<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bypass video traffic exclusion in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-video-traffic-exclusion/m-p/341626#M85683</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try creating a application override policy where source as GP client ips destination as 10.0.0.0/8 subnets on required ports . So the firewall not process this traffic for app identification . Try and let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;</description>
    <pubDate>Fri, 31 Jul 2020 16:30:28 GMT</pubDate>
    <dc:creator>RamprakashRT</dc:creator>
    <dc:date>2020-07-31T16:30:28Z</dc:date>
    <item>
      <title>Bypass video traffic exclusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-video-traffic-exclusion/m-p/337674#M84989</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have GP set up and one of the settings include "Exclude video traffic from the tunnel". However, we have come across an issue that private site for developers hosted in 10.0.0.0/8 network includes internally hosted videos (http-video app-id) needed for work. So when user tries to connect to website while connected to GlobalProtect, it times out, because traffic is being pushed through physical network adapter rather than via virtual tunnel and well, 10/8 network isn't helping in this case.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is and I really couldn't find the answer anywhere, is there anything that takes precedence before the "Exclude video traffic from the tunnel" option gets evaluated?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One option would be to enable video traffic generally and exclude tens and hundreds of apps and domains that shouldn't be going via GP, but that is not very convenient/efficient. Is there a way how to include just one specific app-id or one specific IP/domain that would bypass this rule and go via GP even though video traffic is present?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In GP GW configuration - Agent - Video traffic, there is no way to include specifics, only to exclude all/specifics.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we tried to adjust client settings config in Split Tunnel options and included required network in Access Route under Include, it still did not work as if Video traffic setting was evaluated first and traffic has been pushed via physical link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 07:55:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-video-traffic-exclusion/m-p/337674#M84989</guid>
      <dc:creator>kalolu</dc:creator>
      <dc:date>2020-07-10T07:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Bypass video traffic exclusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bypass-video-traffic-exclusion/m-p/341626#M85683</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try creating a application override policy where source as GP client ips destination as 10.0.0.0/8 subnets on required ports . So the firewall not process this traffic for app identification . Try and let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 16:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bypass-video-traffic-exclusion/m-p/341626#M85683</guid>
      <dc:creator>RamprakashRT</dc:creator>
      <dc:date>2020-07-31T16:30:28Z</dc:date>
    </item>
  </channel>
</rss>

