openconnect-8.08 CentOS 7.6 protocol=gp This was as you say, plug and play when I ran the build and install. Functioned perfectly with my dual factor cert+password authentication. my split tunnels (at that time) were all added to the route table and my /etc/resolv.conf was updated to include the domain. I was thrilled because PaloAlto wanted $15k for linux licensing of the GP client - just way too much $$$ for the couple of us on linux. more access = more split tunnels, and it seems I have hit a 16 route max. I reviewed the /etc/vpnc/vpnc-script, but don’t really see a facility to increase the number of routes in the split. On my macbook, I am running the paloalto native client and this is properly adding the 19 splits to the route table. I am able to manually add a route on the openconnect CentOS host, and this functions as expected. is there a “max split” value I can adjust? thank you for your attention - grant _______________________________________________ openconnect-devel mailing list openconnect-devel@xxxxxxxxxxxxxxxxxxx http://lists.infradead.org/mailman/listinfo/openconnect-devel