believe the warning message you are seeing is expected. Any domain you add to the "Rewrite Exclude Domain List" are excluded from rewrite rules and cannot be rewritten. And paths are not supported in domain names. You can check the step 6 of this documentation:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-globalprotect/configure-clientless-vpn-prisma-access" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-globalprotect/configure-clientless-vpn-prisma-access&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope that answers your questions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Vickynet.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 09 Feb 2025 01:27:16 GMT</pubDate>
    <dc:creator>Vickynet</dc:creator>
    <dc:date>2025-02-09T01:27:16Z</dc:date>
    <item>
      <title>Rewrite Exclude domain list</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/rewrite-exclude-domain-list/m-p/1219525#M1074</link>
      <description>&lt;P data-unlink="true"&gt;Hi, Tried to rewrite internal domain on clientless vpn prisma SASE, but i cant access it. if didnt rewrite the domain i can access it through clientless vpn. for example i have domain&amp;nbsp;https://trulymagical.com/https/halo.deer.com&amp;nbsp;&amp;nbsp; but i want to rewrite and exclude domain list to be&amp;nbsp;https://halo.deer.com&amp;nbsp;&amp;nbsp;&amp;nbsp;only without the gp portal name in front of it. but i got an error i cant access it anymore if i rewrite it. please help me if anyone knows.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2025 16:32:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/rewrite-exclude-domain-list/m-p/1219525#M1074</guid>
      <dc:creator>FarrasErdiansyah</dc:creator>
      <dc:date>2025-02-05T16:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Rewrite Exclude domain list</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/rewrite-exclude-domain-list/m-p/1219673#M1078</link>
      <description>&lt;P&gt;As your question is a little bit unclear and I admit that I don't completely understand it I can mention that you need to make certain that Prisma Access also is able to resolve your internal domain &lt;SPAN&gt;halo.deer.com&amp;nbsp;&lt;/SPAN&gt;as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-setup/dns-for-prisma-access" target="_blank" rel="noopener"&gt;DNS for Prisma Access&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Outside of that the article for clientless vpn on the NGFW is better&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-clientless-vpn/configure-clientless-vpn" target="_blank" rel="noopener"&gt;Configure Clientless VPN&lt;/A&gt;&amp;nbsp;than the one for Prisma Access&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-globalprotect/configure-clientless-vpn-prisma-access" target="_blank" rel="noopener"&gt;GlobalProtect — Clientless VPN&lt;/A&gt;&amp;nbsp;so better review it as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you could set your crypto settings to the lowest level as it could be that your origin web uses old TLS just to see if it works and then to harden it. Also use tcpdump on the origin server to see if Prisma access connects to it and if needed check the origin server logs as well.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Feb 2025 12:47:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/rewrite-exclude-domain-list/m-p/1219673#M1078</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2025-02-08T12:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Rewrite Exclude domain list</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/rewrite-exclude-domain-list/m-p/1219840#M1079</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1155637765"&gt;@FarrasErdiansyah&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P data-unlink="true"&gt;Hi, Tried to rewrite internal domain on clientless vpn prisma SASE, but i cant access it. if didnt rewrite the domain i can access it through clientless vpn. for example i have domain&amp;nbsp;https://trulymagical.com/https/halo.deer.com&amp;nbsp;&amp;nbsp; but i want to rewrite and exclude domain list to be&amp;nbsp;https://halo.deer.com&amp;nbsp;&amp;nbsp;&amp;nbsp;only without the gp portal name in front of it. but i got an error i cant access it anymore if i rewrite it. please help me if anyone knows.&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1155637765"&gt;@FarrasErdiansyah&lt;/a&gt;&amp;nbsp;, I understand you are trying to rewrite an Internal domain for your clientless VPN in Prisma Access SASE, I believe the warning message you are seeing is expected. Any domain you add to the "Rewrite Exclude Domain List" are excluded from rewrite rules and cannot be rewritten. And paths are not supported in domain names. You can check the step 6 of this documentation:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-globalprotect/configure-clientless-vpn-prisma-access" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/mobile-users-globalprotect/configure-clientless-vpn-prisma-access&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope that answers your questions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Vickynet.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2025 01:27:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/rewrite-exclude-domain-list/m-p/1219840#M1079</guid>
      <dc:creator>Vickynet</dc:creator>
      <dc:date>2025-02-09T01:27:16Z</dc:date>
    </item>
  </channel>
</rss>

