<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS suffix not applying in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373555#M685</link>
    <description>&lt;P&gt;perhaps GPO takes precedence here..... our suffix is part of the image...&lt;/P&gt;</description>
    <pubDate>Thu, 10 Dec 2020 16:25:01 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2020-12-10T16:25:01Z</dc:date>
    <item>
      <title>DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/367880#M668</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have deployed a GlobalProtect gateway in an office that uses a different domain than our own.&amp;nbsp; To that end, I have added their dns suffix to the gateway but when I connect onto that gateway, the suffix is never appended.&amp;nbsp; I cannot access their domain resources unless I use FQDN.&amp;nbsp; In the logs, I see the config being sent and it does include the DNS suffix so I'm not sure why it won't be appended?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 18:49:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/367880#M668</guid>
      <dc:creator>COlson</dc:creator>
      <dc:date>2020-12-08T18:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373505#M672</link>
      <description>&lt;P&gt;are you applying this suffix in the gateway global config or in the client configuration settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It only seems to work for us if we add it to the global gateway setting for network services,&amp;nbsp; we just seperate with a comma.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 13:17:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373505#M672</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-10T13:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373509#M674</link>
      <description>&lt;P&gt;Also,,,]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure where you are seeing the info sent but the GP logs are showing this...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i add fred.com to gateway settings..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;/dns&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;wins&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;/wins&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;dns-suffix&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;member&amp;gt;fred.com&amp;lt;/member&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;/dns-suffix&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i add fred.com to client settings&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;/dns&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;wins&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;/wins&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;dns-suffix&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;lt;/dns-suffix&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;seems to be not working and dns reverts to local suffix prior to VPN connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 13:34:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373509#M674</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-10T13:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373511#M675</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have added the DNS suffix under Gateway--&amp;gt;Agent--&amp;gt;Network Services.&amp;nbsp; And I see the same thing in the log that you posted, the DNS suffix shows as being processed, but when that DNS suffix does not show up ipconfig or in the adapter settings for GlobalProtect and when I try and contact by hostname only FQDN works.&amp;nbsp; So it's as though the config for DNS suffix is processed but never actually applied as far as I can see.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 13:40:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373511#M675</guid>
      <dc:creator>COlson</dc:creator>
      <dc:date>2020-12-10T13:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373512#M676</link>
      <description>&lt;P&gt;I also see no suffix in the ipconfig setting but wireshark port 53 showed that the suffix was added for DNS,&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 13:48:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373512#M676</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-10T13:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373513#M677</link>
      <description>&lt;P&gt;When I do a ping hostname and look in wireshark, I see the DNS request to the proper DNS server but it uses the DNS suffix from the local machine (there are actually two and it tries both), not the DNS that should be applied via GlobalProtect.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 14:04:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373513#M677</guid>
      <dc:creator>COlson</dc:creator>
      <dc:date>2020-12-10T14:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373514#M678</link>
      <description>&lt;P&gt;Hmmm...&amp;nbsp; &amp;nbsp; yes thats correct...&amp;nbsp; but would that matter.... i suppose the only issue would be if you had servers with the same name on different domains...&amp;nbsp; &amp;nbsp; apart from that, as long as it resolves would it really matter?&amp;nbsp; works ok for me....&amp;nbsp; perhaps you are having other issues with this.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 14:22:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373514#M678</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-10T14:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373515#M679</link>
      <description>&lt;P&gt;this id comment from PAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;This is expected behavior as the DNS suffix is just a linear list of suffixes to search, and is not adapter dependent."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;so it's not supposed&amp;nbsp;to reconfigure the adapter, just add a search suffix.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 14:30:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373515#M679</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-10T14:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373516#M680</link>
      <description>&lt;P&gt;I had read that as well... but unfortunately, it doesn't seem to be adding the suffix.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's not resolving properly.&amp;nbsp; So, my laptop is in domain A and receives DNS suffix for domain A and domain B.&amp;nbsp; GlobalProtect has a DNS suffix for domain C.&amp;nbsp; So when I connect to the GP gateway, I want to be able to resolve hostnames for domain C without FQDN but when I ping hostname, Wireshark shows DNS is trying hostname.domain A and hostname.domain B (which fails because the hostname is only in domain C) and then returns that the host can't be found.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 14:33:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373516#M680</guid>
      <dc:creator>COlson</dc:creator>
      <dc:date>2020-12-10T14:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373517#M681</link>
      <description>&lt;P&gt;Oh i see....&amp;nbsp; &amp;nbsp; &amp;nbsp;so where exactly are you getting domain B suffix from, is that set on the adapter...&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 15:03:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373517#M681</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-10T15:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373552#M683</link>
      <description>&lt;P&gt;DomainA and DomainB DNS suffix are received via GPO.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 16:16:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373552#M683</guid>
      <dc:creator>COlson</dc:creator>
      <dc:date>2020-12-10T16:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373554#M684</link>
      <description>&lt;P&gt;I have a few local domains on my NIC and have added these additional ones to GP Gateway...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_1-1607616791419.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29053i2FC8A52ECE58160A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_1-1607616791419.png" alt="MickBall_1-1607616791419.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on GP connection my ipconfig /all&amp;nbsp; shows&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_2-1607616901266.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29054iBF02328A3FAB5D35/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_2-1607616901266.png" alt="MickBall_2-1607616901266.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and when i ping elzzzbelzzzz i see this in wireshark&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_3-1607617180549.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29055iD53C87F834B149C2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_3-1607617180549.png" alt="MickBall_3-1607617180549.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so it does work and i have no idea why it wouldn't work for you....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using PAN 9.1.6 and GP 5.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 16:22:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373554#M684</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-10T16:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373555#M685</link>
      <description>&lt;P&gt;perhaps GPO takes precedence here..... our suffix is part of the image...&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 16:25:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373555#M685</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-10T16:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373569#M686</link>
      <description>&lt;P&gt;you could try this...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; Run gpedit.msc&lt;BR /&gt;&amp;gt; Browse Local Computer Policy&lt;BR /&gt;&amp;gt; Computer Configuration&lt;BR /&gt;&amp;gt; Administrative Templates -&amp;gt; Network -&amp;gt; DNS Client&lt;/P&gt;&lt;P&gt;Enable "Allow DNS Suffix Appending to Unqualified Multi-Label Name Queries"&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 16:32:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373569#M686</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-12-10T16:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373638#M687</link>
      <description>&lt;P&gt;Based on what you're showing, it would seem that GPO would indeed take a precedence; which makes the DNS suffix option not useful.&amp;nbsp; Although, I'm unable to find it anywhere in their documentation that confirms or denies that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 18:51:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/373638#M687</guid>
      <dc:creator>COlson</dc:creator>
      <dc:date>2020-12-10T18:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: DNS suffix not applying</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/376051#M743</link>
      <description>&lt;P&gt;Did you find a solution for your issue? I am running into the exact same scenrario. On our PAN device, we configured the DNS suffix in DHCP options to add it. But once the GP client connects and we check ip config the dns suffix is not there.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2020 16:12:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/dns-suffix-not-applying/m-p/376051#M743</guid>
      <dc:creator>Erasmo</dc:creator>
      <dc:date>2020-12-23T16:12:06Z</dc:date>
    </item>
  </channel>
</rss>

