<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect messes up my DNS route table on MacOS in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-messes-up-my-dns-route-table-on-macos/m-p/407819#M1304</link>
    <description>&lt;P&gt;Here are photos showing the problem.&amp;nbsp; The first is netstat output showing DNS routing when &lt;STRONG&gt;not&lt;/STRONG&gt; connected to GP, everything works as expected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second photos shows what happens to DNS when I connect to GP.&amp;nbsp; 10.0.0.1 is the IP I was given from the IP pool after I connected to GP.&amp;nbsp; &amp;nbsp;DNS obviously doesn't work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-05-19 at 11.22.03 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33960iF263136D234C195C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-05-19 at 11.22.03 AM.png" alt="Screen Shot 2021-05-19 at 11.22.03 AM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-05-19 at 11.21.47 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33961i568C7F69B57BAFC0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-05-19 at 11.21.47 AM.png" alt="Screen Shot 2021-05-19 at 11.21.47 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 19 May 2021 18:39:43 GMT</pubDate>
    <dc:creator>pomologist</dc:creator>
    <dc:date>2021-05-19T18:39:43Z</dc:date>
    <item>
      <title>Global Protect messes up my DNS route table on MacOS</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-messes-up-my-dns-route-table-on-macos/m-p/407807#M1303</link>
      <description>&lt;P&gt;Hello!&amp;nbsp; Quick question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just configured global protect.&amp;nbsp; When I first configured it, I was sending all traffic through the tunnel which wasn't working well.&amp;nbsp; So afterword I set it to allow split tunneling.&amp;nbsp; But here's the problem:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first computer (MacOS) which I enrolled in GP when I was forcing all traffic through the tunnel, now will not connect to the internet when connected to GP, although it does connect to GP assets fine.&amp;nbsp; Another MacOS computer that I enrolled &lt;STRONG&gt;after&lt;/STRONG&gt; I turned on split tunneling, works to access internet perfectly as well as GP assets&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Turns out this is a DNS issue on the first computer. The routing table in the troublesome computer reveals I have duplicate DNS entries in the routing table, two that are pointing to the IP I receive after connecting to the GP gateway (these have priority as they appear first in the list), and two more that are pointing where they should.&amp;nbsp; When I manually update my routing table to remove the DNS entries pointing to the IP I receive after connecting to the GP gateway, all my troubles vanish, I can access the GP assets, as well as my local network.&amp;nbsp; However restarting the computer and reconnecting to GP restores the routing table to the incorrect state.&amp;nbsp; When I disconnect from GP, the rogue DNS entries disappear and my routing table behaves normally allowing normal internet access. When I reconnect to GP, my DNS routing table entries again are messed up. I have deleted the GP app and re-installed, but the incorrect routing table entries are still there.&amp;nbsp; I have flushed my routing table completely, but upon connecting to GP, the rogue DNS entries in the routing table mysteriously appear.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I said above, I enrolled a second computer in GP and it connects normally and doesn't have the rogue DNS entries.&amp;nbsp; It's just the first computer that is messed up now, the one I enrolled when I was still forcing all traffic to use the GP tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Any idea what I can do to fix the problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 18:08:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-messes-up-my-dns-route-table-on-macos/m-p/407807#M1303</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2021-05-19T18:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect messes up my DNS route table on MacOS</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-messes-up-my-dns-route-table-on-macos/m-p/407819#M1304</link>
      <description>&lt;P&gt;Here are photos showing the problem.&amp;nbsp; The first is netstat output showing DNS routing when &lt;STRONG&gt;not&lt;/STRONG&gt; connected to GP, everything works as expected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second photos shows what happens to DNS when I connect to GP.&amp;nbsp; 10.0.0.1 is the IP I was given from the IP pool after I connected to GP.&amp;nbsp; &amp;nbsp;DNS obviously doesn't work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-05-19 at 11.22.03 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33960iF263136D234C195C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-05-19 at 11.22.03 AM.png" alt="Screen Shot 2021-05-19 at 11.22.03 AM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-05-19 at 11.21.47 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33961i568C7F69B57BAFC0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-05-19 at 11.21.47 AM.png" alt="Screen Shot 2021-05-19 at 11.21.47 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 18:39:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-messes-up-my-dns-route-table-on-macos/m-p/407819#M1304</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2021-05-19T18:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect messes up my DNS route table on MacOS</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-messes-up-my-dns-route-table-on-macos/m-p/407920#M1305</link>
      <description>&lt;P&gt;Well it looks like I may be wrong about my above conclusion! The netstat output of the working computer is exactly the same as the output of the non-working computer pictured above!&amp;nbsp; The only other difference between the computers is that the working computer is running MacOS 10.14.6, and the non-working is running MacOS 11.2.3.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone has any pointers, I'd be glad to hear.&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 02:14:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-messes-up-my-dns-route-table-on-macos/m-p/407920#M1305</guid>
      <dc:creator>pomologist</dc:creator>
      <dc:date>2021-05-20T02:14:42Z</dc:date>
    </item>
  </channel>
</rss>

