Prisma Access
Configure Split Tunneling for Privileged Remote Access Traffic
Table of Contents
Expand All
|
Collapse All
Prisma Access Docs
-
-
- Prisma Access China
- 4.0 & Later
- 3.2 Preferred and Innovation
- 3.1 Preferred and Innovation
- 3.0 Preferred and Innovation
- 2.2 Preferred
-
-
-
- 5.2 Preferred and Innovation
- 5.1 Preferred and Innovation
- 5.0 Preferred and Innovation
- 4.2 Preferred
- 4.1 Preferred
- 4.0 Preferred
- 3.2 Preferred and Innovation
- 3.1 Preferred and Innovation
- 3.0 Preferred and Innovation
- 2.2 Preferred
Configure Split Tunneling for Privileged Remote Access Traffic
For users trying to access Privileged Remote Access from managed devices, configure split
tunneling for the PRA domain to help improve performance.
Privileged Remote Access (PRA) users will typically access the PRA
portal from unmanaged devices where the GlobalProtect agent isn't installed. In use
cases where your users access PRA from managed devices, it's
recommended to configure split-tunneling for the PRA domain to
help improve performance.
You can configure split tunnel settings according to the Prisma Access management
interface you're using.
Configure Split Tunneling for Privileged Remote Access Traffic (Strata Cloud Manager)
For managed devices, you can configure split tunneling for Privileged Remote Access traffic
on Strata Cloud Manager to help improve PRA performance.
In use cases where PRA is being accessed from managed devices
that have GlobalProtect installed, configure split tunneling for the PRA domain to help improve performance.
- From Strata Cloud Manager, go to WorkflowsPrisma Access SetupAccess AgentGlobalProtect App.In the Tunnel Settings section, select Default.Configure split tunnel settings to exclude traffic based on the destination domain.
- In the Exclude Traffic section, click Add Domain.Enter the Domain you're using for PRA. This can be the default PRA domain (*.panwpra.com) or your custom PRA domain.Save your domain.Save your tunnel settings and Push Config.
Configure Split Tunneling for Privileged Remote Access Traffic (Panorama)
For managed devices, you can configure split tunneling for Privileged Remote Access traffic on Panorama to help improve PRA performance.In use cases where your users access PRA from managed devices that have GlobalProtect installed, configure split tunneling for the PRA domain to help improve performance.- In the Cloud Services plugin, select NetworkGlobalProtectGateways<GlobalProtect_External_Gateway>.Configure split tunnel settings for PRA based on the destination domain. These settings are assigned to the virtual network adapter on the endpoint when the tunnel is established with the gateway.
- In the GlobalProtect Gateway Configuration dialog, select AgentClient SettingsDefault.In the Configs dialog, select Split TunnelDomain and ApplicationExclude Domain.Add the PRA domain that you want to exclude from the tunnel using the destination domain. This can be the default PRA domain (*.panwpra.com) or your custom PRA domain.Click OK to save the split tunnel settings and Commit your changes.