{"id":1616,"date":"2026-09-20T14:55:46","date_gmt":"2026-09-20T09:25:46","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/globalprotect-split-tunneling-configuration\/"},"modified":"2026-09-30T14:57:54","modified_gmt":"2026-09-30T09:27:54","slug":"globalprotect-split-tunneling-configuration","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/","title":{"rendered":"GlobalProtect Split Tunneling on Palo Alto Firewall: Design and Configuration"},"content":{"rendered":"<p>As remote workforce models mature, security engineers face a persistent challenge: balancing corporate network security with endpoint performance and WAN bandwidth consumption. When all remote user traffic is backhauled through a central firewall\u2014a model known as full tunneling\u2014high-bandwidth, non-sensitive cloud applications like video conferencing, streaming services, and software updates can rapidly exhaust corporate internet links.<\/p>\n<p>Implementing <strong>GlobalProtect split tunneling<\/strong> solves this operational bottleneck. By selectively routing corporate application traffic through the encrypted IPsec or SSL VPN tunnel while steering approved non-corporate traffic directly out the user&#8217;s local internet connection, organizations optimize bandwidth usage, reduce latency for SaaS applications, and maintain strict access controls over internal enterprise assets.<\/p>\n<p>This technical guide details the architecture, design models, and step-by-step configuration required to deploy split tunneling on Palo Alto Networks firewalls running PAN-OS.<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>Apex Financial Services employs 500 remote workers who require access to on-premises banking applications and cloud-hosted enterprise services. Under their previous full-tunnel VPN configuration, video calls and large OS updates caused severe interface utilization on the edge firewall&#8217;s internet link, leading to dropped sessions and poor voice quality for internal database operations.<\/p>\n<p>The enterprise network team was tasked with implementing a split tunneling architecture to satisfy three distinct operational requirements:<\/p>\n<ul>\n<li><strong>Corporate Route Steering:<\/strong> Direct all internal data center traffic (subnets <code>10.10.0.0\/16<\/code> and <code>10.20.0.0\/16<\/code>) securely through the GlobalProtect tunnel.<\/li>\n<li><strong>Direct Internet Breakout:<\/strong> Direct general public internet traffic directly out the client&#8217;s local network adapter to bypass the enterprise gateway.<\/li>\n<li><strong>Domain-Specific Steering:<\/strong> Route all corporate internal domain queries (<code>*.corp.apex.lab<\/code>) through the tunnel to ensure internal DNS resolution works without leaking requests to public DNS resolvers.<\/li>\n<\/ul>\n<h2>Lab Topology<\/h2>\n<p>The following diagram illustrates the logical path for traffic originating from a GlobalProtect client endpoint after split tunneling policies are applied.<\/p>\n<pre>\n                                     +-----------------------+\n                                     | Public Internet \/ SaaS|\n                                     +-----------+-----------+\n                                                 ^\n                                                 | (Direct Local Path)\n+-----------------------+             +----------+------------+\n|  GlobalProtect Client |             | Remote User Router    |\n|  (Local WAN IP)       +------------&gt;| (Local ISP Breakout)  |\n+-----------+-----------+             +-----------------------+\n            |\n            | (Encrypted Tunnel Path)\n            v\n+-----------+-----------+\n| External Gateway      |\n| IP: 192.0.2.10        |\n+-----------+-----------+\n            |\n            v\n+-----------+-----------+             +-----------------------+\n|  Palo Alto Firewall   +------------&gt;| Enterprise Subnets    |\n|  (Zone: Trust-VPN)    |             | 10.10.0.0\/16          |\n+-----------------------+             | 10.20.0.0\/16          |\n                                      +-----------------------+\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>The configuration examples in this tutorial rely on the following network parameters and firewall objects. Adapt these laboratory values to your specific IP address plan.