Unknown GlobalProtect config tags
This is with GlobalProtect (requiring SAML authN and) reporting version 6.1.2-83 and OpenConnect 9.12.
The client reports
Unknown GlobalProtect config tag <exclude-split-tunneling-domain>:
...
Unknown GlobalProtect config tag <exclude-video-redirect>: yes
A trace shows this being sent
...
</exclude-access-routes>
<exclude-split-tunneling-domain>
<member>outlook.office365.com:443</member>
<member>outlook.office.com:443</member>
...
</exclude-split-tunneling-domain>
<exclude-video-redirect>yes</exclude-video-redirect>
<ipsec>
...
If that's not enough info I can send the whole thing, and I have logs from the proprietary client if that's useful. The corresponding configuration items are in the Palo Alto doc.