You can use Endpoint
Traffic Policy Enforcement in conjunction with No Direct Access
to Local Network Support to control access to the local network.
The following table shows the traffic behavior and interaction between the
features.
IPv4 and IPv6 Traffic | Endpoint Traffic Policy Enforcement
Enabled No Direct Access to Local Network is Disabled | Endpoint Traffic Policy Enforcement
Enabled No Direct Access to Local Network is Enabled |
| Before the tunnel is established | After the tunnel is established | Before the tunnel is established | After the tunnel is established |
New Incoming Traffic | Traffic is allowed on the local subnet through
the physical adapter. | Local subnet traffic is excluded. Return
traffic from the local subnet will not be dropped on the non-tunnel interface. | Traffic is allowed on the local subnet through
the physical adapter. | Return traffic is dropped on the physical adapter
unless split tunneling is configured to exclude traffic based on
the following conditions: |
New Outgoing Traffic | Traffic is allowed on the local subnet through
the physical adapter. | Traffic is sent through the VPN tunnel unless
the destination IP address matches the following exclusions for
split tunnel: Access routes Destination domains and applications Exclude video streaming traffic Destined for the local subnet that is retrieved at the time
that the tunnel is established
| Traffic is allowed on the local subnet through
the physical adapter. | Traffic is sent through the VPN tunnel unless the
destination IP address matches the following exclusions for split tunnel: |
Existing Traffic | Traffic is allowed on the local subnet through
the physical adapter. | Traffic is terminated unless the destination
IP address matches the following exclusions for split tunnel: Access routes Destination domains 1 (Windows Only) Applications Exclude video streaming traffic Destined for the local subnet that is retrieved at the time
that the tunnel is established.
| Traffic is allowed on the local subnet through
the physical adapter. | Traffic is terminated unless the destination
IP address matches the following exclusions for split tunnel: |
1 The destination domains will not
work for existing connections that started before establishing the
GlobalProtect connection because GlobalProtect does not have visibility
that is associated with the DNS. However, this traffic behavior will
work for existing connections across GlobalProtect reconnections
because GlobalProtect can monitor the DNS during the reconnect interval.