Configure Forwarding Profiles to Replace GlobalProtect Split Tunnel Settings (Panorama)
Focus
Focus
Prisma Agent

Configure Forwarding Profiles to Replace GlobalProtect Split Tunnel Settings (Panorama)

Table of Contents

Configure Forwarding Profiles to Replace GlobalProtect Split Tunnel Settings (Panorama)

Replicate your GlobalProtect split tunnel exclusions by creating forwarding profiles and Destination profiles for the Prisma Agent on a Panorama-managed tenant.
Forwarding profiles replace GlobalProtect's split tunnel configuration, providing granular traffic steering control.
Forwarding profiles contain a set of rules that define how to direct traffic based on various criteria. After you set up the forwarding profiles, you can assign them to users or user groups in the Agent Settings page. These forwarding profiles enable you to create a comprehensive traffic management strategy tailored to your organization's needs. Forwarding profiles provide granular control over your network traffic, ensuring consistent security policies and optimal routing based on traffic characteristics.
  1. Create Forwarding Profiles
    1. From Strata Cloud Manager, select ConfigurationPrisma Access AgentForwarding ProfilesAdd Forwarding Profile.
    2. Add a meaningful Name for the forwarding profile and click Create.
    3. Assign the forwarding profile to your users.
      1. Return to Agent Settings.
      2. Select the forwarding profile in the agent configuration.
  2. Review the Default Forwarding Rules
    By default, all forwarding profiles contain the following rules:
    • Video Streaming — Sends all network traffic from the video streaming apps defined in the Video Traffic destination directly to the internet (no tunnel). The following image shows the FQDNs in the predefined Video Traffic destination (Forwarding ProfilesDestinationsVideo Traffic).
    • Default — Sends all DNS and network traffic through the tunnel. Any new rules that you add are placed above the default rule. You cannot delete, disable or move the default forwarding rule except to change its Connectivity setting.
  3. Configure Traffic Rules — Migrate Split Tunnel Settings
    To replicate GlobalProtect's exclude traffic settings:
    1. Create destination profiles under ConfigurationPrisma Access AgentForwarding ProfilesDestinations.
    2. Configure specific domains and IP addresses that should bypass the tunnel. For example:
    3. Within the forwarding profile, create a forwarding rule in the Forwarding Rules section by clicking Add Rule and refer.
    4. Within the forwarding profile, create forwarding rules that reference these destinations with Connectivity set to Direct.
      Traffic matching this rule bypasses the tunnel to Prisma Access.
    5. After you create the rules, place them in the appropriate order.
      Prisma Agent applies traffic forwarding rules from the top down in the forwarding rules table. Therefore, configure the forwarding profile in a top-down manner, such as configuring the most specific rules first and the least specific rules last.
  4. Apply Example Forwarding Rules As Needed
    The following example forwarding profiles contain rules that cover various types of traffic and the respective connectivity verdicts.
    • Scenario A: Always On, full tunnel (Best Available – Fail Open)
      All traffic is sent through the tunnel. If the tunnel is unavailable, traffic falls back to a direct connection. This replicates the GlobalProtect Always On connect method with permissive failover behavior.
      No additional forwarding rules are required. Verify that the Default rule uses the Connectivity type Best Available – Fail Open.
      Rule TypeNameEnabledSource ApplicationUser LocationDestinationConnectivityTraffic Type
      PredefinedVideo StreamingFALSEAnyAnyVideo TrafficDirectNetwork Traffic
      PredefinedDefaultTRUEAnyAnyAnyBest Available - Fail OpenDNS + Network Traffic
    • Scenario B: Always On, full tunnel (Best Available – Fail Safe)
      All traffic is sent through the tunnel. If the tunnel is unavailable, traffic is blocked rather than falling back to a direct connection. This replicates the GlobalProtect Always On connect method with strict failover behavior.
      Change the Default rule Connectivity to Best Available – Fail Safe. No additional rules are required.
