Adding Address object to GlobalProtect split tunnel access route list

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Adding Address object to GlobalProtect split tunnel access route list

L2 Linker

Hi.  In the Palo Alto firewall, I've created a new Address object with the type set to FQDN and with a valid DNS record.   Saved and committed the change.  Then I try to add this newly created address object to the access route list in the GlobalProtect's split tunnel list (we using split tunnel for the VPN connection).  However, I am not seeing the new address object that I've created showing in the access route list.  It looks the address object with the type set to FQDN do not supported as an entry in the access route.  Can someone please confirm if this is true?  

Thank you.

1 accepted solution

Accepted Solutions

L7 Applicator

Hi @UXPSystems

 

No, what you are trying to configure is not possible. With PAN-OS 8.1 and GlobalProtect 4.1 you will have a lot more options about split tunneling but still not exactly this what you are asking in this topic.

More informations about the new features you cand find here: https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-f...

 

Edit: @BPry and once again I was a few seconds too late

View solution in original post

6 REPLIES 6

Cyber Elite
Cyber Elite

@UXPSystems,

It actually let you include an FQDN object in the Access Route configuration.... It isn't supposed to even allow you to do that. FQDN address objects are not supported within the Access Route configuration within the Agent settings, not sure why it even let you include one. 

L7 Applicator

Hi @UXPSystems

 

No, what you are trying to configure is not possible. With PAN-OS 8.1 and GlobalProtect 4.1 you will have a lot more options about split tunneling but still not exactly this what you are asking in this topic.

More informations about the new features you cand find here: https://www.paloaltonetworks.com/documentation/41/globalprotect/globalprotect-app-new-features/new-f...

 

Edit: @BPry and once again I was a few seconds too late

Great.  Thank you all for the input.

It looks like PANOS 8.1 and GlobalProtect 4.1 might provide a solution for me. 

Basically I can set the whole SaaS domain to pass through the VPN tunnel; but is not do-able on my PA right now (PA software version is still at 7.1.x).

 

@UXPSystems,

Just as a friendly FYI PAN-OS 8.1 includes a lot of helpful features that people are looking for, but is not currently recommended for production deployments. Please don't install it on your production firewall and not expect to run into issues.....please! 

L7 Applicator

... and in case you haven't already a GlobalProtect subscription ... you will need one for this new split tunneling feature

@Remo,

See I always said that Palo didn't give GlobalProtect enough love, and that AnyConnect was superior in UI and featureset. Now that it's finally getting on par with other vendors they start hiding all the good stuff behind this subscription. It's like it costs money to make a good product or something 😉 

  • 1 accepted solution
  • 4596 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!