List view
Integrations
Integrations
Applications
Applications
App-specific Handling
App-specific Handling
test
test
Â
Â
GlobalProtect (Palo Alto) Split Tunnel
This page explains how to install the Lumia Agent together with GlobalProtect on the same endpoint. If you’re looking for instructions on how to forward traffic from your Palo Alto gateways to Lumia, see here.
Â
In this step, you will configure GlobalProtect users to use Lumia’s PAC URL.
- Go to NETWORK → GlobalProtect → Agents, then click the relevant GlobalProtect profile.
- Click the Agent tab, select the Client Settings tab, then click the relevant gateway config profile.
- In the Configs window, select the Split Tunnel tab, then select Domain and Application, then add an EXCLUDE DOMAIN for
*.lumiasecurity.com.
- Click OK to close all windows, then commit and push the changes you’ve made.
Â
To verify that the bypass is working, go to https://proxy.lumiasecurity.com
(it’s okay if you receive a 404 windows), then check the certificate:
(it’s okay if you receive a 404 windows), then check the certificate:
You should see the original certificate’s issuer (Let’s Encrypt). If you see your Palo Alto CA instead, it means the split tunnel is NOT applied — please recheck your configuration. If you encounter any issues, feel free to contact us at info@lumia.security.
Â