Exclude all Zoom traffic from GlobalProtect VPN

Reply
Highlighted
L2 Linker
Highlighted
L4 Transporter

We added all ranges but we are still seeing sessions to these zoom ips reaching the Palo Alto. Did you do any more action?

Tags (1)
Highlighted
L1 Bithead

When we looked at the network ranges last week, we saw 75 of them (I know @HDC mentioned 85 to his count but we only saw 75). This week (5/18/20) there are 88 IP ranges. We had to add these to our list:

 

69.174.108.0/22

140.238.128.0/24

152.67.20.0/24

152.67.118.0/24

152.67.180.0/24

158.101.64.0/24

168.138.16.0/24

168.138.48.0/24

168.138.72.0/24

168.138.244.0/24

193.122.32.0/22

193.123.0.0/19

193.123.40.0/22

193.123.128.0/19

 

Check to make sure you aren't missing any.

 

 

Highlighted
L4 Transporter

We add all IPs in the excluded but if i go to monitor session i can see traffic to these IPs in PA.

Its like GPclient is not taking the routes added properly. 

Highlighted
L1 Bithead

It seems to be that there are new ranges coming on faster than they are updating the list of ranges.

Highlighted
L4 Transporter

we have the correct ranges but its like the clients are not splitting the traffic and this traffic is still going through the tunnel.

Is it needed to restart the agent or any action in GP to refresh?

Highlighted
L2 Linker

You need to do a GP connection refresh, and after connection is reestablished exit & access again Zoom, that should do it.

 

What version of GP are you using? My tests showed that begore GP v5.1.1 lots of things are not right with the split tunnel.

Highlighted
L4 Transporter

We configured the zoon split tunneling using domain and application but we see that sessions to zoom using port 8801. These 8801 sessions are going through the tunnel. Is there any way to split this traffic?

Highlighted
L4 Transporter

I have the same issue. Port 8801 is going through GP tunnel and some 443 zoom-base sessions.

 

How did you solve it? any idea?

Highlighted
L2 Linker

What GP version are you using? TO me, deploying GP v5.1.1 solved the issue.Before we were using v4.something.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!