How to verify the information of Included/Excluded domains and Applications in the PANGPS log?

How to verify the information of Included/Excluded domains and Applications in the PANGPS log?

9246
Created On 08/31/22 16:34 PM - Last Modified 05/10/23 01:09 AM


Objective


To verify Included/Excluded domains and Applications in the PANGPS log for Domain and Application-based Split tunnel configuration.

 


Environment


  • Palo Alto Firewall.
  • Supported PAN-OS
  • GlobalProtect (Gateway and App)
  • Split Tunnel Based on the Domain and Application.


Procedure


The process  is explained with an example configuration below. 
GUI: Network > Global Protect > Gateways> (gateway name) > Agent > Client Settings > Split Tunnel

Split Tunnel Configuration

Note: For information of the PanGPS log mentioned, refer to the Links in the additional Section.
 
  1. Upon a successful Gateway Login,  GP Client sends "Get gateway config" getconfig.esp,POST REQUEST to the Gateway.
  2. The client receives the GATEWAY configuration.
  3. In Pangps logs , Excluded Domains from GP tunnel, "*.netflix.com,*.zoom.us, *.zoom.com, *.ringcentral.com, *.primevideo.com"  are seen as Excluded from the tunnel:
<exclude-split-tunneling-domain>
   <member>*.netflix.com</member>
   <member>*.zoom.us</member>
   <member>*.zoom.com</member>
   <member>*.ringcentral.com</member>
   <member>*.primevideo.com</member>
</exclude-split-tunneling-domain> 
  1. Similarly the Included Domains through the GP tunnel, are seen under "include-split-tunneling-domain" as shown.
 <include-split-tunneling-domain>
        <member>*.xyz.local</member>
  </include-split-tunneling-domain> 
  1.  Excluded applications from the tunnel are seen under <exclude-split-tunneling-application>,  Zoom application is Excluded in the below example:​​​​​
<exclude-split-tunneling-application>
       <member>%AppData%\Roaming\Zoom\bin\Zoom.exe</member>
       <member>/Applications/zoom.us.app/Contents/MacOS/zoom.us</member>
       <member>C:\Program Files (x86)\Zoom\bin\Zoom.exe</member>
</exclude-split-tunneling-application> 
  1. The Log also provides  the number of Included/Excluded Doamins and Applications:
"(P5864-T6980)Debug( 772): 08/02/22 20:03:01:719 Split tunneling is enabled: 0 include app, 3 exclude app, 1 include domain, 5 exclude domain, video-redirect yes"


Additional Information




Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlSDCAY&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language