      Rule TypeNameEnabledSource ApplicationUser LocationDestinationConnectivityTraffic Type
      PredefinedVideo StreamingFALSEAnyAnyVideo TrafficDirectNetwork Traffic
      PredefinedDefaultTRUEAnyAnyAnyBest Available - Fail SafeDNS + Network Traffic
    • Scenario C: Always On, full tunnel with specific domain exclusions
      All traffic goes through the tunnel except traffic matching specific predefined destination groups, which are sent directly to the internet. Use this scenario to exclude known high-bandwidth destinations such as video streaming services from the tunnel.
      Enable the predefined Video Traffic rule to send all video streaming application traffic directly to the internet. Keep the Default rule Connectivity set to Best Available – Fail Open. To exclude additional destinations, create custom forwarding rules with Direct connectivity referencing Destination profiles that contain the domains or IP addresses to exclude, and place them above the Default rule in the forwarding profile.
      Rule TypeNameEnabledSource ApplicationUser LocationDestinationConnectivityTraffic Type
      PredefinedVideo StreamingTRUEAnyAnyVideo TrafficDirectNetwork Traffic
      PredefinedDefaultTRUEAnyAnyAnyBest Available - Fail OpenDNS + Network Traffic
    • Scenario D: Always On, full tunnel with excluded networks/domains (replicate GlobalProtect Exclude Traffic)
      Specific application traffic and corporate network destinations that were excluded from the GlobalProtect tunnel are sent directly to the internet or routed through the tunnel with Best Available connectivity, while all remaining traffic uses Best Available – Fail Open. Use this scenario to replicate your existing GlobalProtect Exclude Traffic split tunnel settings.
      1. Select Forwarding Profiles SetupDestinations and create Destination profiles for each group of excluded traffic: for example, ADEM FQDNs, Prisma Browser FQDNs, corporate IP subnets, and corporate domains.
      2. In your forwarding profile, add custom forwarding rules that reference these Destination profiles with the appropriate connectivity types:
        • Application-based exclusions (such as ADEM, Cortex XDR, Prisma Browser): Set Connectivity to Direct.
        • Corporate IP and FQDN destinations that should still go through the tunnel when off-network: Set Connectivity to Best Available – Fail Safe.
      3. Keep the Default rule set to Best Available – Fail Open so all other traffic uses the tunnel with a direct fallback.
      4. Place the custom rules above the Default rule, with the most specific rules at the top.
      Rule TypeNameEnabledSource ApplicationUser LocationDestinationConnectivityTraffic Type
      CustomADEM Access DirectTRUEADEMAnyADEM FQDN DestinationsDirectNetwork Traffic
      CustomPB Access DirectTRUEAnyAnyPB FQDN DestinationsDirectNetwork Traffic
      CustomCortex Access DirectTRUECortex XDRAnyAnyDirectNetwork Traffic
      CustomOff Network-Corp IP TrafficTRUEAnyAnyNetwork TrafficBest Available - Fail SafeNetwork Traffic
      CustomOff Network Corp FQDN TrafficTRUEAnyAnyCorp DomainBest Available - Fail SafeDNS + Network Traffic
      PredefinedVideo StreamingFALSEAnyAnyVideo TrafficDirectNetwork Traffic
      PredefinedDefaultTRUEAnyAnyAnyBest Available - Fail OpenDNS + Network Traffic
    • Scenario E: All traffic Direct except private application traffic through the tunnel
      All traffic goes directly to the internet by default. Only specific private application traffic is routed through the tunnel. Use this scenario when most traffic should bypass Prisma Access and only designated internal applications require secure tunnel access.
      1. Add custom forwarding rules for application-based and destination-based traffic that must go directly to the internet (such as ADEM, Prisma Browser, and Cortex XDR traffic), with Connectivity set to Direct.
      2. Add custom rules for corporate IP and FQDN destinations that should reach the tunnel when off-network, with Connectivity set to Best Available – Fail Safe.
