|
Add routes to exclude from the VPN tunnel.
These routes are sent through the physical adapter on endpoints
rather than through the virtual adapter (the tunnel).
You can define the routes you send through the VPN tunnel as routes
you include in the tunnel, routes you exclude from the tunnel, or a
combination of both. For example, you can set up split tunneling to
allow remote users to access the internet without going through the
VPN tunnel. Excluded routes should be more specific than the
included routes to avoid excluding more traffic than you intend to
exclude.
You can exclude IPv6 or IPv4 subnets. The firewall supports up to 100
exclude access routes in a split tunnel gateway configuration.
Unless combined with GlobalProtect app 4.1 and later releases, up to
200 exclude access routes can be used. You cannot exclude access
routes for endpoints running Android on Chromebooks. Only IPv4
routes are supported on Chromebooks.
If you do not enable split tunneling, every request is routed through
the tunnel (no split tunneling). In this case, each internet request
passes through the firewall and then out to the network. This method
can prevent the possibility of an external party accessing user
endpoints and gaining access to the internal network (with a user
endpoint acting as a bridge).
|