<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA500 split tunnelling DNS question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50234#M36988</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am seeing traffic denied from untrust to untrust per my last global deny rule application not applicable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dosent seem to be any other deny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Sue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Aug 2011 13:11:39 GMT</pubDate>
    <dc:creator>sue_town</dc:creator>
    <dc:date>2011-08-30T13:11:39Z</dc:date>
    <item>
      <title>PA500 split tunnelling DNS question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50232#M36986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a PA 500 set up for split tunnelling - so clients access internet locally and all other traffic is passed over VPN tunnel to our office&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have DHCP set up on PA box so clients get primary DNS server (local ISP one) and secondary DNS (office one)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set up a rule from trust to untrust to allow application DNS and service DNS however i am getting errors saying failed to resolve domain name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so I SSH to the box and cannot ping host www.yahoo.com nor can i ping host yahoo.com by IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Sue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2011 12:27:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50232#M36986</guid>
      <dc:creator>sue_town</dc:creator>
      <dc:date>2011-08-30T12:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 split tunnelling DNS question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50233#M36987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you cannot ping yahoo.com by IP as well, it is unlikely to be a DNS problem. Would you check the traffic log to see if any traffic has been denied? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2011 13:02:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50233#M36987</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-08-30T13:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 split tunnelling DNS question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50234#M36988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am seeing traffic denied from untrust to untrust per my last global deny rule application not applicable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dosent seem to be any other deny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Sue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2011 13:11:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50234#M36988</guid>
      <dc:creator>sue_town</dc:creator>
      <dc:date>2011-08-30T13:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 split tunnelling DNS question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50235#M36989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Sue,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. go to &lt;CITE&gt;whatis&lt;STRONG&gt;myip&lt;/STRONG&gt;address.com/ to check the public IP you are using before you connect to the SSLVPN.&lt;/CITE&gt;&lt;/P&gt;&lt;P&gt;&lt;CITE&gt;2. start the vpn connection, check if there is any deny traffic from your public ip address&lt;/CITE&gt;&lt;/P&gt;&lt;P&gt;&lt;CITE&gt;3. most likely you will see there is traffic from your public IP address from untrust to untrust running on port 443 being denied. for that case you should add the SSL as the app and app. default as the port no.&lt;/CITE&gt;&lt;/P&gt;&lt;P&gt;&lt;CITE&gt;4. remember to add the NAT policy for your client.&lt;/CITE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2011 13:34:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50235#M36989</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-08-30T13:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 split tunnelling DNS question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50236#M36990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for your reply....but the traffic over the VPN tunnel into the companys network is working ok&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the issue is just with internet access and DNS it seems...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2011 13:44:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50236#M36990</guid>
      <dc:creator>sue_town</dc:creator>
      <dc:date>2011-08-30T13:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 split tunnelling DNS question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50237#M36991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sue,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so would you run ipconfig to see if the DNS setting is well populated? Also check if the "route print" output to see if the routing to SSLVPN gateway just cover the corporate network subnet, and run a traceroute to see check which is the next hop for traffic to yahoo.com.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2011 14:34:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50237#M36991</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-08-30T14:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 split tunnelling DNS question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50238#M36992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;just to let you know this is resolved&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the issue was that the default route was set to go via an interface rather than IP address - once i changed it to IP, all web browsing and DNS worked fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just for info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for replies&lt;/P&gt;&lt;P&gt;Sue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Aug 2011 07:57:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50238#M36992</guid>
      <dc:creator>sue_town</dc:creator>
      <dc:date>2011-08-31T07:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: PA500 split tunnelling DNS question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50239#M36993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sue,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good to know that &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Aug 2011 15:49:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa500-split-tunnelling-dns-question/m-p/50239#M36993</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-08-31T15:49:31Z</dc:date>
    </item>
  </channel>
</rss>