<\/p>\n<table>\n<thead>\n<tr>\n<th>Object Name \/ Type<\/th>\n<th>Value \/ CIDR Block<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>192.0.2.10<\/code><\/td>\n<td>IPv4 Address<\/td>\n<td>External Interface (Gateway Public IP)<\/td>\n<\/tr>\n<tr>\n<td><code>10.200.1.0\/24<\/code><\/td>\n<td>IPv4 Address Pool<\/td>\n<td>GlobalProtect Virtual Adapter IP Pool<\/td>\n<\/tr>\n<tr>\n<td><code>10.10.0.0\/16<\/code><\/td>\n<td>IPv4 Subnet<\/td>\n<td>Data Center Primary Network<\/td>\n<\/tr>\n<tr>\n<td><code>10.20.0.0\/16<\/code><\/td>\n<td>IPv4 Subnet<\/td>\n<td>Data Center Secondary Network<\/td>\n<\/tr>\n<tr>\n<td><code>10.10.1.53<\/code><\/td>\n<td>IPv4 Address<\/td>\n<td>Internal Enterprise DNS Server<\/td>\n<\/tr>\n<tr>\n<td><code>*.corp.apex.lab<\/code><\/td>\n<td>FQDN Pattern<\/td>\n<td>Internal Enterprise Domain String<\/td>\n<\/tr>\n<tr>\n<td><code>tunnel.1<\/code><\/td>\n<td>Interface<\/td>\n<td>GlobalProtect Tunnel Interface<\/td>\n<\/tr>\n<tr>\n<td><code>VPN-Users<\/code><\/td>\n<td>Security Zone<\/td>\n<td>Zone assigned to <code>tunnel.1<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<p>Before configuring split tunneling policies on the gateway, verify that the following underlying infrastructure components are operational:<\/p>\n<ul>\n<li>A fully operational GlobalProtect Portal and Gateway configuration.<\/li>\n<li>A dedicated tunnel interface (e.g., <code>tunnel.1<\/code>) assigned to a dedicated security zone (e.g., <code>VPN-Users<\/code>).<\/li>\n<li>Active security policy rules allowing traffic from the GlobalProtect security zone to required internal destination zones.<\/li>\n<li>GlobalProtect Agent version 5.2 or higher installed on user endpoints (required for advanced application and domain split tunneling features).<\/li>\n<\/ul>\n<h2>Step-by-Step GUI Configuration<\/h2>\n<p>GlobalProtect split tunneling is configured within the gateway client settings. Follow these steps to configure route-based and domain-based split tunneling.<\/p>\n<h3>Step 1: Access the Gateway Client Configuration<\/h3>\n<ol>\n<li>Log into the PAN-OS web interface.<\/li>\n<li>Navigate to <strong>Network<\/strong> &gt; <strong>GlobalProtect<\/strong> &gt; <strong>Gateways<\/strong>.<\/li>\n<li>Select your active gateway configuration (e.g., <code>GP-Gateway-GW<\/code>).<\/li>\n<li>Select the <strong>Agent<\/strong> tab, then select the <strong>Client Configuration<\/strong> sub-tab.<\/li>\n<li>Select your existing client configuration profile or click <strong>Add<\/strong> to create a new profile.<\/li>\n<\/ol>\n<h3>Step 2: Configure Network Settings and DNS<\/h3>\n<p>To ensure internal name resolution functions cleanly alongside local internet breakout, define internal enterprise DNS servers within the client configuration.<\/p>\n<ol>\n<li>Inside the Client Configuration window, select <strong>Network Settings<\/strong>.<\/li>\n<li>Under <strong>IP Pools<\/strong>, verify your IP pool object (e.g., <code>10.200.1.0\/24<\/code>) is defined.<\/li>\n<li>Under <strong>DNS Servers<\/strong>, add your primary internal DNS server IP (e.g., <code>10.10.1.53<\/code>).<\/li>\n<\/ol>\n<h3>Step 3: Configure Route-Based Split Tunneling (Access Routes)<\/h3>\n<p>Route-based split tunneling dictates which IP destination networks are injected into the endpoint&#8217;s routing table by the GlobalProtect virtual network adapter.<\/p>\n<ol>\n<li>Select the <strong>Split Tunnel<\/strong> tab.<\/li>\n<li>Locate the <strong>Include Tunnel Route<\/strong> section under the Access Route tab.<\/li>\n<li>Click <strong>Add<\/strong> and enter the internal enterprise subnets that must pass through the encrypted VPN tunnel:\n<ul>\n<li><code>10.10.0.0\/16<\/code><\/li>\n<li><code>10.20.0.0\/16<\/code><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p><em>Note on Access Route Behavior:<\/em> Leaving <strong>Include Tunnel Route<\/strong> blank causes GlobalProtect to push a default route (<code>0.0.0.0\/0<\/code>) to the client, enforcing full tunneling. Explicitly defining routes in <strong>Include Tunnel Route<\/strong> instructs the client to steer only matching destination traffic into the tunnel. All unlisted destinations bypass the tunnel via the endpoint&#8217;s physical default gateway.<\/p>\n<h3>Step 4: Configure Domain-Based Split Tunneling<\/h3>\n<p>Domain-based split tunneling allows steering traffic based on FQDN targets regardless of dynamic IP address changes. This is critical for enterprise SaaS tools or multi-homed web applications.<\/p>\n<ol>\n<li>Within the <strong>Split Tunnel<\/strong> tab, select the <strong>Domain Traffic<\/strong> sub-tab.<\/li>\n<li>Under <strong>Include Domain<\/strong>, click <strong>Add<\/strong>.