Windows OS Batch Script Examples

You can configure the GlobalProtect agent to initiate and run a script for any or all of the following events: before and after establishing the tunnel, and before disconnecting the tunnel. To run the script at a particular event, reference the batch script from a command registry entry for that event. The following examples show scripts you can run on Windows systems at pre-connect, post-connect, and pre-disconnect events:

Example: Exclude Traffic from the VPN Tunnel on Windows Endpoints

To exclude traffic from the VPN tunnel after establishing the VPN connection, reference the following script from a command registry entry for a post-vpn-connect event. This enables you to selectively exclude routes and to send all other traffic through the VPN tunnel.
As a best practice, delete any exclude network routes that were previously added before adding the new exclude routes. In most cases, when a user moves between networks (such as when switching between Wi-Fi and a local network) the old network routes are automatically deleted. In the event that the old network routes persist, following this best practice ensures that traffic destined for the exclude routes will go through the gateway of the new network instead of the gateway of the old network.
For a script that you can copy and paste, go here.
@echo off 
REM Run this script (route_exclude) post-vpn-connect. 
REM Add exclude routes. This allows traffic to these
network and hosts to go directly and not use the tunnel. 
REM Syntax: route_exclude <network1> <mask1> <network2>
<mask2> ...<networkN> <maskN> 
REM Example-1: route_exclude 
REM Example-2: route_exclude 
REM Example-3: route_exclude 
REM Initialize 'DefaultGateway' 
set "DefaultGateway=" 
REM Use the route print command and find the DefaultGateway
on the endpoint 
@For /f "tokens=3" %%* in ( 
   'route.exe print ^|findstr "\<\>"' 
   ) Do if not defined DefaultGateway Set "DefaultGateway=%%*" 
REM Use the route add command to add the exclude routes 
if "%1" =="" goto end 
route delete %1 
route add %1 mask %2 %DefaultGateway% 
goto add_route 

Example: Mount a Network Share on Windows Endpoints

To mount a network share after establishing a VPN connection, reference the following script from a command registry entry for a post-vpn-connect event:
@echo off 
REM Mount filer1 to Z: drive 
net use Z: \\filer1.mycompany.local\share /user:mycompany\user1

Related Documentation