As remote workforce models mature, security engineers face a persistent challenge: balancing corporate network security with endpoint performance and WAN bandwidth consumption. When all remote user traffic is backhauled through a central firewall—a model known as full tunneling—high-bandwidth, non-sensitive cloud applications like video conferencing, streaming services, and software updates can rapidly exhaust corporate internet links.
Implementing GlobalProtect split tunneling solves this operational bottleneck. By selectively routing corporate application traffic through the encrypted IPsec or SSL VPN tunnel while steering approved non-corporate traffic directly out the user’s local internet connection, organizations optimize bandwidth usage, reduce latency for SaaS applications, and maintain strict access controls over internal enterprise assets.
This technical guide details the architecture, design models, and step-by-step configuration required to deploy split tunneling on Palo Alto Networks firewalls running PAN-OS.
Real-Life Scenario
Apex Financial Services employs 500 remote workers who require access to on-premises banking applications and cloud-hosted enterprise services. Under their previous full-tunnel VPN configuration, video calls and large OS updates caused severe interface utilization on the edge firewall’s internet link, leading to dropped sessions and poor voice quality for internal database operations.
The enterprise network team was tasked with implementing a split tunneling architecture to satisfy three distinct operational requirements:
- Corporate Route Steering: Direct all internal data center traffic (subnets
10.10.0.0/16and10.20.0.0/16) securely through the GlobalProtect tunnel. - Direct Internet Breakout: Direct general public internet traffic directly out the client’s local network adapter to bypass the enterprise gateway.
- Domain-Specific Steering: Route all corporate internal domain queries (
*.corp.apex.lab) through the tunnel to ensure internal DNS resolution works without leaking requests to public DNS resolvers.
Lab Topology
The following diagram illustrates the logical path for traffic originating from a GlobalProtect client endpoint after split tunneling policies are applied.
+-----------------------+
| Public Internet / SaaS|
+-----------+-----------+
^
| (Direct Local Path)
+-----------------------+ +----------+------------+
| GlobalProtect Client | | Remote User Router |
| (Local WAN IP) +------------>| (Local ISP Breakout) |
+-----------+-----------+ +-----------------------+
|
| (Encrypted Tunnel Path)
v
+-----------+-----------+
| External Gateway |
| IP: 192.0.2.10 |
+-----------+-----------+
|
v
+-----------+-----------+ +-----------------------+
| Palo Alto Firewall +------------>| Enterprise Subnets |
| (Zone: Trust-VPN) | | 10.10.0.0/16 |
+-----------------------+ | 10.20.0.0/16 |
+-----------------------+
Example Addressing and Objects
The configuration examples in this tutorial rely on the following network parameters and firewall objects. Adapt these laboratory values to your specific IP address plan.
| Object Name / Type | Value / CIDR Block | Description |
|---|---|---|
192.0.2.10 |
IPv4 Address | External Interface (Gateway Public IP) |
10.200.1.0/24 |
IPv4 Address Pool | GlobalProtect Virtual Adapter IP Pool |
10.10.0.0/16 |
IPv4 Subnet | Data Center Primary Network |
10.20.0.0/16 |
IPv4 Subnet | Data Center Secondary Network |
10.10.1.53 |
IPv4 Address | Internal Enterprise DNS Server |
*.corp.apex.lab |
FQDN Pattern | Internal Enterprise Domain String |
tunnel.1 |
Interface | GlobalProtect Tunnel Interface |
VPN-Users |
Security Zone | Zone assigned to tunnel.1 |
Prerequisites
Before configuring split tunneling policies on the gateway, verify that the following underlying infrastructure components are operational:
- A fully operational GlobalProtect Portal and Gateway configuration.
- A dedicated tunnel interface (e.g.,
tunnel.1) assigned to a dedicated security zone (e.g.,VPN-Users). - Active security policy rules allowing traffic from the GlobalProtect security zone to required internal destination zones.
- GlobalProtect Agent version 5.2 or higher installed on user endpoints (required for advanced application and domain split tunneling features).
Step-by-Step GUI Configuration
GlobalProtect split tunneling is configured within the gateway client settings. Follow these steps to configure route-based and domain-based split tunneling.
Step 1: Access the Gateway Client Configuration
- Log into the PAN-OS web interface.
- Navigate to Network > GlobalProtect > Gateways.
- Select your active gateway configuration (e.g.,
GP-Gateway-GW). - Select the Agent tab, then select the Client Configuration sub-tab.
- Select your existing client configuration profile or click Add to create a new profile.
Step 2: Configure Network Settings and DNS
To ensure internal name resolution functions cleanly alongside local internet breakout, define internal enterprise DNS servers within the client configuration.
- Inside the Client Configuration window, select Network Settings.
