Route traffic to certain website(s) through site to site VPN without Route All Traffic VPN set.

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Route traffic to certain website(s) through site to site VPN without Route All Traffic VPN set.

L0 Member

In existing site to site vpn tunnel setup between Head Office and Remote Office, there would be requirement that traffic to certain website
from remote office need to be routed through head office Internet connection through the existing site to site vpn tunnel.
However the requirement would not be to configure the site to site vpn tunnel in Route All Traffic through the vpn tunnel.


Please help to me to achieve this . Quick help really appreciated . 





Cyber Elite
Cyber Elite

You can't route based on URL because routing decision needs to be done based on first packet but URL is 4th in best case (SYN, SYN ACK, ACK, HTTP GET).

You could set up Policy based forwarding using FQDN address object as destination to achieve this.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cyber Elite
Cyber Elite


Just as a disclaimer to @Raido_Rattameister's suggestion (which is the only way you'd get something like this to actually work), this could also capture way more traffic than what you actually want. I'd highly recommend checking what the FQDN objects would actually include before adopting this solution and deciding if that'll actually work for you in this case. It's possible depending on the site that you'll be including a fair bit more traffic than you actually intent to. 

  • 2 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!