<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect split tunnel setup in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/259799#M73636</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can use the userprofile environmental variable like so:&lt;/P&gt;&lt;P&gt;%userprofile%\AppData\Local\Microsoft\Teams\current\Teams.exe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing I can think with the exclusion is that you should add youtube-base and netflix-base and see if that works. I haven't tried including just the streaming app-ids to see how well that works.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 May 2019 18:52:46 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-05-03T18:52:46Z</dc:date>
    <item>
      <title>Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/259697#M73619</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have 8.1.5 on the pa and 4.1.11-9 client&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have setup the gateway for video traffic exclusion, and selected&amp;nbsp;&lt;/P&gt;
&lt;P&gt;youtube-streaming&lt;/P&gt;
&lt;P&gt;netflix-streaming&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But a simple test shows utube still come over the tunnel address&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to allow MS Teams to by pass the tunnel, so I goto agent / client setting select my config and split tunnel&amp;nbsp;&lt;/P&gt;
&lt;P&gt;domain and application&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but the app runs from&amp;nbsp;&lt;/P&gt;
&lt;P&gt;{userprofile}\AppData\Local\Microsoft\Teams\current\Teams.exe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how can i enter that into the config&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 14:13:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/259697#M73619</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-03-20T14:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/259799#M73636</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can use the userprofile environmental variable like so:&lt;/P&gt;&lt;P&gt;%userprofile%\AppData\Local\Microsoft\Teams\current\Teams.exe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing I can think with the exclusion is that you should add youtube-base and netflix-base and see if that works. I haven't tried including just the streaming app-ids to see how well that works.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 18:52:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/259799#M73636</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-05-03T18:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/259855#M73647</link>
      <description>&lt;P&gt;Cool, I will try that with teams. I presume it runs under the current user so the env variable will point to the right place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now - do I want to include - does that mean by pass the vpn or exclude ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yeah , not getting utube to work. watching now and its still in vpn&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I turn on video traffic exclude&lt;/P&gt;&lt;P&gt;and selected utube and netflix&lt;/P&gt;&lt;P&gt;but its not working&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2019 22:11:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/259855#M73647</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2019-05-03T22:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/261014#M73988</link>
      <description>&lt;P&gt;So i have found my answer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need a license for the video split tunnel .... sigh&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 23:55:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/261014#M73988</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2019-05-14T23:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/261020#M73989</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That you do; this is not included within the "base" functionality of GlobalProtect included with the device. If I would have to guess I would assume that the "free" version of GlobalProtect will essentially stay at where it is currently, and all the new exciting things will be included in the license.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 03:26:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/261020#M73989</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-05-15T03:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/261219#M74049</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;While I understand why you want to do a split tunnel, its not best practice and will fail most major compliance requirements.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 19:21:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/261219#M74049</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-05-15T19:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/261286#M74076</link>
      <description>&lt;P&gt;Yes understand but, we haved started to use MS teams video chat - and well hair pin turning a video stream 1/2 way around the world is a pain.&amp;nbsp; So we are looking at allowing just MS teams to have direct access out to just O365 ip's&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2019 00:58:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/261286#M74076</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2019-05-16T00:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/310051#M80313</link>
      <description>&lt;P&gt;Anyone else try this out?&lt;/P&gt;&lt;P&gt;From real-world testing I found it did work with exceptions by adding the path %userprofile\&lt;SPAN&gt;AppData\Local\Microsoft\Teams\current\Teams.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The exception being that the ability to join meetings is completely&amp;nbsp;broken. That traffic somehow ends up coming back across the tunnel while keeping the main teams application on the local network which causes the attempt to join to fail.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Upon investigation of the processes that are created while joining a meeting in Teams it seems Teams temporarily stages another Teams.exe at this location&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;%userprofile\AppData\Local\Microsoft\Teams\stage\Teams.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, adding this to the Split Tunnel config still did not work.&lt;BR /&gt;&lt;BR /&gt;Not sure what I am missing, but the fact that Palo Alto does not support the ability to Split Tunnel based on external IP blocks is ridiculous as this would have been much easier and working now.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 16:23:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/310051#M80313</guid>
