How to verify the information of Included/Excluded domains and Applications in the PANGPS log?
9246
Created On 08/31/22 16:34 PM - Last Modified 05/10/23 01:09 AM
Objective
To verify Included/Excluded domains and Applications in the PANGPS log for Domain and Application-based Split tunnel configuration.
Environment
- Palo Alto Firewall.
- Supported PAN-OS
- GlobalProtect (Gateway and App)
- Split Tunnel Based on the Domain and Application.
Procedure
The process is explained with an example configuration below.
GUI: Network > Global Protect > Gateways> (gateway name) > Agent > Client Settings > Split Tunnel
Note: For information of the PanGPS log mentioned, refer to the Links in the additional Section.
- Upon a successful Gateway Login, GP Client sends "Get gateway config" getconfig.esp,POST REQUEST to the Gateway.
- The client receives the GATEWAY configuration.
- In Pangps logs , Excluded Domains from GP tunnel, "*.netflix.com,*.zoom.us, *.zoom.com, *.ringcentral.com, *.primevideo.com" are seen as Excluded from the tunnel:
<exclude-split-tunneling-domain>
<member>*.netflix.com</member>
<member>*.zoom.us</member>
<member>*.zoom.com</member>
<member>*.ringcentral.com</member>
<member>*.primevideo.com</member>
</exclude-split-tunneling-domain>
- Similarly the Included Domains through the GP tunnel, are seen under "include-split-tunneling-domain" as shown.
<include-split-tunneling-domain>
<member>*.xyz.local</member>
</include-split-tunneling-domain>
- Excluded applications from the tunnel are seen under <exclude-split-tunneling-application>, Zoom application is Excluded in the below example:
<exclude-split-tunneling-application>
<member>%AppData%\Roaming\Zoom\bin\Zoom.exe</member>
<member>/Applications/zoom.us.app/Contents/MacOS/zoom.us</member>
<member>C:\Program Files (x86)\Zoom\bin\Zoom.exe</member>
</exclude-split-tunneling-application>
- The Log also provides the number of Included/Excluded Doamins and Applications:
"(P5864-T6980)Debug( 772): 08/02/22 20:03:01:719 Split tunneling is enabled: 0 include app, 3 exclude app, 1 include domain, 5 exclude domain, video-redirect yes"