Exclude only communications on specific port numbers from Global Protect

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Exclude only communications on specific port numbers from Global Protect

L2 Linker

Is there a way to exclude traffic on port 8080 from the VPN tunnel while connected to Global Protect?

 

I want to establish direct communication exclusively over port 8080, separate from VPN traffic.

 

Is it possible? If so, please tell me how to set it up.

5 REPLIES 5

Cyber Elite
Cyber Elite

Hi!

 

regular split tunneling only allows you to add IP subnets, you can't exclude _all_ port 8080

 

if you have the GlobalProtect (now Prisma Access Agent) subscription license, you do have the option to add specific domains (FQDN) and add a port number

alternatively if there's a specificvexecutable you want to exclude, you can add the path:

 

reaper_0-1758114541448.png

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Thanks for your reply!

I've verified it.

 

In the screenshot you provided, is it possible to “set exclusion rules by specifying the sender (specific user)”?
I checked, but it doesn't seem possible to set exclusion rules by specifying the sender.

Does this mean that only when you have a GlobalProtect subscription license can you register senders limited to specific users?

if you want more granular control, you should probably consider using security rules instead of split tunneling

you mention exclusion rules per sender, which would be a security policy configuration (in security rules you can also specify source user)

 

You can limit a profile to a specific user or group, but this is not very scalable

 

reaper_0-1759750636270.png

 

 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Dear

Regarding the configuration settings you provided,
I verified the “Config Selection Criteria” name in both the documentation and on the actual device.

Network > GlobalProtect > Portals > [Portal Name]→
GlobalProtect Portal Configuration (portal-config) > Agent tab > [config]→
I confirmed the Config Selection Criteria.

Reference Document:
https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-portals/defin...

I'm unsure if the configuration location is accurate. Is the above correct?
I would appreciate it if you could provide a link to the documentation.

【Question 2】
I am unclear about the configuration location for security rules and the statement “For sender-specific exclusion rules, configure the security policy.”

Regarding the question: “Is it possible to configure Global Protect so that only traffic for specific protocols like 8080 bypasses the Global Protect connection?” and “Can this be set for specific users?”, is this referring to an implementable method?

Since it mentions “security policy,” I'm unsure if this meets the requirement to bypass the VPN tunnel for specific users or specific protocols.




The path to split tunneling is in the gateway configuration:

Network > Globalprotect > Gateways > <yourgateway> > Agent > Client Settings

 

In client settings you can configure the Config Selection Criteria so you apply this profile only to a user/group/all-users (as depicted in my previous screenshot)

 

in the Split Tunnel config you can then (If you have the GlobalProtect or Prisma Access Agent license) set an exclusion for an FQDN with a specific port:

reaper_0-1760601121333.png

 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 954 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!