<\/li>\n<li>Enter the target domain pattern (e.g., <code>*.corp.apex.lab<\/code>).<\/li>\n<\/ol>\n<p>When configured, the GlobalProtect agent intercepts DNS requests matching this pattern and forces the endpoint to send DNS queries through the tunnel interface to the configured internal DNS server (<code>10.10.1.53<\/code>).<\/p>\n<h3>Step 5: Commit Configuration Changes<\/h3>\n<ol>\n<li>Click <strong>OK<\/strong> to close the Client Configuration window.<\/li>\n<li>Click <strong>OK<\/strong> to close the Gateway configuration window.<\/li>\n<li>Click <strong>Commit<\/strong> in the top-right corner of the web interface and select <strong>Commit<\/strong> to activate the configuration.<\/li>\n<\/ol>\n<h2>CLI Section<\/h2>\n<p>You can review and verify the gateway configuration via the PAN-OS Command Line Interface (CLI). Use the following commands to check gateway state and active client parameters.<\/p>\n<p>To view currently connected GlobalProtect users and the split tunneling routes pushed to their client endpoints:<\/p>\n<pre><code>show global-protect-gateway current-user gateway GP-Gateway-GW<\/code><\/pre>\n<p>To inspect session details for a connected split-tunnel user (substitute <code>10.200.1.10<\/code> with your target client virtual IP address):<\/p>\n<pre><code>show session all filter source 10.200.1.10<\/code><\/pre>\n<p>To verify the firewall&#8217;s FIB lookup for traffic originating from the GlobalProtect tunnel interface toward internal destinations:<\/p>\n<pre><code>test routing fib-lookup virtual-router default ip 10.10.5.20<\/code><\/pre>\n<h2>How the Traffic Flows<\/h2>\n<p>Understanding how the client OS driver and firewall process split-tunneled traffic ensures accurate security policies and faster troubleshooting.<\/p>\n<h3>1. Initialization Phase<\/h3>\n<ol>\n<li>The client endpoint establishes a TLS\/IPsec session with the GlobalProtect Gateway on <code>192.0.2.10:443<\/code>.<\/li>\n<li>The gateway authenticates the endpoint and pushes network settings: the virtual IP address (<code>10.200.1.10<\/code>), internal DNS server (<code>10.10.1.53<\/code>), include routes (<code>10.10.0.0\/16<\/code>, <code>10.20.0.0\/16<\/code>), and domain include rules (<code>*.corp.apex.lab<\/code>).<\/li>\n<li>The GlobalProtect filter driver on the client installs explicit routes into the host system&#8217;s routing table.<\/li>\n<\/ol>\n<h3>2. Packet Path Decision (Client-Side)<\/h3>\n<ul>\n<li><strong>Scenario A (Corporate IP Traffic):<\/strong> A packet is destined for <code>10.10.5.20<\/code>. The OS routing table matches the explicit <code>10.10.0.0\/16<\/code> route assigned to the GlobalProtect virtual adapter. The agent encapsulates the frame in IPsec\/SSL and transmits it across the public Internet to <code>192.0.2.10<\/code>.<\/li>\n<li><strong>Scenario B (Public Web Traffic):<\/strong> A packet is destined for <code>198.51.100.45<\/code> (a public website). The target does not match any entry in the virtual adapter route table. The host OS forwards the frame to the physical network card&#8217;s local default gateway. The packet exits directly to the local ISP.<\/li>\n<li><strong>Scenario C (Domain Steering):<\/strong> The user initiates a connection to <code>app.corp.apex.lab<\/code>. The GlobalProtect client filter driver intercepts the DNS query. Because it matches the included domain rule (<code>*.corp.apex.lab<\/code>), the query is steered over the encrypted tunnel to the internal DNS server (<code>10.10.1.53<\/code>).<\/li>\n<\/ul>\n<h3>3. Packet Path Processing (Firewall-Side)<\/h3>\n<ol>\n<li>Encapsulated VPN packets arrive on the physical interface (e.g., <code>ethernet1\/1<\/code>) and undergo IPsec decryption.<\/li>\n<li>Decapsulated inner packets emerge logically on interface <code>tunnel.1<\/code> in the <code>VPN-Users<\/code> security zone.<\/li>\n<li>The firewall performs a standard forwarding lookup, evaluating destination IP addresses against the virtual router table.<\/li>\n<li>Security policy evaluation takes place: traffic moving from <code>VPN-Users<\/code> to internal target zones (e.g., <code>Trust-DataCenter<\/code>) is matched against configured security rules.<\/li>\n<\/ol>\n<h2>Verification<\/h2>\n<p>Verify split tunneling operations from both the client workstation and the firewall console.