Can we use ping to test domain split tunneling in Globalprotect?

Can we use ping to test domain split tunneling in Globalprotect?

9049
Created On 01/29/20 00:27 AM - Last Modified 06/30/20 21:23 PM


Question
Can we use ping to test domain split tunneling in Globalprotect?

Environment
  • PAN-OS 8.1 and above.
  • Palo Alto Firewall.
  • Global Protect configured with split tunnel.


Answer
Ping Cannot be used to Domain Split Tunnel, The Split Tunnel DNS does not take effect on ICMP protocol and works only with TCP and UDP connections. Ping uses ICMP and so it does not work.
One needs to test using actual traffic/domain in question.
 


Additional Information

Refer Optimized Split Tunneling for GlobalProtect for more information.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000PORd&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FkCSArticleDetail

Attachments
Choose Language