<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN DNS not resolving in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/121070#M46012</link>
    <description>&lt;P&gt;We are seeing a similar issue&amp;nbsp;every so often&amp;nbsp;when our users connect to our DFS share via VPN. The DFS share is sometimes unavailable while \\servername resolves immediately. Could this be the same issue?&lt;/P&gt;&lt;P&gt;GlobalProtect Client 3.1.1-27&lt;/P&gt;</description>
    <pubDate>Tue, 25 Oct 2016 07:37:30 GMT</pubDate>
    <dc:creator>Indorama_Ventures</dc:creator>
    <dc:date>2016-10-25T07:37:30Z</dc:date>
    <item>
      <title>VPN DNS not resolving</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/120027#M45858</link>
      <description>&lt;P&gt;I have users on 3 different local AD domains. We are consolidating, but in the mean time, users have been able to connect to the GlobalProtect VPN and browser network resources. A few weeks ago one user emailed me and said he is connected to VPN, but cannot connect to a terminal server. I check into it and realize that he can ping the IP of the server and connect via the IP address, but DNS is not resolving any names, although the DNS server for the GlobalProtect adpater is set correctly. If i remove the user's computer from the domain, and log into the local account, VPN works perfectly. I am confused how the AD domain would affect the VPN tunnel DNS. Does anyone have any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 21:30:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/120027#M45858</guid>
      <dc:creator>newfrenchbakery</dc:creator>
      <dc:date>2016-10-18T21:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN DNS not resolving</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/120030#M45859</link>
      <description>&lt;P&gt;Sounds like a GP bug. There is a current issue where DNS servers don't update when a network change is detected by the globalprotect client on Windows machines, this issue probably doesn't have anything to do with your AD configuration. Flushing DNS is the current workaround. I'd open up a support case to verify the bug is the same, and to inquire if/when a fix will be released.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 21:46:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/120030#M45859</guid>
      <dc:creator>MangoTango</dc:creator>
      <dc:date>2016-10-18T21:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN DNS not resolving</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/120046#M45860</link>
      <description>&lt;P&gt;Weird, we are only seeing it on one client. I am an end user of a share Palo Alto Firewall, so I am not able to open a support ticket. Does downgrading the GP client to an older version work? You mention a workaround, can you elaborate?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 23:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/120046#M45860</guid>
      <dc:creator>newfrenchbakery</dc:creator>
      <dc:date>2016-10-18T23:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN DNS not resolving</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/121070#M46012</link>
      <description>&lt;P&gt;We are seeing a similar issue&amp;nbsp;every so often&amp;nbsp;when our users connect to our DFS share via VPN. The DFS share is sometimes unavailable while \\servername resolves immediately. Could this be the same issue?&lt;/P&gt;&lt;P&gt;GlobalProtect Client 3.1.1-27&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 07:37:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/121070#M46012</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2016-10-25T07:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: VPN DNS not resolving</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/121106#M46014</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We were having the exact same issue, when our users changed from default VPN to a 2 factor authenticated one, the DNS servers would change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The change of the DNS server will cause Windows to invalidate all cached DNS entries, and it will not try to resolve them again until the invalidated cache entry has been purged.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our solution was to use the same DNS server for all VPN gateways.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 10:20:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/121106#M46014</guid>
      <dc:creator>arvesynd</dc:creator>
      <dc:date>2016-10-25T10:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN DNS not resolving</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/126796#M46549</link>
      <description>&lt;P&gt;Did you ever find a fix for this?&lt;/P&gt;&lt;P&gt;We're running version 3.1.1 on the client in hopes to resolve this, but nothing so far besides manually running an ipconfig /flushdns script.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 17:09:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/126796#M46549</guid>
      <dc:creator>policeman51</dc:creator>
      <dc:date>2016-11-16T17:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN DNS not resolving</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/126801#M46550</link>
      <description>&lt;P&gt;We never did. I ended up moving the user to a new computer with a matching domain as the VPN client and that fixed the issue. Not sure why it stopped working or what the issue was, but we found a workaround.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 17:21:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/126801#M46550</guid>
      <dc:creator>newfrenchbakery</dc:creator>
      <dc:date>2016-11-16T17:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN DNS not resolving</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/127566#M46610</link>
      <description>&lt;P&gt;I've seen this type of behavior in multiple windows domain systems. &amp;nbsp;The issue there was with how windows handles the "short" names for resolution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First is adding the computer local domain&lt;/P&gt;&lt;P&gt;Next is cycling through the domain suffix options on the workstation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The fix was two fold.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All DNS servers in each domain had forwarders configured to point to all the other internal domain names. &amp;nbsp;This way no matter what domain the computer belonged to and used for DNS the forwarder would work for the other domain name resolutions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A group policy was then added for computers in each domain to add all the other internal domain names to the DNS suffix list on the computer. &amp;nbsp;This way they would all be tried for each short name if the local computer domain failed in the lookup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 22:52:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-dns-not-resolving/m-p/127566#M46610</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-11-18T22:52:29Z</dc:date>
    </item>
  </channel>
</rss>

