The following figure shows a deployment using a GlobalProtect gateway along with Explicit Proxy.
GlobalProtect routes the traffic using the GlobalProtect client to the Palo Alto
Networks next-generation firewall. To configure this deployment, you create a
split tunnel configuration in GlobalProtect,
allowing private apps to be secured with GlobalProtect and public apps to be secured
with Explicit Proxy. When configuration is complete, mobile users connect to the private
apps in your organization’s data center using GlobalProtect and connect to private
internet-based apps using Explicit Proxy.