<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS traffic outside of GlobalProtect tunnel in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-traffic-outside-of-globalprotect-tunnel/m-p/615971#M6057</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/145258"&gt;@MikeHinz&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You would expect to see &lt;EM&gt;some &lt;/EM&gt;limited DNS traffic happen outside of the tunnel for things like internal host detection. I'd look at what is actually being sent outside of the tunnel to validate, but you're likely seeing that traffic and it's nothing to worry about. &lt;/P&gt;</description>
    <pubDate>Fri, 01 Nov 2024 20:44:25 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2024-11-01T20:44:25Z</dc:date>
    <item>
      <title>DNS traffic outside of GlobalProtect tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-traffic-outside-of-globalprotect-tunnel/m-p/615854#M6047</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We use Global Protect to connect our employees via VPN to our site. We think we have configured it that way, that the complete traffic is tunneled to our site after establishing the Global Portect connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now we see that unencrypted DNS traffic is visible outside the tunnel. The target adress of that DNS traffic is the IP of our Global Protect gateway (where also the DNS proxy resides).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why is this traffic not encrypted an transported via the Global Protect connection and do you have any suggestion which options could be the reason for that behaviour?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 08:09:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-traffic-outside-of-globalprotect-tunnel/m-p/615854#M6047</guid>
      <dc:creator>MikeHinz</dc:creator>
      <dc:date>2024-10-31T08:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic outside of GlobalProtect tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-traffic-outside-of-globalprotect-tunnel/m-p/615948#M6053</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What does your split tunnel configuration look like? Is it just include 0.0.0.0/0? Under the app configuration of the portal there is also a flag for "Split-Tunnel-Option" what do you have selected for that?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 13:39:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-traffic-outside-of-globalprotect-tunnel/m-p/615948#M6053</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2025-12-16T13:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic outside of GlobalProtect tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-traffic-outside-of-globalprotect-tunnel/m-p/615971#M6057</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/145258"&gt;@MikeHinz&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You would expect to see &lt;EM&gt;some &lt;/EM&gt;limited DNS traffic happen outside of the tunnel for things like internal host detection. I'd look at what is actually being sent outside of the tunnel to validate, but you're likely seeing that traffic and it's nothing to worry about. &lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 20:44:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-traffic-outside-of-globalprotect-tunnel/m-p/615971#M6057</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-11-01T20:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic outside of GlobalProtect tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-traffic-outside-of-globalprotect-tunnel/m-p/615989#M6062</link>
      <description>&lt;P&gt;Check these settings on the App:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-released-in-gp-app/split-dns#:~:text=With%20the%20Split%2DTunnel%20Option,in%20addition%20to%20network%20traffic" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-released-in-gp-app/split-dns#:~:text=With%20the%20Split%2DTunnel%20Option,in%20addition%20to%20network%20traffic&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Split tunnel Options and Resolve all FQDNs. If its still leaking out of Physical interface try different GP version.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 05:40:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-traffic-outside-of-globalprotect-tunnel/m-p/615989#M6062</guid>
      <dc:creator>arusharma</dc:creator>
      <dc:date>2024-11-02T05:40:40Z</dc:date>
    </item>
  </channel>
</rss>

