Split tunneling based on the domain is not working.

Reply
MickBall
L7 Applicator

@goran.katava  Yes that worked for me. Do you know the similar command for domain exclusion. Also when yo use the show gateway command it does not include domain exclusion.

 

thanks for your help.

goran.katava
L2 Linker

@MickBall 

 

You can use '?' in order to see available commands. When in set config mode try next :

 

set global-protect global-protect-gateway GATEWAY-NAME remote-user-tunnel-configs ?

 

Thus for domain exclusion it is:

 

set global-protect global-protect-gateway GATEWAY-NAME remote-user-tunnel-configs CONFIG-NAME split-tunneling exclude-domains list DOMAIN-ENTRY

MickBall
L7 Applicator

@goran.katava 

Thanks again for your help, I was not in the configure mode when using "?" so I could not find the commands.

 

 

dcaporetto
L1 Bithead

I have the same issue trying to split O365 traffic. I have two VM-300 in HA running 9.1.2 and any domain I put into the exclude list is ignored.  I have to use Access Route exclusions for it to work, which is cumbersome.

 

If I add b-0004.b-msedge.net, or *.b-msedge.net as a domain exclusion, my system will connect via the VPN tunnel. IfI add its IP (13.107.6.156) to the Access Route exclusion, it work.

 

How Can I fix this?

 

 

Tags (1)
goran.katava
L2 Linker

Hi, it should be working. You do need license for that.

 

 

 

dcaporetto
L1 Bithead

Yeah, I got the GP Gateway license, that's the strange thing. Might have to contact support.

vathreya
L3 Networker

@NavigantNetworkteam 

Please refer the following document for determining the precedence order while using split-tunnel rules.

 

https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-gateways/spli...

 

Regards,

Varun

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!