<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS Fall Back is not working in GP 5.2.x Series in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-fall-back-is-not-working-in-gp-5-2-x-series/m-p/440190#M1869</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using GP-5.2.6 with split tunnel, When ever the tunnel configured DNS not resolving a hostname, The traffic is not falling back to local DNS server configured in physical adaptor. Actually this is not working in all 5.2.x series.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the same scenario working in GP-5.1.8(5.1.x). Palo Alto has introduce split-DNS feature from 5.2 series, Is it anything&amp;nbsp;related with this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Oct 2021 04:21:57 GMT</pubDate>
    <dc:creator>SubaMuthuram</dc:creator>
    <dc:date>2021-10-12T04:21:57Z</dc:date>
    <item>
      <title>DNS Fall Back is not working in GP 5.2.x Series</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-fall-back-is-not-working-in-gp-5-2-x-series/m-p/440190#M1869</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using GP-5.2.6 with split tunnel, When ever the tunnel configured DNS not resolving a hostname, The traffic is not falling back to local DNS server configured in physical adaptor. Actually this is not working in all 5.2.x series.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the same scenario working in GP-5.1.8(5.1.x). Palo Alto has introduce split-DNS feature from 5.2 series, Is it anything&amp;nbsp;related with this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 04:21:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-fall-back-is-not-working-in-gp-5-2-x-series/m-p/440190#M1869</guid>
      <dc:creator>SubaMuthuram</dc:creator>
      <dc:date>2021-10-12T04:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Fall Back is not working in GP 5.2.x Series</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-fall-back-is-not-working-in-gp-5-2-x-series/m-p/441368#M1889</link>
      <description>&lt;P&gt;You can test it on test users as it could be related for domains that are added to not enter the split tunnel:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/define-the-globalprotect-app-configurations.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/define-the-globalprotect-app-configurations.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-released-in-gp-app/split-dns" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-released-in-gp-app/split-dns&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also see this option "&lt;SPAN&gt;Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)&lt;/SPAN&gt;" as it can also be related to your issue to test changing it for couple of test users that you made specific portal app config to be assigned based on AD user/group:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/customize-the-globalprotect-app.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-portals/define-the-globalprotect-client-authentication-configurations/customize-the-globalprotect-app.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if needed upgrade to the latest globalprotect version.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 12:28:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-fall-back-is-not-working-in-gp-5-2-x-series/m-p/441368#M1889</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-10-17T12:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Fall Back is not working in GP 5.2.x Series</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-fall-back-is-not-working-in-gp-5-2-x-series/m-p/441452#M1898</link>
      <description>&lt;P&gt;Hi Nikolay,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already Did, "&lt;SPAN&gt;Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)&lt;/SPAN&gt;&lt;SPAN&gt;" without this option in GP 5.1.x the DNS fall back to local DNS, But in 5.2.x it is not. But I enable&amp;nbsp;"Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)". It is working fine.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 01:41:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-fall-back-is-not-working-in-gp-5-2-x-series/m-p/441452#M1898</guid>
      <dc:creator>SubaMuthuram</dc:creator>
      <dc:date>2021-10-18T01:41:44Z</dc:date>
    </item>
  </channel>
</rss>

