1. Palo Alto Networks PAN-OS® Administrator's Guide 10.2: In the section on configuring a GlobalProtect gateway
the first step under the "General" tab is to enable Tunnel Mode. The documentation states
"To enable the gateway to establish a VPN tunnel
select Tunnel Mode." This is the prerequisite for all tunneling features. (Reference: PAN-OS Administrator's Guide 10.2 > GlobalProtect > Set Up the GlobalProtect Infrastructure > Configure the GlobalProtect Gateway > General Tab)
2. Palo Alto Networks PAN-OS® Administrator's Guide 10.2: The section on split-tunneling explains the configuration for including or excluding traffic by domain
application
and route. This entire feature set is predicated on the existence of a VPN tunnel
which is established by the gateway operating in Tunnel Mode. (Reference: PAN-OS Administrator's Guide 10.2 > GlobalProtect > Configure Split Tunneling for GlobalProtect)
3. Palo Alto Networks GlobalProtect™ Administrator's Guide 6.1: This guide explicitly links Tunnel Mode to subsequent configurations. "After you enable tunnel mode
you can configure tunnel settings..." The guide then details how to configure the agent
which includes the split-tunnel settings. (Reference: GlobalProtect Administrator's Guide 6.1 > Set Up the GlobalProtect Infrastructure > Configure the GlobalProtect Gateway)