<\/p>\n<h3>Client-Side Verification<\/h3>\n<p>On a Windows endpoint connected to GlobalProtect, open Command Prompt or PowerShell and inspect the routing table:<\/p>\n<pre><code>route print<\/code><\/pre>\n<p>Verify that explicit routes exist for <code>10.10.0.0\/16<\/code> and <code>10.20.0.0\/16<\/code> pointing to the GlobalProtect virtual interface gateway address, while the default route (<code>0.0.0.0\/0<\/code>) remains anchored to the local physical local network interface.<\/p>\n<p>Execute a traceroute to an internal server IP versus a public IP:<\/p>\n<pre><code>tracert 10.10.1.5\ntracert 198.51.100.1<\/code><\/pre>\n<p>The trace to <code>10.10.1.5<\/code> should show the tunnel gateway IP as its first hop. The trace to <code>198.51.100.1<\/code> should display the local home\/remote router&#8217;s IP address as its first hop.<\/p>\n<h3>Firewall-Side Verification<\/h3>\n<p>Execute the operational command on the CLI to review connected client states:<\/p>\n<pre><code>show global-protect-gateway current-user gateway GP-Gateway-GW<\/code><\/pre>\n<p>Verify the output lists the assigned virtual IP and explicitly assigned access routes for the target user session.<\/p>\n<h2>Troubleshooting<\/h2>\n<p>When split tunneling does not behave as intended, apply this structured troubleshooting workflow.<\/p>\n<h3>Symptom 1: All Traffic Continues Passing Through the Tunnel<\/h3>\n<ul>\n<li><strong>Probable Cause:<\/strong> An inclusion route of <code>0.0.0.0\/0<\/code> exists in the configuration, or duplicate gateway client settings profiles are overriding policy matching.<\/li>\n<li><strong>Verification Check:<\/strong> Review the client routing table (<code>route print<\/code>). If <code>0.0.0.0\/0<\/code> points to the virtual adapter metric lower than the physical adapter metric, full tunnel mode is active.<\/li>\n<li><strong>Corrective Action:<\/strong> Inspect <strong>Network<\/strong> &gt; <strong>GlobalProtect<\/strong> &gt; <strong>Gateways<\/strong> &gt; <strong>Agent<\/strong> &gt; <strong>Client Configuration<\/strong> &gt; <strong>Split Tunnel<\/strong>. Ensure <code>0.0.0.0\/0<\/code> is removed from <strong>Include Tunnel Route<\/strong>.<\/li>\n<\/ul>\n<h3>Symptom 2: Internal Domain Names Fail to Resolve<\/h3>\n<ul>\n<li><strong>Probable Cause:<\/strong> Missing inclusion domain entries or lack of internal DNS push via client configuration.<\/li>\n<li><strong>Verification Check:<\/strong> From the client command prompt, execute:\n<pre><code>nslookup app.corp.apex.lab<\/code><\/pre>\n<p>        If the server responding is the user&#8217;s public\/local ISP router IP instead of <code>10.10.1.53<\/code>, the domain query is leaking to local network adapter DNS servers.\n    <\/li>\n<li><strong>Corrective Action:<\/strong> Verify that the target domain string (e.g., <code>*.corp.apex.lab<\/code>) is entered under the <strong>Domain Traffic<\/strong> &gt; <strong>Include Domain<\/strong> configuration on the gateway.<\/li>\n<\/ul>\n<h3>Symptom 3: Split Tunnel Rules Not Updating on Endpoints<\/h3>\n<ul>\n<li><strong>Probable Cause:<\/strong> The GlobalProtect client caches configuration profiles locally until manual refresh or session re-authentication occurs.<\/li>\n<li><strong>Corrective Action:<\/strong> Open the GlobalProtect App panel on the user workstation, click the top-right menu icon, select <strong>Refresh Connection<\/strong>, or disconnect and reconnect to pull the updated XML configuration payload from the Portal\/Gateway.<\/li>\n<\/ul>\n<h2>Common Mistakes<\/h2>\n<p>Engineers deploying split tunneling frequently encounter three implementation pitfalls:<\/p>\n<ol>\n<li><strong>Combining Empty Include and Exclude Routes Incorrectly:<\/strong> Defining subnets in <strong>Exclude Tunnel Route<\/strong> while leaving <strong>Include Tunnel Route<\/strong> completely blank will default to pushing all routes (full tunnel) minus the excluded routes. Conversely, defining specific subnets in <strong>Include Tunnel Route<\/strong> automatically converts the tunnel behavior to split-include mode without needing explicit entries in Exclude routes.<\/li>\n<li><strong>Overlooking Asymmetric Routing with Multiple Interfaces:<\/strong> If internal subnets added to <strong>Include Tunnel Route<\/strong> overlap with local subnets used on home networks (such as standard <code>192.168.1.0\/24<\/code> ranges), endpoints experience routing conflicts. Always design internal addressing to avoid common residential LAN spaces where possible.<\/li>\n<li><strong>Forgetting NAT\/Security Rules for Tunnel Traffic:<\/strong> Creating split-tunnel inclusion routes handles client-side routing, but traffic arriving at the firewall interface must still match a valid Security Policy rule. Ensure rules explicitly allow traffic from the source zone associated with <code>tunnel.1<\/code> to the target zones.