Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignEasy

A company is planning to deploy GlobalProtect for remote users, requiring full tunnel VPN connectivity and user-based policy enforcement. The design specifies that all remote user traffic must be inspected by the corporate firewall, regardless of destination. Which GlobalProtect gateway configuration type ensures this requirement is met?

  1. ASplit Tunnel
  2. BProxy Tunnel
  3. CNo Tunnel
  4. DFull Tunnel
Show answer & explanation

Correct answer: D. Full Tunnel

A full tunnel GlobalProtect configuration ensures that all traffic from the remote user's device, regardless of its destination, is routed through the GlobalProtect VPN tunnel to the corporate firewall for inspection and policy enforcement.

Why the other options are wrong

  • A. Split tunnel routes only corporate-bound traffic through the VPN, allowing internet traffic to bypass the corporate firewall.
  • B. Proxy tunnel is not a standard GlobalProtect gateway tunnel type; GlobalProtect uses IPSec/SSL for its tunnels.
  • C. No tunnel means no VPN connection is established, rendering the remote user unprotected by the corporate firewall.

GlobalProtect Full Tunnel

A VPN configuration where all network traffic from a remote client, including internet-bound traffic, is routed through the GlobalProtect VPN tunnel to the corporate firewall for security inspection and policy enforcement.

  • All traffic through VPN
  • Centralized security for remote users
  • Ensures full visibility and control

Memory trick: Tunnel vision for your remote security.

More Plan and Design questions