How can I export the GlobalProtect gateway config split tunnel access routes, domains and applications?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How can I export the GlobalProtect gateway config split tunnel access routes, domains and applications?

L3 Networker

We are migrating all our VPN users to GlobalProtect and I want to export our split-tunnel access routes, domains and applications to compare them with our other VPN settings.


I could not find anything that describes how to do this from the CLI or the web interface.

Has anyone found a way to do this?

Thanks

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@PC-TomS,

I would just export your running-config and compare from there. Easiest way to locate them quickly in the XML is by searching for "

<split-tunneling>" which is going to take you directly to your remote-user-tunnel-configs where this is set.

View solution in original post

5 REPLIES 5

Cyber Elite
Cyber Elite

@PC-TomS,

I would just export your running-config and compare from there. Easiest way to locate them quickly in the XML is by searching for "

<split-tunneling>" which is going to take you directly to your remote-user-tunnel-configs where this is set.

Thanks, but there is no split-tunnel entry in the running-config.xml.
Tom

Cyber Elite
Cyber Elite

@PC-TomS,

So two things then:

  • Have you actively configured any split-tunneling at present in your gateway configurations? If you have and the configuration is actually active, it should show up in the running-config export from the firewall.
  • If you are managing this device via Panorama the running-config on the firewall itself will only show what is configured directly on the device, not what's being merged into the configuration from Panorama. You would need to fetch it from Panorama to have the complete configuration or gather a technical support file on the firewall and extracted the merged-config.xml from the TGZ from the local firewall.

 

You can get this via the CLI by running the following

# Multi-Vsys example #
show vsys <vsys> global-protect global-protect-gateway <gateway> remote-user-tunnel-configs

# Normal #
show global-protect global-protect-gateway <gateway> remote-user-tunnel-configs

Yes we have split tunneling enabled on both gateways and each have several configs.

I found information similar to what you posted by interpolating some tech docs about configuring GP split tunnel via the CLI.


That said, I got an error using the 2nd command until I added name in front of <gateway>.

 show global-protect-gateway gateway name <gateway>

 

The output shows our access routes, but not the domains.

I also got an error when I put remote-user-tunnel-configs at the end.

 

You still get the win lol
Thanks
Tom

It was in the Panorama running-config.xml file.  I was looking at the export from the firewall.  

 

You were correct in your first post.  Thanks again.

 

Tom

  • 1 accepted solution
  • 1389 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!