<\/li>\n<\/ol>\n<h2>Production Considerations<\/h2>\n<p>When rolling out GlobalProtect split tunneling across enterprise environments, consider these security and operational best practices:<\/p>\n<h3>1. Security Posture and End-User Direct Breakout<\/h3>\n<p>Direct internet breakout means non-corporate web traffic bypasses perimeter firewall controls (such as Threat Prevention, WildFire, and URL Filtering). To mitigate endpoint risks, ensure all remote workstations run active Endpoint Protection (EPP\/EDR) software, such as Cortex XDR, to inspect traffic locally at the host layer.<\/p>\n<h3>2. Video Traffic Offloading<\/h3>\n<p>For high-volume video conferencing applications (Zoom, Microsoft Teams, WebEx), consider using the built-in <strong>Exclude Video Traffic<\/strong> configuration tab under <strong>Split Tunnel<\/strong> settings. This feature uses Palo Alto Networks App-ID signatures to dynamic-bypass bandwidth-heavy multimedia streaming sessions from the encrypted tunnel while maintaining full security coverage for other application protocols.<\/p>\n<h3>3. Dynamic Route Updates<\/h3>\n<p>If internal data center subnet structures change frequently, consider using FQDN address objects or updating Split Tunnel inclusion settings via automated PAN-OS XML API integrations to keep remote client routing tables aligned with corporate infrastructure changes without requiring manual firewall configuration updates.<\/p>\n<h2>Summary<\/h2>\n<p>Configuring GlobalProtect split tunneling on Palo Alto Networks firewalls preserves WAN bandwidth and minimizes latency for remote workforce applications. By combining route-based access lists and domain inclusion rules, security engineers maintain strict control over sensitive enterprise network access while allowing non-corporate traffic to route locally.<\/p>\n<p><strong>Related guides:<\/strong> See the <a href=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-globalprotect-configuration\/\">Palo Alto GlobalProtect remote-user configuration guide<\/a> for the full VPN deployment workflow and the <a href=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-log-forwarding-syslog-siem\/\">Palo Alto Syslog\/SIEM guide<\/a> for centralized visibility.<\/p>","protected":false},"excerpt":{"rendered":"<p>Design GlobalProtect split tunneling so corporate destinations use the VPN while approved Internet traffic follows the local path.<\/p>","protected":false},"author":2,"featured_media":1615,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[5],"tags":[137,29,75,1187,32,31],"class_list":["post-1616","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-palo","tag-advanced","tag-firewall-tutorial","tag-globalprotect","tag-globalprotect-split-tunneling","tag-palo-alto-networks","tag-pan-os"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>GlobalProtect Split Tunneling on Palo Alto: Configuration Guide<\/title>\n<meta name=\"description\" content=\"Configure GlobalProtect split tunneling on Palo Alto with routing design, gateway settings, security policy checks and client-side verification.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GlobalProtect Split Tunneling on Palo Alto Firewall: Design and Configuration\" \/>\n<meta property=\"og:description\" content=\"Configure GlobalProtect split tunneling on Palo Alto with routing design, gateway settings, security policy checks and client-side verification.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-20T09:25:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-30T09:27:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/globalprotect-split-tunneling-on-palo-alto-firewall-design-and-configuration-featured.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"GlobalProtect Split Tunneling on Palo Alto Firewall: Design and Configuration\",\"datePublished\":\"2026-09-20T09:25:46+00:00\",\"dateModified\":\"2026-09-30T09:27:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/\"},\"wordCount\":1930,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/globalprotect-split-tunneling-on-palo-alto-firewall-design-and-configuration-featured.jpg\",\"keywords\":[\"Advanced\",\"Firewall Tutorial\",\"GlobalProtect\",\"GlobalProtect split tunneling\",\"Palo Alto Networks\",\"PAN-OS\"],\"articleSection\":[\"Palo Alto\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/\",\"name\":\"GlobalProtect Split Tunneling on Palo Alto: Configuration Guide\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/globalprotect-split-tunneling-on-palo-alto-firewall-design-and-configuration-featured.jpg\",\"datePublished\":\"2026-09-20T09:25:46+00:00\",\"dateModified\":\"2026-09-30T09:27:54+00:00\",\"description\":\"Configure GlobalProtect split tunneling on Palo Alto with routing design, gateway settings, security policy checks and client-side verification.