<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect Split tunnel dns resoleving problems in MacOS configured with Private Relay in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnel-dns-resoleving-problems-in-macos/m-p/594200#M5643</link>
    <description>&lt;P&gt;hey,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i recently got an issue with a user that got a new MacOs laptop that had an issue with connecting to internal resources, looks like Chrome and Ping and also other client application would not work because the dns is not resolved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there is an Apple feature called "Private Relay" it basically acts like a "vpn" that routes traffic through some gateway so the ISP etc wont see the user's traffic. that was probably collide with the GP client.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if this feature is enabled on the user's intune this will be enabled by default on a new device that is linked to this user's intune.&lt;/P&gt;
&lt;P&gt;this feature can be disabled on the user MacOS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DorMarcovitch_0-1723010525131.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61368i1CA6B90E26484CD3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DorMarcovitch_0-1723010525131.png" alt="DorMarcovitch_0-1723010525131.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.apple.com/en-il/102602" target="_blank"&gt;https://support.apple.com/en-il/102602&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Aug 2024 06:03:04 GMT</pubDate>
    <dc:creator>DorMarcovitch</dc:creator>
    <dc:date>2024-08-07T06:03:04Z</dc:date>
    <item>
      <title>Global Protect Split tunnel dns resoleving problems in MacOS configured with Private Relay</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnel-dns-resoleving-problems-in-macos/m-p/594200#M5643</link>
      <description>&lt;P&gt;hey,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i recently got an issue with a user that got a new MacOs laptop that had an issue with connecting to internal resources, looks like Chrome and Ping and also other client application would not work because the dns is not resolved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there is an Apple feature called "Private Relay" it basically acts like a "vpn" that routes traffic through some gateway so the ISP etc wont see the user's traffic. that was probably collide with the GP client.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if this feature is enabled on the user's intune this will be enabled by default on a new device that is linked to this user's intune.&lt;/P&gt;
&lt;P&gt;this feature can be disabled on the user MacOS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DorMarcovitch_0-1723010525131.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61368i1CA6B90E26484CD3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DorMarcovitch_0-1723010525131.png" alt="DorMarcovitch_0-1723010525131.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.apple.com/en-il/102602" target="_blank"&gt;https://support.apple.com/en-il/102602&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 06:03:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnel-dns-resoleving-problems-in-macos/m-p/594200#M5643</guid>
      <dc:creator>DorMarcovitch</dc:creator>
      <dc:date>2024-08-07T06:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Split tunnel dns resoleving problems in MacOS configured with Private Relay</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnel-dns-resoleving-problems-in-macos/m-p/594504#M5650</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/218161"&gt;@DorMarcovitch&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for sharing this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that you can also prevent the use of private relay on network level by blocking the DNS resolution for these two FQDNs&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;mask.icloud.com
mask-h2.icloud.com&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;As described by Apple documentation - &lt;A href="https://developer.apple.com/icloud/prepare-your-network-for-icloud-private-relay/" target="_blank"&gt;https://developer.apple.com/icloud/prepare-your-network-for-icloud-private-relay/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2024 13:52:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-split-tunnel-dns-resoleving-problems-in-macos/m-p/594504#M5650</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2024-08-09T13:52:00Z</dc:date>
    </item>
  </channel>
</rss>

