<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect DNS name resolution. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17875#M13009</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Slawek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GP tunnel interface is the part of inside zone and DNS servers resides in the same zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Parvez &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Jan 2014 13:50:22 GMT</pubDate>
    <dc:creator>ParvezAhmad</dc:creator>
    <dc:date>2014-01-23T13:50:22Z</dc:date>
    <item>
      <title>Global protect DNS name resolution.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17873#M13007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Through global protect, users are getting IP address from the pool and take network setting as defined including primary DNS and Secondary DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but the users want to access servers via name(s) not IP addess(es). Since it was working before with cisco remote vpn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know is there any setting in global protect gateway to make it functional?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Parvez &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 12:52:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17873#M13007</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-01-23T12:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect DNS name resolution.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17874#M13008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Parvez&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my opinion it isn't GP issue. Please use in GP configuration your local DNS servers, servers that are able to resolve name of servers that are want to use by your users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you miss security policy that allow DNS traffic from zone VPN to zone where are Your DNS sererwers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 13:27:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17874#M13008</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-01-23T13:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect DNS name resolution.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17875#M13009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Slawek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GP tunnel interface is the part of inside zone and DNS servers resides in the same zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Parvez &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 13:50:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17875#M13009</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-01-23T13:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect DNS name resolution.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17876#M13010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could You ping by IP address this servers?&lt;/P&gt;&lt;P&gt;What about nslookup - is it possible to get response about google.com?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 14:22:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17876#M13010</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-01-23T14:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect DNS name resolution.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17877#M13011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Firewall Policy? is DNS allowed from the tunnel zone to the destination zone ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 14:55:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17877#M13011</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2014-01-23T14:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect DNS name resolution.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17878#M13012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes you need to autorize via security policy dns app or via service base on tcp and udp 53 port &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 16:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17878#M13012</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-01-23T16:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect DNS name resolution.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17879#M13013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;since tunnel interface is the part of inside zone - from inside to outside permit all for this VPN subnet.&lt;/P&gt;&lt;P&gt;Moreover, after connecting GP, we tried nslookup of some servers it is resolving the correct IP address.&lt;/P&gt;&lt;P&gt;I tried to access(through RDP) servers via its name it is not working but via IP address - It is working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jan 2014 07:54:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17879#M13013</guid>
      <dc:creator>ParvezAhmad</dc:creator>
      <dc:date>2014-01-24T07:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect DNS name resolution.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17880#M13014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm 99,99% sure, if everything is allowed from VPN to the LAN and nslookup works, it shouldn't be a firewall issue!&lt;/P&gt;&lt;P&gt;It can be the HOST.txt file, Windows/3rdParty Client Firewall, DNS Server, NIC driver/setting or the Remote Server itself...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to google that. Sorry, because I don't know your infrastructure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW: Do you see something in the traffic logs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jan 2014 08:08:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17880#M13014</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2014-01-24T08:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect DNS name resolution.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17881#M13015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;STRONG&gt;I tried to access(through RDP) servers via its name it is not working but via IP address - It is working&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;STRONG&gt;and when you try a nslookup with this server name, what is the result?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;STRONG&gt;if it's work it's not a firewall issue. but RDP service on this server&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jan 2014 11:15:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17881#M13015</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-01-24T11:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect DNS name resolution.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17882#M13016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is actually a well known problem for Windows as well as Mac OSX.&amp;nbsp; It has to do with the DNS server binding order.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Written for XP but applies to 7 as well:&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.microsoft.com/kb/311218" title="http://support.microsoft.com/kb/311218"&gt;Cannot Change the Binding Order for Remote Access Connections&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Google search that shows how wide spread this issue is and some resolutions for it.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.google.com/search?q=windows+dns+binding+order&amp;amp;rlz=1C1LENP_enUS544US544&amp;amp;oq=windows+dns+bind&amp;amp;aqs=chrome.2.69i57j0l5.7472j0j7&amp;amp;sourceid=chrome&amp;amp;espv=210&amp;amp;es_sm=122&amp;amp;ie=UTF-8#newwindow=1&amp;amp;q=windows+vpn+uses+wrong+dns&amp;amp;safe=off" title="https://www.google.com/search?q=windows+dns+binding+order&amp;amp;rlz=1C1LENP_enUS544US544&amp;amp;oq=windows+dns+bind&amp;amp;aqs=chrome.2.69i57j0l5.7472j0j7&amp;amp;sourceid=chrome&amp;amp;espv=210&amp;amp;es_sm=122&amp;amp;ie=UTF-8#newwindow=1&amp;amp;q=windows+vpn+uses+wrong+dns&amp;amp;safe=off"&gt;https://www.google.com/search?q=windows+dns+binding+order&amp;amp;rlz=1C1LENP_enUS544US544&amp;amp;oq=windows+dns+bind&amp;amp;aqs=chrome.2.69i5…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Jan 2014 02:47:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/17882#M13016</guid>
      <dc:creator>JimS2</dc:creator>
      <dc:date>2014-01-25T02:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect DNS name resolution.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/312510#M80802</link>
      <description>&lt;P&gt;Were you ever able to find a solution to your problem? I'm experiencing the same thing running macOS 10.15.3. Upon initial connection with GlobalProtect I open terminal and run "scutil --dns". My nameservers show the IPs of the my internal corporate network. After a few seconds I can run the same command, and the nameservers has changed to localhost "127.0.0.1".&lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2020 02:10:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-dns-name-resolution/m-p/312510#M80802</guid>
      <dc:creator>MattCooperCISD</dc:creator>
      <dc:date>2020-02-23T02:10:42Z</dc:date>
    </item>
  </channel>
</rss>

