Vigyata.AI
Is this your channel?

#paloaltofirewalltraining | Day 48 | What is split tunnel and what is full Tunnel ? how it works.

479 views· 14 likes· 16:26· Feb 13, 2026

🛍️ Products Mentioned (2)

Join this channel to get access to perks: https://www.youtube.com/channel/UCBujQdd5rBRg7n70vy7YmAQ/join Please checkout my new video on How to Configure Global Protect VPN with AD Authentication. If you like this video give it a thumps up and subscribe my channel for more video. Have any question put it on comment section Recommend Video #paloaltofirewalltraining | Day 44 | How to Configure Global Protect VPN in Palo Alto https://youtu.be/8imTv9xYlJY #paloaltofirewalltraining | Day 43 | Global Protect SSL VPN in Palo Alto | Concept https://youtu.be/0ca7xsa1K_w Recommend Link (Playlist for EVE-NG LAB Setup) https://www.youtube.com/playlist?list=PLaUiizP3D7fPMmUQqS5QKX_FVSoMP68Z5 Palo Alto Certification information URL: https://www.paloaltonetworks.com/services/education For Palo Alto Documentation https://docs.paloaltonetworks.com/ Please follow me Instagram : https://www.instagram.com/bikashtech Twitter : https://twitter.com/Bikashshaw82 E-mail ID : bikashshaw261@gmail.com #Paloaltotraining ##bikashtech #paloaltofirewalltraining #paloaltonetworks #paloaltotraining #paloaltovpn #vpn #ike #ipsec

About This Video

Hello friends, welcome back—Day 48 of my PCNSA series. In this video I explained one of the most important GlobalProtect concepts you will face in real projects: split tunnel vs full tunnel, and how exactly it works when the user connects from home to the portal and then builds the tunnel to the gateway. I first covered the concept using a simple topology, then I moved to the lab so you can clearly see how the client routing changes based on what we configure on the gateway. In full tunnel, I showed that all traffic (including internet traffic) is forced into the VPN tunnel, and the gateway/firewall takes the decision based on policy—so you get maximum control. But the disadvantage is bandwidth: if you have 500 or 1000 users, you need strong bandwidth and capacity because everything is hairpinned through the gateway. In split tunnel, I configured an include network (example: 192.168.20.0/24) so only that destination traffic goes through the tunnel, and the rest goes directly to the user’s local internet via the NIC—less control, but you can support more users with less bandwidth. In the lab, I also showed you where to verify it on the client side (GlobalProtect troubleshooting > advanced > network configuration > routing table) and where to configure it on the gateway (Client Settings > GP Client > Split Tunnel).

Frequently Asked Questions

🎬 More from Bikash's Tech