The following figure shows a deployment using an on-premise or
virtual GlobalProtect gateway along with Explicit Proxy. GlobalProtect
routes the traffic using the GlobalProtect client to the Palo Alto
Networks next-generation firewall. To configure this deployment,
you create a
split tunnel configuration
in GlobalProtect, allowing private apps to be secured with GlobalProtect
and public apps to be secured with Explicit Proxy. When configuration is
complete, mobile users connect to the private apps in your organization’s
data center using GlobalProtect and connect to private internet-based
apps using Explicit Proxy.