01-25-2022 11:12 AM
I've read a few posts on Split Tunnel by Domain Name. But so far I am only able to get
specific routes to work and not split tunneling by domain name. My test is ipchicken.com
as traffic to it will reveal either my home IP as the source or the corporate public
subnet. I added to INCLDE *.ipchicken.com without specifying ports. After establishing
the GP tunnel my browsing to ipchicken.com shows my home IP. I then tried also
adding ports 443 and 80 to see if that might make a difference. Nope. My system
is still showing my home IP address. Any recommendation on how to get this working?
I figured to hit up the community before opening a case.
01-25-2022 11:55 AM
Do you have a GlobalProtect license installed on your VPN gateway? The domain split feature requires that license to be installed.
01-25-2022 01:10 PM
As @JoergSchuetter mentioned the first thing to check is the license and after that you may look also how you have configured your DNS traffic (the Split DNS feature):
How to configure Split DNS - Knowledge Base - Palo Alto Networks
If you have still issues check the PanGPS and PanGPA logs of the globalprotect agent and maybe known issues for your version and the addressed issues for the versions newer than yours:
GlobalProtect App 5.2 Known Issues (paloaltonetworks.com)
Addressed Issues in GlobalProtect App 5.2 (paloaltonetworks.com)
LIVEcommunity - Knowledge sharing: Globalprotect troubleshooting/investgation. Split tunnel,Globalpr...
02-09-2023 04:18 PM
I am running into the same problem. I am seeing dns and ssl going out of the machine outside of the tunnel but the ssl session never completes. So far known issues doesn't have anything I can tie to the issue. Really hoping not to have to open a TAC case....but its looking like it may need to happen.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!