      <dc:creator>CoreyKinder</dc:creator>
      <dc:date>2020-02-07T16:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/313370#M80927</link>
      <description>&lt;P&gt;&lt;SPAN&gt;%userprofile% not&amp;nbsp;%userprofile&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 19:36:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/313370#M80927</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2020-02-27T19:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/315975#M81323</link>
      <description>&lt;P&gt;I've added 52.112.0.0/14 to the split tunnel config because all teams traffic seems to go there.&lt;/P&gt;&lt;P&gt;This worked for a bit, but i still see traffic to this subnet comming trought the vpn altough traceroutes and manual request do go the correct way.&lt;/P&gt;&lt;P&gt;to counter this i've blocked this traffic on the palo so the client has to take the direct route via local internet, but this raises some strange issues for users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does ms teams override the routing table ? very strange.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 09:00:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/315975#M81323</guid>
      <dc:creator>wiresharky</dc:creator>
      <dc:date>2020-03-12T09:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/317184#M81533</link>
      <description>&lt;P&gt;Exclude by using the &amp;nbsp;"Access Route" Exclude list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use 13.107.64.0/18 and 52.112.0.0/14 as the excluded networks. There may be more but that's what I tested with and it works. The latest releases of supported PAN-OS do not appear to work with %userprofile% variables as an option in the path.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 01:34:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/317184#M81533</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2020-03-19T01:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/317216#M81543</link>
      <description>&lt;P&gt;thanks for replying&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did that (and added a few more over the last days).&lt;/P&gt;&lt;P&gt;so you didn't notice any traffic of those ranges still going through the vpn tunnel?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 05:52:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/317216#M81543</guid>
      <dc:creator>wiresharky</dc:creator>
      <dc:date>2020-03-19T05:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/317424#M81594</link>
      <description>&lt;P&gt;I don't believe I'm seeing anything there. With my testing anyway it showed correctly disappearing traffic while in a Teams meeting. I have not double checked later on yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created a list for Zoom and that works well also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm struggling with anything EXE based but it might be due to the multiple possible folders Outlook might be installed into based on 32bit vs. 64bit O365 vs stand alone install. I did successfully split MS AppStore as a test and that worked flawlessly all the time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Palo needs to support %userprofile% and %appdata% in the config!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 16:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/317424#M81594</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2020-03-19T16:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/317640#M81640</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98821"&gt;@CoreyKinder&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have observed the same behavior as the one you described.&lt;/P&gt;&lt;P&gt;We are running v9.0.4 on the Gateway and 5.0.7-2 on the GP Clients.&lt;/P&gt;&lt;P&gt;We configured split tunneling for the process&amp;nbsp;&lt;SPAN&gt;%userprofile\&lt;/SPAN&gt;&lt;SPAN&gt;AppData\Local\Microsoft\Teams\current\Teams.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Works pretty well but in some cases, joining a Teams Meeting online is not working. Several users reported this issue, while I personally never faced it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My first analysis shows that traffic to the following FQDN is always going through the Tunnel and will not break out locally: api.flightproxy.teams.microsoft.com&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Unfortunately this FQDN returns random IP addresses from different subnets.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am also not sure whether or not this is the cause of the issue. I tried collecting GlobalProtect debug logs, MS Teams debug logs, but did not find anything so far&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did anyone manage to make this work?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 10:00:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/317640#M81640</guid>
      <dc:creator>yannogrodowicz</dc:creator>
      <dc:date>2020-03-20T10:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/317644#M81641</link>
