<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Route Precedence in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232971#M66818</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;How about something like in the article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/10/cloud-services/globalprotect-cloud-service-gsg/gpcs-quick-configs/remote-network-locations-with-overlapping-subnets" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/10/cloud-services/globalprotect-cloud-service-gsg/gpcs-quick-configs/remote-network-locations-with-overlapping-subnets&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 28 Sep 2018 14:27:52 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-09-28T14:27:52Z</dc:date>
    <item>
      <title>GlobalProtect Cloud Services Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232712#M66760</link>
      <description>&lt;P&gt;We have had overlapping subnet scenarios where someone is connecting using GlobalProtect Cloud Services from a subnet that overlaps our internal subnet and, as they have a more specific route, access to internal resources is failing as the taffic is being routed via the local router instead of over the VPN due to the more specific route. Due to the size of our internal network, adding more specific routes for all of our subnets isn't really an option and this could be undone anyway with a more specific route.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know a way to force all internal traffic down the VPN instead of following more specific routes?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;NOTE: GlobalProtect Cloud Service has changed to Prisma Access.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 02:47:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232712#M66760</guid>
      <dc:creator>LCMember2050</dc:creator>
      <dc:date>2019-07-11T02:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232719#M66761</link>
      <description>&lt;P&gt;Hmm.. no, but do they need local routing, seems a bit odd if your route takes precedence, or is it all the other routes that are local...&lt;/P&gt;&lt;P&gt;never had this issue as we do not allow split tunneling...&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 14:36:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232719#M66761</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-27T14:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232720#M66762</link>
      <description>&lt;P&gt;well i say "No" but watch this space...&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 14:37:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232720#M66762</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-27T14:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232910#M66809</link>
      <description>&lt;P&gt;We mostly see the issue when users are connecting from hotel networks so have no control on their routes. We can manually remove the local route to get the traffic down the tunnel but not the easiest solution for users.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 08:28:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232910#M66809</guid>
      <dc:creator>LCMember2050</dc:creator>
      <dc:date>2018-09-28T08:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232913#M66810</link>
      <description>&lt;P&gt;if you remove all routes from the gateway config on the palo alto it will auto force all traffic down the tunnel by default.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 08:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232913#M66810</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-28T08:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232938#M66813</link>
      <description>&lt;P&gt;Have removed all routes but traffic matching the local route still isn't going down the tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S. thanks for your helpful replies.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 12:03:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232938#M66813</guid>
      <dc:creator>LCMember2050</dc:creator>
      <dc:date>2018-09-28T12:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232941#M66814</link>
      <description>&lt;P&gt;It looks like we need to enable the option "No direct access to local network" to force all traffic down the tunnel but this would prevent access to local resources like printers. Guess thats a decision we'll have to make.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for your help Mick.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 12:28:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232941#M66814</guid>
      <dc:creator>LCMember2050</dc:creator>
      <dc:date>2018-09-28T12:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232971#M66818</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;How about something like in the article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/10/cloud-services/globalprotect-cloud-service-gsg/gpcs-quick-configs/remote-network-locations-with-overlapping-subnets" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/10/cloud-services/globalprotect-cloud-service-gsg/gpcs-quick-configs/remote-network-locations-with-overlapping-subnets&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 14:27:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/232971#M66818</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-28T14:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/233002#M66828</link>
      <description>&lt;P&gt;Sure, but the user could just disable GP to print, or use USB, you have a few options but if you deffo need access to both then specific host routes could be an option as you only need to set them once for all users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;luckily we have a strict no split tunnel policy so never been an issue and for a small group of users that must remote print they have a seperate portal config via AD group that allows GP disable.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 15:29:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/233002#M66828</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-28T15:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/233003#M66829</link>
      <description>&lt;P&gt;Sorry&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;, that was not a reply to you... i only just read your post. Is this doable on local kit or do you need to invest in cloud services.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 15:31:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/233003#M66829</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-09-28T15:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/233016#M66836</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The PAN's can do this nativly, I should have read more rather than pasting :). Check this out:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Help-with-IPSec-Proxy-IDs-with-overlapping-IPs/ta-p/69123" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/DotW-Help-with-IPSec-Proxy-IDs-with-overlapping-IPs/ta-p/69123&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this more closely resendble the scenario?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 16:20:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/233016#M66836</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-09-28T16:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Cloud Services Route Precedence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/510208#M106174</link>
      <description>&lt;P&gt;I think we have a fix for this issue of overlapping addresses for Mobile Users of Prisma Access.&amp;nbsp; We applied the traditional GlobalProtect approach by updating the split-tunnel settings to include both the internal network which should be routed over the tunnel and the 0.0.0.0/0.&amp;nbsp; By default (with no entries in this box), Prisma Access sends all traffic to the regional gateway.&amp;nbsp; With the overlapping issue, we need the client to ignore the local network routing.&amp;nbsp; The default route is needed in order to send client internet traffic to the regional gateway.&amp;nbsp; Without the default route, internet is offloaded at the local network POP rather than the regional Prisma Access gateway.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jasonrakers_0-1659034453315.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42682i0A14AEDA5BDBAC57/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jasonrakers_0-1659034453315.png" alt="jasonrakers_0-1659034453315.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 19:03:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-cloud-services-route-precedence/m-p/510208#M106174</guid>
      <dc:creator>jasonrakers</dc:creator>
      <dc:date>2022-07-28T19:03:12Z</dc:date>
    </item>
  </channel>
</rss>