- Under IP Pools, verify your IP pool object (e.g.,
10.200.1.0/24) is defined. - Under DNS Servers, add your primary internal DNS server IP (e.g.,
10.10.1.53).
Step 3: Configure Route-Based Split Tunneling (Access Routes)
Route-based split tunneling dictates which IP destination networks are injected into the endpoint’s routing table by the GlobalProtect virtual network adapter.
- Select the Split Tunnel tab.
- Locate the Include Tunnel Route section under the Access Route tab.
- Click Add and enter the internal enterprise subnets that must pass through the encrypted VPN tunnel:
10.10.0.0/1610.20.0.0/16
Note on Access Route Behavior: Leaving Include Tunnel Route blank causes GlobalProtect to push a default route (0.0.0.0/0) to the client, enforcing full tunneling. Explicitly defining routes in Include Tunnel Route instructs the client to steer only matching destination traffic into the tunnel. All unlisted destinations bypass the tunnel via the endpoint’s physical default gateway.
Step 4: Configure Domain-Based Split Tunneling
Domain-based split tunneling allows steering traffic based on FQDN targets regardless of dynamic IP address changes. This is critical for enterprise SaaS tools or multi-homed web applications.
- Within the Split Tunnel tab, select the Domain Traffic sub-tab.
- Under Include Domain, click Add.
- Enter the target domain pattern (e.g.,
*.corp.apex.lab).
When configured, the GlobalProtect agent intercepts DNS requests matching this pattern and forces the endpoint to send DNS queries through the tunnel interface to the configured internal DNS server (10.10.1.53).
Step 5: Commit Configuration Changes
- Click OK to close the Client Configuration window.
- Click OK to close the Gateway configuration window.
- Click Commit in the top-right corner of the web interface and select Commit to activate the configuration.
CLI Section
You can review and verify the gateway configuration via the PAN-OS Command Line Interface (CLI). Use the following commands to check gateway state and active client parameters.
To view currently connected GlobalProtect users and the split tunneling routes pushed to their client endpoints:
show global-protect-gateway current-user gateway GP-Gateway-GW
To inspect session details for a connected split-tunnel user (substitute 10.200.1.10 with your target client virtual IP address):
show session all filter source 10.200.1.10
To verify the firewall’s FIB lookup for traffic originating from the GlobalProtect tunnel interface toward internal destinations:
test routing fib-lookup virtual-router default ip 10.10.5.20
How the Traffic Flows
Understanding how the client OS driver and firewall process split-tunneled traffic ensures accurate security policies and faster troubleshooting.
1. Initialization Phase
- The client endpoint establishes a TLS/IPsec session with the GlobalProtect Gateway on
192.0.2.10:443. - The gateway authenticates the endpoint and pushes network settings: the virtual IP address (
10.200.1.10), internal DNS server (10.10.1.53), include routes (10.10.0.0/16,10.20.0.0/16), and domain include rules (*.corp.apex.lab). - The GlobalProtect filter driver on the client installs explicit routes into the host system’s routing table.
2. Packet Path Decision (Client-Side)
- Scenario A (Corporate IP Traffic): A packet is destined for
10.10.5.20. The OS routing table matches the explicit10.10.0.0/16route assigned to the GlobalProtect virtual adapter. The agent encapsulates the frame in IPsec/SSL and transmits it across the public Internet to192.0.2.10. - Scenario B (Public Web Traffic): A packet is destined for
198.51.100.45(a public website). The target does not match any entry in the virtual adapter route table. The host OS forwards the frame to the physical network card’s local default gateway. The packet exits directly to the local ISP. - Scenario C (Domain Steering): The user initiates a connection to
app.corp.apex.lab. The GlobalProtect client filter driver intercepts the DNS query. Because it matches the included domain rule (*.corp.apex.lab), the query is steered over the encrypted tunnel to the internal DNS server (10.10.1.53).
3. Packet Path Processing (Firewall-Side)
- Encapsulated VPN packets arrive on the physical interface (e.g.,
ethernet1/1) and undergo IPsec decryption. - Decapsulated inner packets emerge logically on interface
tunnel.1in theVPN-Userssecurity zone. - The firewall performs a standard forwarding lookup, evaluating destination IP addresses against the virtual router table.
- Security policy evaluation takes place: traffic moving from
VPN-Usersto internal target zones (e.g.,Trust-DataCenter) is matched against configured security rules.
Verification
Verify split tunneling operations from both the client workstation and the firewall console.
Client-Side Verification
On a Windows endpoint connected to GlobalProtect, open Command Prompt or PowerShell and inspect the routing table:
route print
Verify that explicit routes exist for 10.10.0.0/16 and 10.20.0.0/16 pointing to the GlobalProtect virtual interface gateway address, while the default route (0.0.0.0/0) remains anchored to the local physical local network interface.
