<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global protect domain based local breakout in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/199261#M59071</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have a question regarding Global protect and partial split tunnelling.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does GP have an option to only allow specific domains via local breakout, all other traffic should be forwarded into the tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm asking this question regarding 0365, all domains should pass our company security checks only O365 traffic should be allowed to use end-user local breakout. This to speed-up O365 connectivity.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Steven.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Feb 2018 10:06:19 GMT</pubDate>
    <dc:creator>Steven_Liefferinckx</dc:creator>
    <dc:date>2018-02-07T10:06:19Z</dc:date>
    <item>
      <title>Global protect domain based local breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/199261#M59071</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have a question regarding Global protect and partial split tunnelling.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does GP have an option to only allow specific domains via local breakout, all other traffic should be forwarded into the tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm asking this question regarding 0365, all domains should pass our company security checks only O365 traffic should be allowed to use end-user local breakout. This to speed-up O365 connectivity.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Steven.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 10:06:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/199261#M59071</guid>
      <dc:creator>Steven_Liefferinckx</dc:creator>
      <dc:date>2018-02-07T10:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect domain based local breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/199300#M59080</link>
      <description>&lt;P&gt;this would be easy if O365 had just one IP address...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you could add this to the exclude list of the split tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or ... perhaps there is a known list of IP's but I have only seen URL's for this, not IP's and they probably change on a daily basis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can only see the option to add IP's/IP subnets to the exclusion so I think not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 11:22:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/199300#M59080</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-02-07T11:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect domain based local breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/200546#M59316</link>
      <description>&lt;P&gt;The list with office 365 IP adresses is here (but ther are quite afew entries in that list):&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.content.office.net/en-us/static/O365IPAddresses.xml" target="_blank"&gt;https://support.content.office.net/en-us/static/O365IPAddresses.xml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With that you could exclude these IP addresses in your gateway config. Or if there are too many entries your next possibility is with a script that gets executed on the client when it is connected to globalprotect. This script then manipulates the local route table and adds entries for these o365 IP ranges that connections to them will be routed directly instead of into the tunnel.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 20:09:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/200546#M59316</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-14T20:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect domain based local breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/201065#M59450</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks fort his reply but not really manageable, we currently have +12K users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I guess these is almost no other option than enable split tunnelling, which I don’t like.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Steven.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 07:52:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/201065#M59450</guid>
      <dc:creator>Steven_Liefferinckx</dc:creator>
      <dc:date>2018-02-19T07:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect domain based local breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/201071#M59451</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66330"&gt;@Steven_Liefferinckx&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I assume the users computers are not managed by your company?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 08:17:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/201071#M59451</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-19T08:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect domain based local breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/201075#M59453</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are manaed by our company. Updating list is omsething we need to avoid.&lt;/P&gt;&lt;P&gt;Based on domain would be easier, it's not only for 0365 (just used as example). We would like to have similar setup for skype/teams and other known/trusted cloud applications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Steven.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 08:57:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/201075#M59453</guid>
      <dc:creator>Steven_Liefferinckx</dc:creator>
      <dc:date>2018-02-19T08:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect domain based local breakout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/201078#M59454</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66330"&gt;@Steven_Liefferinckx&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then it would be a one time setup task. A little help you can find here: &lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-clients/deploy-agent-settings-transparently/deploy-agent-settings-to-windows-clients/windows-os-batch-script-examples#id917d79e2-32af-456a-82bc-aecfa187fa11" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-clients/deploy-agent-settings-transparently/deploy-agent-settings-to-windows-clients/windows-os-batch-script-examples#id917d79e2-32af-456a-82bc-aecfa187fa11&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With this base configuration you could write a script that automatically pulls the IP addresslist from microsoft and then adds direct routes for all these IP addresses/ranges. I know it's not as easy as configuring domain based exceptions but there is at least a way to achieve what you are asking.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 09:10:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-domain-based-local-breakout/m-p/201078#M59454</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-19T09:10:57Z</dc:date>
    </item>
  </channel>
</rss>

