<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple DHCP Leases with Global Protect in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-dhcp-leases-with-global-protect/m-p/1223297#M6565</link>
    <description>&lt;P&gt;The clients updating their DNS Information themselves via their Kerberos ticket is something that's come up as a possible solution. Meant to have this in my original post but we are using IPControl for our DNS/DHCP server which is a bind server. I don't personally administer that side of the world but apparently it's not the easier application to deal with.&lt;/P&gt;</description>
    <pubDate>Sun, 09 Mar 2025 14:22:16 GMT</pubDate>
    <dc:creator>B.Jones279846</dc:creator>
    <dc:date>2025-03-09T14:22:16Z</dc:date>
    <item>
      <title>Multiple DHCP Leases with Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-dhcp-leases-with-global-protect/m-p/1223274#M6562</link>
      <description>&lt;P&gt;Environment: panos 11.2.4 h5, GP 6.3.2-525, New customer/configuration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are running into an issue where a GP user that logs in from their home, gets a DHCP/dns record tied to the GP MacAddress via our internal DHCP/dns Server in the expected subnet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That all works. If they come into the office and connect to the internal network they get a new DHCP tied to their physical MacAddress but because the old lease is still out there in the GP Subnet, reverse DNS cant be updated. They still get the IP and can browse out through the network but nothing can connect back to them via dns name until the other lease runs out and the physical MacAddress lease reattempts to record itself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue can happen in reverse as well. User has their physical MacAddress registered internally then goes home and logs in via GP and dns cant register the GP MacAddress because the machine is tied to another lease already under a different Mac.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As we are new to palo and new to GP i'm not sure if i'm missing something in the config or if this is just how it works and i'd need to have the leases set really low or work something else out.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Mar 2025 17:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-dhcp-leases-with-global-protect/m-p/1223274#M6562</guid>
      <dc:creator>B.Jones279846</dc:creator>
      <dc:date>2025-03-08T17:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple DHCP Leases with Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-dhcp-leases-with-global-protect/m-p/1223292#M6564</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/498325685"&gt;@B.Jones279846&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This doesn't really have anything to do with the GlobalProtect configuration itself, but instead the DNS server that you are using. There's a number of things on the DNS server that can help out with this like integration with Active Directory, dynamic updates being properly enabled, and ensuring that you have aging and scavenging setup properly. When GlobalProtect connects the DHCP client service should be sending an update about the change of address infromation, but you can also change how often a client is setup to update its registration through the DefaultRegistrationRefreshInterval registry.&lt;/P&gt;
&lt;P&gt;As long as the DHCP server has dynamic updates enabled you really shouldn't be seeing any issue here on a regular basis. Even when everything is setup properly there's still instances where you'll see stale entries, but it should be an infrequent occurrence where it sounds like you're running into this on a regular basis. If you're not the one managing the DHCP and DNS infrastructure, I would recommend engaging that individual/team and really have them validating their side of things. With a proper configuration, clients can update their DNS information themselves even if you were using an internal IP pool for GlobalProtect instead of routing them through to your DHCP server(s). &lt;/P&gt;</description>
      <pubDate>Sun, 09 Mar 2025 06:29:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-dhcp-leases-with-global-protect/m-p/1223292#M6564</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-03-09T06:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple DHCP Leases with Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-dhcp-leases-with-global-protect/m-p/1223297#M6565</link>
      <description>&lt;P&gt;The clients updating their DNS Information themselves via their Kerberos ticket is something that's come up as a possible solution. Meant to have this in my original post but we are using IPControl for our DNS/DHCP server which is a bind server. I don't personally administer that side of the world but apparently it's not the easier application to deal with.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Mar 2025 14:22:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-dhcp-leases-with-global-protect/m-p/1223297#M6565</guid>
      <dc:creator>B.Jones279846</dc:creator>
      <dc:date>2025-03-09T14:22:16Z</dc:date>
    </item>
  </channel>
</rss>

