<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS lookup takes a long time with GP in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/411066#M1392</link>
    <description>&lt;P&gt;The issue was resolved as follows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cause: Querying queries to all NICs that have DNS Lookup enabled, so lookup time increases while waiting for results from VPN NIC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Resolution: Register in paloalto registry to run batch script after VPN authentication.&lt;BR /&gt;The script content deletes the DNS Server settings of the VPN NIC to set DNS queries to use only the primary NIC of the PC.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jun 2021 02:20:04 GMT</pubDate>
    <dc:creator>Jinnypt</dc:creator>
    <dc:date>2021-06-04T02:20:04Z</dc:date>
    <item>
      <title>DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/400734#M1184</link>
      <description>&lt;P&gt;GlobalProtect Gateway is being used, and all traffic is being routed to the firewall except for some network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DNS lookup takes a long time when I input the domain (website which not in the PC DNS table) that the browser accesses first while connected to a VPN&lt;/P&gt;&lt;P&gt;- DNS Lookup time takes about&amp;nbsp;5-10 seconds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The DNS server is using an internal server, and the network is belong to split tunneling exceptions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am wondering why DNS lookup processing is delayed.&lt;/P&gt;&lt;P&gt;Or is it correct that DNS lookup takes a long time during VPN connection?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 06:39:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/400734#M1184</guid>
      <dc:creator>Jinnypt</dc:creator>
      <dc:date>2021-04-21T06:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/400936#M1197</link>
      <description>&lt;P&gt;Do you also have GP app setting to split tunnel DNS and what GP client version are you using?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 14:41:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/400936#M1197</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-04-21T14:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401040#M1201</link>
      <description>&lt;P&gt;GP Client version is 5.2.6-87(latest)&lt;/P&gt;&lt;P&gt;And Split-Tunnel Option is "Both Network Traffic and DNS" from GP-Portal-Agent-Config-App&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 00:11:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401040#M1201</guid>
      <dc:creator>Jinnypt</dc:creator>
      <dc:date>2021-04-22T00:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401053#M1203</link>
      <description>&lt;P&gt;Try removing that setting from the agent to see if that is the issue.&lt;/P&gt;&lt;P&gt;are you testing with a dns lookup tool/app or in the browser itself.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 05:10:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401053#M1203</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-04-22T05:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401056#M1204</link>
      <description>&lt;P&gt;That option was initially "Network Traffic Only", but DNS Lookup took a long time, so I switched to "Both Network Traffic and DNS".&lt;/P&gt;&lt;P&gt;The test is being done on my PC, and the DNS cache table is checked with the "ipconfig /displaydns" command.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 05:15:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401056#M1204</guid>
      <dc:creator>Jinnypt</dc:creator>
      <dc:date>2021-04-22T05:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401119#M1205</link>
      <description>&lt;P&gt;are you adding the url in nslookup or just adding it in the browser&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 07:00:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401119#M1205</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-04-22T07:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401186#M1209</link>
      <description>&lt;P&gt;I do not add additional URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For my case, the DNS server belongs to the split tunneling exception, so the dns server is left blank in the gateway-agent-network service configuration.&lt;BR /&gt;So DNS uses PC's default DNS settings.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 08:27:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401186#M1209</guid>
      <dc:creator>Jinnypt</dc:creator>
      <dc:date>2021-04-22T08:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401213#M1210</link>
      <description>&lt;P&gt;This does not happen when i do the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 1 domain in "Domain Split Tunnel" and have left my DNS servers blank in the gateway services and have set both network and DNS in portal app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as soon as i browse to the website that is in my split tunnel it resolves instantly with my local DNS.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 09:14:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401213#M1210</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-04-22T09:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401216#M1211</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1619082909059.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32395iBD456EFA0E2A44D9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1619082909059.jpeg" alt="MickBall_0-1619082909059.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_1-1619083254881.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32396i26E5A2DD96712D13/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_1-1619083254881.png" alt="MickBall_1-1619083254881.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 09:21:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401216#M1211</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-04-22T09:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401469#M1225</link>
      <description>&lt;P&gt;As you said, I call the internal DNS server and get the IP right away.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;However, the browser notificate that the host is being searched, and the DNS lookup time is very long.&lt;/P&gt;&lt;P&gt;Looking through wireshark during this time, vpc nic are not communicating with the target website.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The chrome/edge browser issue are the same. It doesn't appear to be a browser issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In summary&lt;/P&gt;&lt;P&gt;1. vpn connect&lt;/P&gt;&lt;P&gt;2. connect to website domain from browser, connect to internal DNS server from pc default nic&lt;/P&gt;&lt;P&gt;3. get IP from internal DNS server (There seems to be no problem so far.)&lt;/P&gt;&lt;P&gt;4. (vpn nic) The browser is looking for the host, and this is taking a long time.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 08:26:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401469#M1225</guid>
      <dc:creator>Jinnypt</dc:creator>
      <dc:date>2021-04-23T08:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401478#M1226</link>
      <description>&lt;P&gt;If you are using wireshark then what happens to the packet captures when the DNS replies in summary 3.&amp;nbsp; does it pause or do you see connection attempts to the correct address.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 08:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401478#M1226</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-04-23T08:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401769#M1230</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/32476i7E1FAF665C59586E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This packet is a capture of DNS query with nslookup command on PC's origin NIC(not VPN NIC).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The first second query is the result of a query against the DNS suffix, and the last is the correct query result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Further confirmation&lt;/P&gt;&lt;P&gt;The VPN NIC also sends query packets to the internal DNS.&lt;BR /&gt;(Packets come into the Paloalto firewall. It doesn't seem to apply to the split-tunneling exception.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Information&lt;BR /&gt;1. Not all queries are requested, but only a few packets request duplicate DNS queries using Origin NICs and VPN NICs.&lt;BR /&gt;2. Packets requested by the VPN NIC only have a request and no response.&lt;BR /&gt;3. If the DNS lookup in the web browser takes a long time and the web page is displayed normally, the query packet is only sent to the PC NIC, and the packet is not generated from the VPN NIC.&lt;/P&gt;&lt;P&gt;It seems to be because the DNS query is being called concurrently with the PC NIC and VPN NIC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 01:54:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/401769#M1230</guid>
      <dc:creator>Jinnypt</dc:creator>
      <dc:date>2021-04-26T01:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: DNS lookup takes a long time with GP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/411066#M1392</link>
      <description>&lt;P&gt;The issue was resolved as follows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cause: Querying queries to all NICs that have DNS Lookup enabled, so lookup time increases while waiting for results from VPN NIC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Resolution: Register in paloalto registry to run batch script after VPN authentication.&lt;BR /&gt;The script content deletes the DNS Server settings of the VPN NIC to set DNS queries to use only the primary NIC of the PC.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 02:20:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-lookup-takes-a-long-time-with-gp/m-p/411066#M1392</guid>
      <dc:creator>Jinnypt</dc:creator>
      <dc:date>2021-06-04T02:20:04Z</dc:date>
    </item>
  </channel>
</rss>

