<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prevent GlobalProtect default route overwriting local static routes? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182374#M56173</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73439"&gt;@StuartFordham&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll need to configure split tunnel (PAN-OS 8.0) :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/split-tunnel-to-exclude-by-access-route" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/split-tunnel-to-exclude-by-access-route&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In 7.1 it's in&amp;nbsp;a different location under Gateway configuration &amp;gt; Agent &amp;gt; Client Settings &amp;gt;Network Settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2017 15:41:08 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2017-10-17T15:41:08Z</dc:date>
    <item>
      <title>How to prevent GlobalProtect default route overwriting local static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182333#M56170</link>
      <description>&lt;P&gt;This is using PAN-OS 8 in AWS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a site which has multiple networks attached. Users from the "main" network (let's call it 1.1.1.0/24) can also access 1.1.2.0/24, 1.1.3.0/24 via the default route supplied by the DHCP server, which goes to our core switch. (before you ask, I cant just change the subnet masks as the real subnets are completely discontiguous).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the same site, we would use the GP VPN to connect to site B, and likewise, someone could connect to GP and get access to site A (in order to get to all of the networks) and site B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When connecting to the VPN from site A it seems silly to have GP send all of the traffic to 1.1.2.0/24 and 1.1.3.0/24 through itself, when that traffic should be routed internally to site A.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried adding static routes to our DHCP and could see that in my routing table, however, it got overwritten by the GP default route once I connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also tried to change the next-hop info for the particular routes in the virtual router - but still get local traffic heading all the way up to Amazon and back down again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone encountered such a situation, and any advice on how to fix it, so local traffic remains local?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 14:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182333#M56170</guid>
      <dc:creator>StuartFordham</dc:creator>
      <dc:date>2017-10-17T14:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent GlobalProtect default route overwriting local static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182374#M56173</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73439"&gt;@StuartFordham&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll need to configure split tunnel (PAN-OS 8.0) :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/split-tunnel-to-exclude-by-access-route" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/newfeaturesguide/globalprotect-features/split-tunnel-to-exclude-by-access-route&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In 7.1 it's in&amp;nbsp;a different location under Gateway configuration &amp;gt; Agent &amp;gt; Client Settings &amp;gt;Network Settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 15:41:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182374#M56173</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-10-17T15:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent GlobalProtect default route overwriting local static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182375#M56174</link>
      <description>&lt;P&gt;Thanks for the link. But&amp;nbsp;if this approach is taken, the remote access users that need access to those networks won't have access.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 15:44:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182375#M56174</guid>
      <dc:creator>StuartFordham</dc:creator>
      <dc:date>2017-10-17T15:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent GlobalProtect default route overwriting local static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182376#M56175</link>
      <description>&lt;P&gt;this sounds interesting but i dont get it...&amp;nbsp;&amp;nbsp; &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;suggestion seems good but are you saying that the 3 networks listed can be accessed both by local and GP.&amp;nbsp; i also dont understand your previous response regarding remote access users, are these the GP users? perhaps a doodle would suffice, are networks A and B within those given subnets?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 15:54:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182376#M56175</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-17T15:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent GlobalProtect default route overwriting local static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182486#M56202</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73439"&gt;@StuartFordham&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You could also configure separate gateways for VPN access and for access to your internal resources. With this configuration the agents will perform an internal host detection to determine if they are on the internal network or not and choose the gateway accordingly.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/60/globalprotect/global_protect_6-0/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/60/globalprotect/global_protect_6-0/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The above link is on PAN-OS 6.0 which is officially EoL but the general idea remains the same.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 07:39:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182486#M56202</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-10-18T07:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent GlobalProtect default route overwriting local static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182498#M56207</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the basic idea:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Basic PA layout - Page 1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11989iD26709722DAE761B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Basic PA layout - Page 1.png" alt="Basic PA layout - Page 1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;For the remote users, this will not be an issue, they will get the networks they need to access through the GlobalProtect gateway (Sites A, B, and C).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users in site A would not normally need to connect to GP, unless they need to access Site C.&amp;nbsp; All traffic would flow to the L3 switch and reach what it needs to reach. However, if they need to access Site C, when they connect to the GP VPN, all the traffic to 10.10.10.10 will go up to the Palo Alto GP, instead of directly to the switch.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because of various rules and regulations, we need to follow, split-tunnel is not an option. Also, the only PA gateway we have (at the moment) is in the Amazon cloud.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if there was a way to pick and choose the routes that the GP client overwrites, then this would fit the bill perfectly, however, this does not seem to be the case, or if there was some form of running a post-logon script, then this would also be a workable solution as we could try and inject the routes back in, dependent on location...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate that this may seem like an odd setup... and thank you for your help!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 09:16:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182498#M56207</guid>
      <dc:creator>StuartFordham</dc:creator>
      <dc:date>2017-10-18T09:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent GlobalProtect default route overwriting local static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182521#M56212</link>
      <description>&lt;P&gt;thanks for the info...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is Network "A" private.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 11:15:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182521#M56212</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-18T11:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent GlobalProtect default route overwriting local static routes?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182523#M56214</link>
      <description>&lt;P&gt;Hmmmm tricky...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you are going to struggle with any pre logon stuff, interject or not as the vpn tunnel will be between device and PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OK so no split network so &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;option 1 is out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure about option 2 as the internal gateway will still connect to PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you do have the option to just connect the client when needed, perhaps not practicle for your users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If site A is private then would you be allowed to split tunnel there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a possible solution would be to have 1 portal with 2 gateways.&lt;/P&gt;&lt;P&gt;gateway 1 is full on access to all networks for peeps at home etc. route =0.0.0.0&amp;nbsp; via tunnel&lt;/P&gt;&lt;P&gt;gateway 2 is split tunnel&amp;nbsp;for users at site A. route = site B &amp;amp; C via tunnel (so traffic for A stays local)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then... use "regions" to decide on GW auto selection. if user is connecting from region A (site A) then GW=2&lt;/P&gt;&lt;P&gt;all other connections then GW=1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;probably other combinations possible including satelite etc but for GP you is limited.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 11:50:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-prevent-globalprotect-default-route-overwriting-local/m-p/182523#M56214</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-18T11:50:59Z</dc:date>
    </item>
  </channel>
</rss>

