<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect include a specific URL? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-include-a-specific-url/m-p/211217#M61636</link>
    <description>&lt;P&gt;If you can get a list of the IPs used by Okta, you can set that up in PAN-OS 7.1.15 with your split tunnel mechanism. &lt;A href="https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/minemeld" target="_blank"&gt;Minemeld&lt;/A&gt; may have something for that as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that is not practical or even not possible at all, tunnel splitting by app is new in 8.1 and cannot be set in 8.0 and older.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Apr 2018 22:21:21 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2018-04-20T22:21:21Z</dc:date>
    <item>
      <title>Global Protect include a specific URL?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-include-a-specific-url/m-p/211185#M61627</link>
      <description>&lt;P&gt;Hey folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is a follow up question from one of my other posts.&amp;nbsp; We are using PAN-OS 7.1.15 and GP client 4.1.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/GlobalProtect-and-general-Internet-access/td-p/207888" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/GlobalProtect-and-general-Internet-access/td-p/207888&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are moving to Okta as our IDP for our applications.&amp;nbsp; When logging into Okta it recognizes your client public IP and we have policy based on that.&amp;nbsp; When we connect to Global Protect first and then log into Okta the traffic goes outside of our VPN tunnel (because we have internal network entries in the access routes - split tunneling).&amp;nbsp; I believe I understand that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need all Okta.com traffic to traverse through our VPN tunnel and use our specific static public IP (when connected to VPN).&lt;/P&gt;&lt;P&gt;It appears to me that this function is only available after upgrade to 8.1?&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/split-tunnel-for-public-applications" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/split-tunnel-for-public-applications&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could anyone agree or confirm?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 16:00:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-include-a-specific-url/m-p/211185#M61627</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2018-04-20T16:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect include a specific URL?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-include-a-specific-url/m-p/211217#M61636</link>
      <description>&lt;P&gt;If you can get a list of the IPs used by Okta, you can set that up in PAN-OS 7.1.15 with your split tunnel mechanism. &lt;A href="https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/minemeld" target="_blank"&gt;Minemeld&lt;/A&gt; may have something for that as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that is not practical or even not possible at all, tunnel splitting by app is new in 8.1 and cannot be set in 8.0 and older.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 22:21:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-include-a-specific-url/m-p/211217#M61636</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2018-04-20T22:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect include a specific URL?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-include-a-specific-url/m-p/211230#M61641</link>
      <description>&lt;P&gt;Okta IP adresses you can find here:&amp;nbsp;&lt;A href="https://support.okta.com/help/Documentation/Knowledge_Article/Configuring-Firewall-Whitelisting-89944588" target="_blank"&gt;https://support.okta.com/help/Documentation/Knowledge_Article/Configuring-Firewall-Whitelisting-89944588&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quite a few, but it could work to configure all of them as global protect routes&lt;/P&gt;</description>
      <pubDate>Sat, 21 Apr 2018 16:30:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-include-a-specific-url/m-p/211230#M61641</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-04-21T16:30:37Z</dc:date>
    </item>
  </channel>
</rss>

