<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exclude only communications on specific port numbers from Global Protect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1240141#M125352</link>
    <description>&lt;P&gt;The path to split tunneling is in the gateway configuration:&lt;/P&gt;
&lt;P&gt;Network &amp;gt; Globalprotect &amp;gt; Gateways &amp;gt; &amp;lt;yourgateway&amp;gt; &amp;gt; Agent &amp;gt; Client Settings&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In client settings you can configure the Config Selection Criteria so you apply this profile only to a user/group/all-users (as depicted in my previous screenshot)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the Split Tunnel config you can then (If you have the GlobalProtect or Prisma Access Agent license) set an exclusion for an FQDN with a specific port:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1760601121333.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69587iA4C0FEA327730874/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_0-1760601121333.png" alt="reaper_0-1760601121333.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Oct 2025 09:39:50 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2025-10-16T09:39:50Z</dc:date>
    <item>
      <title>Exclude only communications on specific port numbers from Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1238153#M125158</link>
      <description>&lt;P&gt;Is there a way to exclude traffic on port 8080 from the VPN tunnel while connected to Global Protect?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to establish direct communication exclusively over port 8080, separate from VPN traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible? If so, please tell me how to set it up.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 02:35:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1238153#M125158</guid>
      <dc:creator>n-tomo</dc:creator>
      <dc:date>2025-09-17T02:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude only communications on specific port numbers from Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1238220#M125162</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regular split tunneling only allows you to add IP subnets, you can't exclude _all_ port 8080&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you have the GlobalProtect (now Prisma Access Agent) subscription license, you do have the option to add specific domains (FQDN) and add a port number&lt;/P&gt;
&lt;P&gt;alternatively if there's a specificvexecutable you want to exclude, you can add the path:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1758114541448.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69271i5BFDAFC89A593C4B/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_0-1758114541448.png" alt="reaper_0-1758114541448.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 13:10:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1238220#M125162</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-09-17T13:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude only communications on specific port numbers from Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1239234#M125258</link>
      <description>&lt;P&gt;Thanks for your reply!&lt;/P&gt;
&lt;P&gt;I've verified it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the screenshot you provided, is it possible to “set exclusion rules by specifying the sender (specific user)”?&lt;BR /&gt;I checked, but it doesn't seem possible to set exclusion rules by specifying the sender.&lt;/P&gt;
&lt;P&gt;Does this mean that only when you have a GlobalProtect subscription license can you register senders limited to specific users?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2025 01:06:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1239234#M125258</guid>
      <dc:creator>n-tomo</dc:creator>
      <dc:date>2025-10-02T01:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude only communications on specific port numbers from Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1239455#M125279</link>
      <description>&lt;P&gt;if you want more granular control, you should probably consider using security rules instead of split tunneling&lt;/P&gt;
&lt;P&gt;you mention exclusion rules per sender, which would be a security policy configuration (in security rules you can also specify source user)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can limit a profile to a specific user or group, but this is not very scalable&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1759750636270.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69453i81E935EA2A84ED35/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_0-1759750636270.png" alt="reaper_0-1759750636270.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2025 11:40:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1239455#M125279</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-10-06T11:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude only communications on specific port numbers from Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1240101#M125349</link>
      <description>&lt;P&gt;Dear &lt;A id="link_21" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608" target="_self" aria-label="View Profile of reaper"&gt;&lt;SPAN class="login-bold"&gt;reaper&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Regarding the configuration settings you provided,&lt;BR /&gt;I verified the “Config Selection Criteria” name in both the documentation and on the actual device.&lt;/P&gt;
&lt;P&gt;Network &amp;gt; GlobalProtect &amp;gt; Portals &amp;gt; [Portal Name]→&lt;BR /&gt;GlobalProtect Portal Configuration (portal-config) &amp;gt; Agent tab &amp;gt; [config]→&lt;BR /&gt;I confirmed the Config Selection Criteria.&lt;/P&gt;
&lt;P&gt;Reference Document:&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-app-configurations" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-app-configurations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I'm unsure if the configuration location is accurate. Is the above correct?&lt;BR /&gt;I would appreciate it if you could provide a link to the documentation.&lt;/P&gt;
&lt;P&gt;【Question 2】&lt;BR /&gt;I am unclear about the configuration location for security rules and the statement “For sender-specific exclusion rules, configure the security policy.”&lt;/P&gt;
&lt;P&gt;Regarding the question: “Is it possible to configure Global Protect so that only traffic for specific protocols like 8080 bypasses the Global Protect connection?” and “Can this be set for specific users?”, is this referring to an implementable method?&lt;/P&gt;
&lt;P&gt;Since it mentions “security policy,” I'm unsure if this meets the requirement to bypass the VPN tunnel for specific users or specific protocols.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 23:39:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1240101#M125349</guid>
      <dc:creator>n-tomo</dc:creator>
      <dc:date>2025-10-15T23:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude only communications on specific port numbers from Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1240141#M125352</link>
      <description>&lt;P&gt;The path to split tunneling is in the gateway configuration:&lt;/P&gt;
&lt;P&gt;Network &amp;gt; Globalprotect &amp;gt; Gateways &amp;gt; &amp;lt;yourgateway&amp;gt; &amp;gt; Agent &amp;gt; Client Settings&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In client settings you can configure the Config Selection Criteria so you apply this profile only to a user/group/all-users (as depicted in my previous screenshot)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the Split Tunnel config you can then (If you have the GlobalProtect or Prisma Access Agent license) set an exclusion for an FQDN with a specific port:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1760601121333.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69587iA4C0FEA327730874/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_0-1760601121333.png" alt="reaper_0-1760601121333.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 09:39:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/exclude-only-communications-on-specific-port-numbers-from-global/m-p/1240141#M125352</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-10-16T09:39:50Z</dc:date>
    </item>
  </channel>
</rss>