Execute a traceroute to an internal server IP versus a public IP:
tracert 10.10.1.5
tracert 198.51.100.1
The trace to 10.10.1.5 should show the tunnel gateway IP as its first hop. The trace to 198.51.100.1 should display the local home/remote router’s IP address as its first hop.
Firewall-Side Verification
Execute the operational command on the CLI to review connected client states:
show global-protect-gateway current-user gateway GP-Gateway-GW
Verify the output lists the assigned virtual IP and explicitly assigned access routes for the target user session.
Troubleshooting
When split tunneling does not behave as intended, apply this structured troubleshooting workflow.
Symptom 1: All Traffic Continues Passing Through the Tunnel
- Probable Cause: An inclusion route of
0.0.0.0/0exists in the configuration, or duplicate gateway client settings profiles are overriding policy matching. - Verification Check: Review the client routing table (
route print). If0.0.0.0/0points to the virtual adapter metric lower than the physical adapter metric, full tunnel mode is active. - Corrective Action: Inspect Network > GlobalProtect > Gateways > Agent > Client Configuration > Split Tunnel. Ensure
0.0.0.0/0is removed from Include Tunnel Route.
Symptom 2: Internal Domain Names Fail to Resolve
- Probable Cause: Missing inclusion domain entries or lack of internal DNS push via client configuration.
- Verification Check: From the client command prompt, execute:
nslookup app.corp.apex.labIf the server responding is the user’s public/local ISP router IP instead of
10.10.1.53, the domain query is leaking to local network adapter DNS servers. - Corrective Action: Verify that the target domain string (e.g.,
*.corp.apex.lab) is entered under the Domain Traffic > Include Domain configuration on the gateway.
Symptom 3: Split Tunnel Rules Not Updating on Endpoints
- Probable Cause: The GlobalProtect client caches configuration profiles locally until manual refresh or session re-authentication occurs.
- Corrective Action: Open the GlobalProtect App panel on the user workstation, click the top-right menu icon, select Refresh Connection, or disconnect and reconnect to pull the updated XML configuration payload from the Portal/Gateway.
Common Mistakes
Engineers deploying split tunneling frequently encounter three implementation pitfalls:
- Combining Empty Include and Exclude Routes Incorrectly: Defining subnets in Exclude Tunnel Route while leaving Include Tunnel Route completely blank will default to pushing all routes (full tunnel) minus the excluded routes. Conversely, defining specific subnets in Include Tunnel Route automatically converts the tunnel behavior to split-include mode without needing explicit entries in Exclude routes.
- Overlooking Asymmetric Routing with Multiple Interfaces: If internal subnets added to Include Tunnel Route overlap with local subnets used on home networks (such as standard
192.168.1.0/24ranges), endpoints experience routing conflicts. Always design internal addressing to avoid common residential LAN spaces where possible. - Forgetting NAT/Security Rules for Tunnel Traffic: Creating split-tunnel inclusion routes handles client-side routing, but traffic arriving at the firewall interface must still match a valid Security Policy rule. Ensure rules explicitly allow traffic from the source zone associated with
tunnel.1to the target zones.
Production Considerations
When rolling out GlobalProtect split tunneling across enterprise environments, consider these security and operational best practices:
1. Security Posture and End-User Direct Breakout
Direct internet breakout means non-corporate web traffic bypasses perimeter firewall controls (such as Threat Prevention, WildFire, and URL Filtering). To mitigate endpoint risks, ensure all remote workstations run active Endpoint Protection (EPP/EDR) software, such as Cortex XDR, to inspect traffic locally at the host layer.
2. Video Traffic Offloading
For high-volume video conferencing applications (Zoom, Microsoft Teams, WebEx), consider using the built-in Exclude Video Traffic configuration tab under Split Tunnel settings. This feature uses Palo Alto Networks App-ID signatures to dynamic-bypass bandwidth-heavy multimedia streaming sessions from the encrypted tunnel while maintaining full security coverage for other application protocols.
3. Dynamic Route Updates
If internal data center subnet structures change frequently, consider using FQDN address objects or updating Split Tunnel inclusion settings via automated PAN-OS XML API integrations to keep remote client routing tables aligned with corporate infrastructure changes without requiring manual firewall configuration updates.
Summary
Configuring GlobalProtect split tunneling on Palo Alto Networks firewalls preserves WAN bandwidth and minimizes latency for remote workforce applications. By combining route-based access lists and domain inclusion rules, security engineers maintain strict control over sensitive enterprise network access while allowing non-corporate traffic to route locally.
Related guides: See the Palo Alto GlobalProtect remote-user configuration guide for the full VPN deployment workflow and the Palo Alto Syslog/SIEM guide for centralized visibility.