      <description>&lt;P&gt;I have gone the cheaper or route the license for GP is $$$ so i use split tunnel routes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/office365/enterprise/office-365-ip-web-service" target="_blank"&gt;https://docs.microsoft.com/en-us/office365/enterprise/office-365-ip-web-service&lt;/A&gt;&amp;nbsp;offical ip ranges used by MS for services - pick the skype ones it covers MS teams from my under standing&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i run this script to produce something I can cut and paste into panorama&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#!/bin/bash&lt;/P&gt;&lt;P&gt;#&lt;BR /&gt;# guid&lt;BR /&gt;# &lt;A href="https://www.guidgenerator.com/online-guid-generator.aspx" target="_blank"&gt;https://www.guidgenerator.com/online-guid-generator.aspx&lt;/A&gt;&lt;BR /&gt;#&lt;BR /&gt;guid=&amp;lt;generate one&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;tp="/tmp/$guid"&lt;/P&gt;&lt;P&gt;#&lt;BR /&gt;# &lt;A href="https://docs.microsoft.com/en-us/office365/enterprise/office-365-ip-web-service" target="_blank"&gt;https://docs.microsoft.com/en-us/office365/enterprise/office-365-ip-web-service&lt;/A&gt;&lt;BR /&gt;#&lt;/P&gt;&lt;P&gt;wget -O "$tp" -q '&lt;A href="https://live.paloaltonetworks.com/" target="_blank"&gt;https://endpoints.office.com/endpoints/WorldWide?ClientRequestId=&amp;lt;getyourown&amp;gt;&amp;amp;AllVersions=false&amp;amp;Format=CSV&amp;amp;NoIPv6=true&amp;amp;TenantName=yieldbroker&amp;amp;ServiceAreas=Skype&lt;/A&gt;'&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#&lt;BR /&gt;theips="prefix other ips"&lt;/P&gt;&lt;P&gt;for x in $( cat "$tp" | sed -e 's/^[^,]*,[^,]*,"[^"]*",//;s/"[^"]*",//;s/^,.*$//;/^id,.*$/d;/^$/d;s/^"\([^"]*\)".*$/\1/;s/,/ /g')&lt;BR /&gt;do&lt;BR /&gt;#echo $x&lt;BR /&gt;theips="$theips $x"&lt;BR /&gt;done&lt;/P&gt;&lt;P&gt;echo "# this is for the &amp;lt;agent name1&amp;gt; people on the gateway"&lt;BR /&gt;echo "set template Active_Passive config vsys vsys1 global-protect global-protect-gateway alcpa-vpn-gateway remote-user-tunnel-configs &amp;lt;agent name1&amp;gt; split-tunneling exclude-access-route [ $theips ]"&lt;/P&gt;&lt;P&gt;echo "# this is for the non singapore people on the gateway"&lt;BR /&gt;echo "set template Active_Passive config vsys vsys1 global-protect global-protect-gateway alcpa-vpn-gateway remote-user-tunnel-configs &amp;lt;agent name2&amp;gt; split-tunneling exclude-access-route [ $theips ]"&lt;/P&gt;&lt;P&gt;echo "# this is for all on the gateway"&lt;BR /&gt;echo "set template ybopa config vsys vsys1 global-protect global-protect-gateway ybopa-vpn-gateway-external remote-user-tunnel-configs &amp;lt;agent name3&amp;gt; split-tunneling exclude-access-route [ $theips ]"&lt;/P&gt;&lt;P&gt;echo&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 11:13:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/317644#M81641</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-03-20T11:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/318430#M81749</link>
      <description>&lt;P&gt;nice!&lt;/P&gt;&lt;P&gt;i have minemeld running and will use that as a source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do any of your users have issues with teams joining meetings or sharing their desktop?&lt;/P&gt;&lt;P&gt;I've got mixed results.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 07:03:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/318430#M81749</guid>
      <dc:creator>wiresharky</dc:creator>
      <dc:date>2020-03-25T07:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/319455#M81922</link>
      <description>&lt;P&gt;Seem like the nice people at PA have opened up trial license for 3-6 months for GP.&amp;nbsp; which will allow me to use all these nice features.&lt;BR /&gt;&lt;BR /&gt;So instead of having to do it by ip address I should be able to do it by app / process ..&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 00:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/319455#M81922</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-03-31T00:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/320460#M82073</link>
      <description>&lt;P&gt;Moved to trying&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;%userprofile%\&lt;/SPAN&gt;&lt;SPAN&gt;AppData\Local\Microsoft\Teams\current\Teams.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;turned it on and MS Teams stop working for some and still working for others &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 05:11:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/320460#M82073</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-04-03T05:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/321248#M82238</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I reading this right in that PanOS doesn't seem to support environment %Variables% in the path name of the executable you're trying to add to the "Include/Exclude Client Application Process Name" fields, be it with or without a GP license!? That's big oversight if that's the case. Has anyone got this confirmed by PA support?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If it makes a difference to the PanOS, we're at 8.1.x and have a GP license.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm basically also looking to add Teams and Zoom to the exclusion list by executable, but it's pretty pointless if neither will work? Or is Zoom working using the .exe path name in conjunction with the IP exclusions for it's IP blocks?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, are you guys seeing the new GP config changes apply after reconnecting / disconnecting and then reconnecting the GP client again? - I asked PA support when the GP configs get applied and they weren't sure, and advised me that's it's best to uninstall the GP client and clear a registry key and remove the GP services following a config change, and referred me to the following article:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJDCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClJDCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems rather drastic!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 15:34:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/321248#M82238</guid>
      <dc:creator>RLJFRY</dc:creator>
      <dc:date>2020-04-07T15:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect split tunnel setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/321338#M82252</link>
      <description>&lt;P&gt;&amp;nbsp;Wow support don't know !&lt;/P&gt;&lt;P&gt;I find it strange you have to remove the client.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i make changes to the split tunnel withe routes they seems to show up after a disconnect reconnect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if they don't support&amp;nbsp;&lt;SPAN&gt;%Variables%, then you can't really do teams can you ?&amp;nbsp; Wow&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 20:49:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-split-tunnel-setup/m-p/321338#M82252</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2020-04-07T20:49:20Z</dc:date>
    </item>
  </channel>
</rss>

