<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect and split-tunnel, strange behavior from Facetime in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49590#M36545</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't have access to the device for the moment, but the Access route is to one internal network only, like:&amp;nbsp; 192.168.100.0/24&lt;/P&gt;&lt;P&gt;We see two specific oddities, where one might be by design:&lt;/P&gt;&lt;P&gt;-If primary and secondary DNS for GP clients is set to i.e. 8.8.8.8 and 4.4.4.4, DNS traffic is still sent over the tunnel&lt;/P&gt;&lt;P&gt;-We see Facetime traffic from iPhone over the tunnel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Nov 2014 12:20:36 GMT</pubDate>
    <dc:creator>arnljot</dc:creator>
    <dc:date>2014-11-11T12:20:36Z</dc:date>
    <item>
      <title>Global Protect and split-tunnel, strange behavior from Facetime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49586#M36541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have set up Global Protect with split-tunnel for mobile clients (iPhone, Android).&amp;nbsp; The goal is that ActiveSync is using the tunnel to reach internal servers, and all other traffic can go directly to the internet.&amp;nbsp; GP is set up to distribute routes to two internal networks to the clients through the Access Route parameter in Gateway configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One strange thing we observe, is that Facetime is sending traffic destined for some Apple servers over the VPN tunnel despite the fact that the routing table says otherwise.&amp;nbsp; We can observe the Facetime traffic in traffic monitor on the gateway.&lt;/P&gt;&lt;P&gt;Has anyone else observed this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An other observation:&amp;nbsp; Even when we specify Google DNS servers in the GP client settings, all DNS requests seem to go over the tunnel.&amp;nbsp; It seems thatl GP always send DNS requests over the VPN tunnel, regardless of the routing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2014 09:58:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49586#M36541</guid>
      <dc:creator>arnljot</dc:creator>
      <dc:date>2014-11-06T09:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and split-tunnel, strange behavior from Facetime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49587#M36542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ArnliJot,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Split tunnelling is not supported with built-in IOS IPsec VPN software. However its supported with Global Protect client. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please confirm which kind of VPN client are you using? Refer bellow article for more information.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/41951"&gt;Re: Split tunneling on iOS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2014 14:12:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49587#M36542</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-11-06T14:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and split-tunnel, strange behavior from Facetime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49588#M36543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its the Global Protect client for IOS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Nov 2014 08:08:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49588#M36543</guid>
      <dc:creator>arnljot</dc:creator>
      <dc:date>2014-11-07T08:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and split-tunnel, strange behavior from Facetime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49589#M36544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amljot,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Global Protect Client split tunnelling should work. Could you please share snapshot for access route of Global Protect Configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Nov 2014 17:21:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49589#M36544</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-11-07T17:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and split-tunnel, strange behavior from Facetime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49590#M36545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't have access to the device for the moment, but the Access route is to one internal network only, like:&amp;nbsp; 192.168.100.0/24&lt;/P&gt;&lt;P&gt;We see two specific oddities, where one might be by design:&lt;/P&gt;&lt;P&gt;-If primary and secondary DNS for GP clients is set to i.e. 8.8.8.8 and 4.4.4.4, DNS traffic is still sent over the tunnel&lt;/P&gt;&lt;P&gt;-We see Facetime traffic from iPhone over the tunnel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Nov 2014 12:20:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49590#M36545</guid>
      <dc:creator>arnljot</dc:creator>
      <dc:date>2014-11-11T12:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and split-tunnel, strange behavior from Facetime</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49591#M36546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arnljot,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case split tunneling should work. This appears to be a bug so far. But I dont have any configuration or logs to verify the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Nov 2014 13:08:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-split-tunnel-strange-behavior-from-facetime/m-p/49591#M36546</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-11-11T13:08:37Z</dc:date>
    </item>
  </channel>
</rss>