      3. Change the Default rule connectivity to Direct so all unmatched traffic bypasses the tunnel.
      4. Place the private application and corporate destination rules above the Default rule.
      Rule TypeNameEnabledSource ApplicationUser LocationDestinationConnectivityTraffic Type
      CustomADEM Access DirectTRUEADEMAnyADEM FQDN DestinationsDirectNetwork Traffic
      CustomPB Access DirectTRUEAnyAnyPB FQDN DestinationsDirectNetwork Traffic
      CustomCortex Access DirectTRUECortex XDRAnyAnyDirectNetwork Traffic
      CustomOff Network-Corp IP TrafficTRUEAnyAnyNetwork TrafficBest Available - Fail SafeNetwork Traffic
      CustomOff Network Corp FQDN TrafficTRUEAnyAnyCorp DomainBest Available - Fail SafeDNS + Network Traffic
      PredefinedVideo StreamingFALSEAnyAnyVideo TrafficDirectNetwork Traffic
      PredefinedDefaultTRUEAnyAnyAnyDirectDNS + Network Traffic
    • Scenario F: Source-application exclusions from the tunnel (except private apps and Default rule traffic)
      Traffic from specific source applications—such as Prisma Browser, ADEM, and Cortex XDR—is sent directly to the internet. Corporate IP and FQDN destinations go through the tunnel when off-network. All remaining traffic matches the Default rule. Use this scenario when you want to steer traffic based on the originating application rather than by destination.
      1. Add custom forwarding rules for each application whose traffic should bypass the tunnel:
        • ADEM traffic to ADEM FQDN Destinations: Direct
        • Prisma Browser traffic to Prisma Browser FQDN Destinations: Direct
        • Cortex XDR traffic to any destination: Direct
        • All Prisma Browser traffic (catch-all): Direct
      2. Add custom rules for corporate IP address and FQDN destinations with Connectivity set to Best Available – Fail Safe.
      3. Keep the Default rule set to Best Available – Fail Open so all remaining traffic uses the tunnel with a direct fallback.
      4. Place all custom rules above the Default rule, with the most specific rules first.
      Rule TypeNameEnabledSource ApplicationUser LocationDestinationConnectivityTraffic Type
      CustomADEM Access DirectTRUEADEMAnyADEM FQDN DestinationsDirectNetwork Traffic
      CustomPB Access DirectTRUEAnyAnyPB FQDN DestinationsDirectNetwork Traffic
      CustomCortex Access DirectTRUECortex XDRAnyAnyDirectNetwork Traffic
      CustomOff Network-Corp IP TrafficTRUEAnyAnyNetwork TrafficBest Available - Fail SafeNetwork Traffic
      CustomOff Network Corp FQDN TrafficTRUEAnyAnyCorp DomainBest Available - Fail SafeDNS + Network Traffic
      CustomAll traffic DirectTRUEPrisma BrowserAnyAnyDirectNetwork Traffic
      PredefinedVideo StreamingFALSEAnyAnyVideo TrafficDirectNetwork Traffic
      PredefinedDefaultTRUEAnyAnyAnyBest Available - Fail OpenDNS + Network Traffic
    When the tunnel is not established as part of Internal Host Detection, the Forwarding Profile rules will continue to route traffic based on Connectivity types such as DIRECT, BLOCK, and BYPASS. The recommended best practice is to use the predefined Default rule at the bottom with connectivity set as either DIRECT or Best Available - Fail Open (fallback as Direct) to avoid any traffic blackholing.
  5. Configure Traffic Enforcement Options
    Within each forwarding profile, the following traffic enforcement options are available:
    Block Non-TCP and Non-UDP based traffic when connected to tunnel — The agent blocks all non-TCP and non-UDP traffic including ICMP, GRE, IGMP, and IPSec protocols while connected to the tunnel. TCP and UDP traffic steering will adhere to the forwarding rules configured above. The default is disabled.
    For in-depth info on setting up Traffic Steering Rules and Enforcement using Forwarding Profiles, see Set Up Forwarding Profiles to Manage Agent Traffic.
  6. Review Forwarding Profile Considerations
    DNS (Windows only) — When configuring forwarding profiles for Prisma Agent on Windows endpoints, there are two specific behaviors to consider. These behaviors require adjustments to your traffic forwarding rules to ensure proper traffic routing and policy enforcement. See Windows Forwarding Profiles Considerations.