<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: split tunnel or tunnel all in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/325346#M82975</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;That is only used for site to site vpn tunnels. You will need a NAT policy for the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFbCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFbCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Wed, 29 Apr 2020 14:06:18 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2020-04-29T14:06:18Z</dc:date>
    <item>
      <title>split tunnel or tunnel all</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/324938#M82904</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Which one is best split tunnel or tunnel all , If tunnel all how to do in PA .&lt;/P&gt;&lt;P&gt;What are the pros and cons&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 18:36:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/324938#M82904</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2020-04-26T18:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: split tunnel or tunnel all</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/324957#M82910</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59972"&gt;@simsim&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This depends solely on your requirements and what you are looking to accomplish. One option is not necessarily "better" than the other if you aren't looking at the full picture. I'm going to assume that you are talking about GlobalProtect and not an IPSec tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;&lt;STRONG&gt;Full Tunnel&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The benefit of a full tunnel GlobalProtect configuration is that you can inspect all traffic from a connected endpoint, tied together with always-on and pre-logon and it's similar to having the device sitting in your office. All of the traffic will be inspected by the firewall and the endpoint is effectively never not connected to your network. This is actually how GlobalProtect configures by default, if you leave your 'Split Tunnel' configuration empty or include 0.0.0.0/0 in your include list it'll tunnel everything through GlobalProtect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp;&lt;STRONG&gt;Split Tunnel&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The benefit of split-tunnel is that you don't have to process all of the endpoints network traffic, which can save you bandwidth if you don't have a connection capable of processing all of the traffic. This is extremely common in a lot of businesses where you have a BYOD VPN tunnel to allow someone to, for example, remote onto their desktop at work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is actually a common practice that I use for customers who simply want a way for someone to RDP back to their desktop at work. The configuration will simply allow for RDP traffic back to the access VLANs and ensure that the connected desktop passes a number of HIP checks to ensure that the client itself is up-to-date and has a supported antivirus solution. In this type of setup, I don't want to process all of the endpoints traffic, just the RDP traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under the Split Tunnel configuration you simply need to include whatever subnets you need to traverse the VPN in the include list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What solution you pick is really going to depend on your requirements and the business and regulatory needs. Banks for example that I've worked with don't allow any non-issued device to connect to their VPN and all traffic is processed through the VPN tunnel. SMB customers might not have the bandwidth to support all of that traffic and just want to allow RDP traffic as I mentioned before while performing a few HIP checks. Completely dependent on what your needs are.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 03:19:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/324957#M82910</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-04-27T03:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: split tunnel or tunnel all</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/325212#M82959</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I say tunnel all. You have a fantastic security appliance, Palo Alto, why not use it to inspect all the traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just my thoughts.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 19:20:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/325212#M82959</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-04-28T19:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: split tunnel or tunnel all</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/325241#M82964</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;My concern is bandwidth&amp;nbsp; if it is full tunnel . and does it require NAT-T ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 10:34:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/325241#M82964</guid>
      <dc:creator>simsim</dc:creator>
      <dc:date>2020-04-29T10:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: split tunnel or tunnel all</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/325346#M82975</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;That is only used for site to site vpn tunnels. You will need a NAT policy for the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFbCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFbCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 14:06:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/325346#M82975</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-04-29T14:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: split tunnel or tunnel all</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/597562#M118854</link>
      <description>&lt;P&gt;My question if I may, split tunneling. I would like to place a policy/rule in order to route streaming to VPN Users own ISP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also agree overall its a great appliance, why not take advantage and we're not hurting most days for bandwidth.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 16:09:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/split-tunnel-or-tunnel-all/m-p/597562#M118854</guid>
      <dc:creator>J.Hansen688028</dc:creator>
      <dc:date>2024-09-11T16:09:22Z</dc:date>
    </item>
  </channel>
</rss>