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/globalprotect-split-tunneling-on-palo-alto-firewall-design-and-configuration-featured.jpg\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/globalprotect-split-tunneling-on-palo-alto-firewall-design-and-configuration-featured.jpg\",\"width\":1200,\"height\":630,\"caption\":\"GlobalProtect Split Tunneling on Palo Alto Firewall: Design and Configuration\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/globalprotect-split-tunneling-configuration\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GlobalProtect Split Tunneling on Palo Alto Firewall: Design and Configuration\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"GlobalProtect Split Tunneling on Palo Alto: Configuration Guide","description":"Configure GlobalProtect split tunneling on Palo Alto with routing design, gateway settings, security policy checks and client-side verification.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/","og_locale":"en_US","og_type":"article","og_title":"GlobalProtect Split Tunneling on Palo Alto Firewall: Design and Configuration","og_description":"Configure GlobalProtect split tunneling on Palo Alto with routing design, gateway settings, security policy checks and client-side verification.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/","og_site_name":"NetworkFix","article_published_time":"2026-09-20T09:25:46+00:00","article_modified_time":"2026-09-30T09:27:54+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/globalprotect-split-tunneling-on-palo-alto-firewall-design-and-configuration-featured.jpg","type":"image\/jpeg"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"GlobalProtect Split Tunneling on Palo Alto Firewall: Design and Configuration","datePublished":"2026-09-20T09:25:46+00:00","dateModified":"2026-09-30T09:27:54+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/"},"wordCount":1930,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/globalprotect-split-tunneling-on-palo-alto-firewall-design-and-configuration-featured.jpg","keywords":["Advanced","Firewall Tutorial","GlobalProtect","GlobalProtect split tunneling","Palo Alto Networks","PAN-OS"],"articleSection":["Palo Alto"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/","url":"https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/","name":"GlobalProtect Split Tunneling on Palo Alto: Configuration Guide","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/globalprotect-split-tunneling-on-palo-alto-firewall-design-and-configuration-featured.jpg","datePublished":"2026-09-20T09:25:46+00:00","dateModified":"2026-09-30T09:27:54+00:00","description":"Configure GlobalProtect split tunneling on Palo Alto with routing design, gateway settings, security policy checks and client-side verification.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/globalprotect-split-tunneling-on-palo-alto-firewall-design-and-configuration-featured.jpg","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/globalprotect-split-tunneling-on-palo-alto-firewall-design-and-configuration-featured.jpg","width":1200,"height":630,"caption":"GlobalProtect Split Tunneling on Palo Alto Firewall: Design and Configuration"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/palo\/globalprotect-split-tunneling-configuration\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"GlobalProtect Split Tunneling on Palo Alto Firewall: Design and Configuration"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1616","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=1616"}],"version-history":[{"count":3,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1616\/revisions"}],"predecessor-version":[{"id":1640,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1616\/revisions\/1640"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/1615"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=1616"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=1616"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=1616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}