<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do I have a split - full tunnel issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8223#M6071</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apologies for the delay - I'm a one-man IT department right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access Routes: 209.49.29.29/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="access_route_sep_17.tiff" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15611_access_route_sep_17.tiff" style="max-width: 620px; height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Sep 2014 18:19:17 GMT</pubDate>
    <dc:creator>bdunbar</dc:creator>
    <dc:date>2014-09-17T18:19:17Z</dc:date>
    <item>
      <title>Do I have a split - full tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8219#M6067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm a system admin, and have also become the Network guy.&amp;nbsp; This is okay: it's a small network.&amp;nbsp; I'm still learning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I have a PA-200, installed by a VAR, in a colocation rack.&amp;nbsp; Rack is filled with windows and linux hosts.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I need to alter the VPN so that when my users in the office connect from their laptops, they can see the systems (ssh, rdp, https) in the rack, while at the same time being able to connect to the office printer, the internet, and so on.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks in Advance,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Brian&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 21:33:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8219#M6067</guid>
      <dc:creator>bdunbar</dc:creator>
      <dc:date>2014-08-26T21:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: Do I have a split - full tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8220#M6068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Brian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please check the access route configuration in your GP gateway. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="access-route.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15127_access-route.jpg" style="height: 427px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Related discussion: &lt;A href="https://live.paloaltonetworks.com/message/32460"&gt;Re: Proper Way to allow Split-tunneling&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 22:08:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8220#M6068</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-26T22:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Do I have a split - full tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8221#M6069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The easy way is use a full tunnel (access route 0.0.0.0/0) and control the access to the host and internet using security policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example&lt;/P&gt;&lt;P&gt;From: specific_users to: DMZ Hosts_needed -&amp;gt; accept&lt;/P&gt;&lt;P&gt;From: All users to: Untrust ANY -&amp;gt; accept.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you need both, you can follow the next guide.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5986"&gt;Using Global Protect with One gateway and both split - full tunnel&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Sep 2014 22:33:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8221#M6069</guid>
      <dc:creator>GLastra</dc:creator>
      <dc:date>2014-09-08T22:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Do I have a split - full tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8222#M6070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check if there are networks defined in access list. If yes, then you need to include the servers, printers ips there.&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;Important -&amp;nbsp; you also need security policy to allow the traffic.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g VPN zone to Trust allow access to &amp;lt;server ip&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2014 00:17:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8222#M6070</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2014-09-09T00:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: Do I have a split - full tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8223#M6071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apologies for the delay - I'm a one-man IT department right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access Routes: 209.49.29.29/32&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="access_route_sep_17.tiff" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15611_access_route_sep_17.tiff" style="max-width: 620px; height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2014 18:19:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8223#M6071</guid>
      <dc:creator>bdunbar</dc:creator>
      <dc:date>2014-09-17T18:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Do I have a split - full tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8224#M6072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bdunbar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If access route is &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;209.49.29.29/32, than GP client will not be able to access anything other than &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;209.49.29.29/32.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2014 19:39:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8224#M6072</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-17T19:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Do I have a split - full tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8225#M6073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Removed that value - and we're good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe, now, that when the client PC logs into the VPN _all_ it's traffic is going to the colocation rack and using their internet.&amp;nbsp; So I still need to set up the split tunnel per the above link.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And next up: the powers that be want to expand our use of the apps and services on the servers in that rack, so 'a client per machine' is now a legacy solution and I need to think about a dedicated VPN tunnel.&amp;nbsp; Joy!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I feel a lot better about this: thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2014 20:02:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8225#M6073</guid>
      <dc:creator>bdunbar</dc:creator>
      <dc:date>2014-09-17T20:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: Do I have a split - full tunnel issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8226#M6074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bdunbar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure all Networks used in COLO in "Access Route". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So Internet traffic will flow through clients Internet circuit. and corporate traffic will flow through VPN tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Sep 2014 20:09:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/do-i-have-a-split-full-tunnel-issue/m-p/8226#M6074</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-09-17T20:09:50Z</dc:date>
    </item>
  </channel>
</rss>

