Host a split tunnel configuration file on a local web server for expanded support for
domains, access routes and applications that you can update dynamically.
| Where Can I Use
This? | What Do I Need? |
- NGFW (managed by Panorama or Strata Cloud Manager)
- Prisma Access (managed by Panorama or Strata Cloud
Manager)
|
|
- Your split tunnel configuration file must parse as valid XML
- The web server must be reachable by all endpoints configured to fetch the split
tunnel configuration file
- The server and the client must be able to mutually authenticate
If the GlobalProtect app cannot fetch the split tunnel configuration file, it falls
back to the split tunnel configuration that you have configured on the gateway.
The following table shows the split tunnel configuration limits when the
configuration is hosted on GlobalProtect vs. when it is hosted in a Split Tunnel
Configuration file in your environment:
| Split Tunnel By... | | Configured on GlobalProtect Gateway | Hosted on a Web Server |
|
Access Route
|
Include
| 1000 | 1000 |
|
Application
|
Include
| 200 | 200 |