Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Split Tunnel by Domain Name is not working

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Split Tunnel by Domain Name is not working

L3 Networker

I've read a few posts on Split Tunnel by Domain Name. But so far I am only able to get 

specific routes to work and not split tunneling by domain name. My test is ipchicken.com

as traffic to it will reveal either my home IP as the source or the corporate public 

subnet. I added to INCLDE *.ipchicken.com without specifying ports. After establishing

the GP tunnel my browsing to ipchicken.com shows my home IP. I then tried also

adding ports 443 and 80 to see if that might make a difference. Nope. My system

is still showing my home IP address.  Any recommendation on how to get this working?

I figured to hit up the community before opening a case.

3 REPLIES 3

L4 Transporter

Hello @palomed 

Do you have a GlobalProtect license installed on your VPN gateway? The domain split feature requires that license to be installed.

L6 Presenter

As @JoergSchuetter  mentioned the first thing to check is the license and after that you may look also how you have configured your DNS traffic (the Split DNS feature):

 

How to configure Split DNS - Knowledge Base - Palo Alto Networks

 

 

If you have still issues check the PanGPS and PanGPA logs of the globalprotect agent and maybe known issues for your version and the addressed issues for the versions newer than yours:

 

GlobalProtect App 5.2 Known Issues (paloaltonetworks.com)

 

 

Addressed Issues in GlobalProtect App 5.2 (paloaltonetworks.com)

 

 

 

LIVEcommunity - Knowledge sharing: Globalprotect troubleshooting/investgation. Split tunnel,Globalpr...

L0 Member

I am running into the same problem. I am seeing dns and ssl going out of the machine outside of the tunnel but the ssl session never completes. So far known issues doesn't have anything I can tie to the issue. Really hoping not to have to open a TAC case....but its looking like it may need to happen. 

 

-jw

  • 5079 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!