<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split tunnel is not working for Linux/IOS devices in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239756#M125308</link>
    <description>&lt;P&gt;&lt;SPAN&gt;GlobalProtect now extends&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref" title="" href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-gateways/split-tunnel-traffic-on-globalprotect-gateways/configure-a-split-tunnel-based-on-the-domain-and-application#id0687b049-6664-4054-96dc-ba880f8c92c9" target="_blank" rel="noopener" data-scope="external" data-format="html" data-type=""&gt;Split DNS&lt;/A&gt;&lt;SPAN&gt;-Include functionality to iOS platforms in addition to Linux, Windows, and macOS.&lt;BR /&gt;&lt;BR /&gt;Split-DNS -Exclude functionality is not supported on iOS platforms.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-gateways/split-tunnel-traffic-on-globalprotect-gateways/configure-split-dns-for-globalprotect-app-on-ios-endpoints#:~:text=GlobalProtect%20now%20extends%20Split%20DNS%20-Include%20functionality%20to,-Exclude%20functionality%20is%20not%20supported%20on%20iOS%20platforms." target="_blank"&gt;Configure Split DNS for GlobalProtect App on iOS Endpoints&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Oct 2025 10:09:56 GMT</pubDate>
    <dc:creator>D.Shanmugam906589</dc:creator>
    <dc:date>2025-10-09T10:09:56Z</dc:date>
    <item>
      <title>Split tunnel is not working for Linux/IOS devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239521#M125288</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a VPN-SSL GP in a FW PA. I have some "Acess routes" in include for LAN ranges (10.0.0.0/8 and 192.168.x.x) and the rest should go through ISP local user.&lt;/P&gt;
&lt;P&gt;The issue is that&amp;nbsp;I'm seeing traffic destined for the internet that shouldn't be reaching the FW via the VPN.&lt;/P&gt;
&lt;P&gt;Goiing to agent logs i can see all routes in Linux client as OK. Default route is its ISP.&lt;/P&gt;
&lt;P&gt;Is there any limitation in GP default route for non Windows device?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 09:10:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239521#M125288</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2025-10-07T09:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel is not working for Linux/IOS devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239550#M125289</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="146" data-end="367"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="172" data-end="429"&gt;Which GlobalProtect client version are you running? There have been documented issues in older GP client versions where split tunneling didn’t function as expected, causing some internet-bound traffic to route through the VPN despite proper configuration.&lt;/P&gt;
&lt;P data-start="172" data-end="429"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="431" data-end="534"&gt;I’d recommend updating to a more recent &lt;STRONG data-start="471" data-end="502"&gt;preferred GP client version&lt;/STRONG&gt; and testing again from there.&lt;/P&gt;
&lt;P data-start="431" data-end="534"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="536" data-end="852"&gt;Also, do you happen to connect to multiple different portals? I’ve seen cases where the issue ended up being agent-related. I had to connect to a completely different portal/gateway, disconnect, and then reconnect to the correct one. Spent an hour digging through configs before realizing that was the culprit. I was supporting multiple sensitive environments so upgrades with anything weren't supported as easily.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 13:57:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239550#M125289</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-10-07T13:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel is not working for Linux/IOS devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239659#M125295</link>
      <description>&lt;P&gt;GP client version is 6.2.8. I think that coud be a limitation in non-windows devices to add the default route or something like this.&lt;/P&gt;
&lt;P&gt;The users only use one portal.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 09:46:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239659#M125295</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2025-10-08T09:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel is not working for Linux/IOS devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239718#M125302</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Did you follow the recommendation that&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;gave you in your &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/linux-iphone-devices-not-working-splitunneling/m-p/1238917#M125236" target="_self"&gt;last post&lt;/A&gt;&amp;nbsp;regarding this? Anything that isn't macOS or Windows handles this differently and implementing split DNS is going to actually allow this to function properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 00:58:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239718#M125302</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-10-09T00:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel is not working for Linux/IOS devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239742#M125306</link>
      <description>&lt;P&gt;But my issue is related to browser traffic http/https to INTERNET. DNS for GP users is internal DNS customer, but then the request to web server should take ISP local I dont understand why split DNS applies to me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 07:24:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239742#M125306</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2025-10-09T07:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel is not working for Linux/IOS devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239756#M125308</link>
      <description>&lt;P&gt;&lt;SPAN&gt;GlobalProtect now extends&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref" title="" href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-gateways/split-tunnel-traffic-on-globalprotect-gateways/configure-a-split-tunnel-based-on-the-domain-and-application#id0687b049-6664-4054-96dc-ba880f8c92c9" target="_blank" rel="noopener" data-scope="external" data-format="html" data-type=""&gt;Split DNS&lt;/A&gt;&lt;SPAN&gt;-Include functionality to iOS platforms in addition to Linux, Windows, and macOS.&lt;BR /&gt;&lt;BR /&gt;Split-DNS -Exclude functionality is not supported on iOS platforms.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-gateways/split-tunnel-traffic-on-globalprotect-gateways/configure-split-dns-for-globalprotect-app-on-ios-endpoints#:~:text=GlobalProtect%20now%20extends%20Split%20DNS%20-Include%20functionality%20to,-Exclude%20functionality%20is%20not%20supported%20on%20iOS%20platforms." target="_blank"&gt;Configure Split DNS for GlobalProtect App on iOS Endpoints&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 10:09:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239756#M125308</guid>
      <dc:creator>D.Shanmugam906589</dc:creator>
      <dc:date>2025-10-09T10:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel is not working for Linux/IOS devices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239780#M125311</link>
      <description>&lt;P&gt;Sorry but i dont understand that config. This issue is happening in IOS and LINUX (UBUNTU). Not only IoS.&lt;/P&gt;
&lt;P&gt;We dont have any domain and application in the tunnel. Just&amp;nbsp; some internal access routes include for LAN CUSTOMER RANGES. All the rest should go by local user ISP.&lt;/P&gt;
&lt;P&gt;DNS in GP config are the internal but when the domain is solved, the HTTP/HTTPS sessions shoud take ISP not GP. Thats the point. Why this is not working.&lt;/P&gt;
&lt;P&gt;route 0.0.0.0/0 by local ISP in GP is installed, i can see in GPagent logs. But INTERNET traffic is still going to GP&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 13:12:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-is-not-working-for-linux-ios-devices/m-p/1239780#M125311</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2025-10-09T13:12:37Z</dc:date>
    </item>
  </channel>
</rss>

