<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS proxy to GP clients in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-to-gp-clients/m-p/171235#M54192</link>
    <description>&lt;P&gt;Have you been able to troubleshoot the user's complaints? using the DNS proxy configuration should be the method to accomplish this requirement&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how did you configure it exactly?&lt;/P&gt;</description>
    <pubDate>Fri, 11 Aug 2017 08:29:15 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-08-11T08:29:15Z</dc:date>
    <item>
      <title>DNS proxy to GP clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-to-gp-clients/m-p/171213#M54187</link>
      <description>&lt;P&gt;DNS configured in GP settings: Primary DNS 10.250.1.1, secondary DNS 10.250.1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Access route: split tunnel- 10.250.0.0/16 allowed in GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once clients are connected to globalprotect, they are getting the above DNS settings. so the traffic going to internet also resolving in above Internal DNS server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now i have the requirement for GP users, when traffic going to internet, it should resolve using public DNS say 8.8.8.8 or 4.2.2.2&lt;/P&gt;&lt;P&gt;and the traffic going to 10.250.0.0/16 to GP tunnel should resolve to&amp;nbsp;&lt;SPAN&gt;DNS 10.250.1.1, secondary DNS 10.250.1.2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have configured as per below KB for fulfil the above requirement. its working fine, some of the users complain about internal DNS server issue for GP connected internal sites sometimes. However internet traffic resolution working fine. so we have removed this config&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-DNS-Proxy-for-GlobalProtect-Clients/ta-p/124541" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-DNS-Proxy-for-GlobalProtect-Clients/ta-p/124541&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kindly suggest if there is any workaround for this requirement&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2017 07:24:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-to-gp-clients/m-p/171213#M54187</guid>
      <dc:creator>Javith_Ali</dc:creator>
      <dc:date>2017-08-11T07:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy to GP clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-to-gp-clients/m-p/171235#M54192</link>
      <description>&lt;P&gt;Have you been able to troubleshoot the user's complaints? using the DNS proxy configuration should be the method to accomplish this requirement&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;how did you configure it exactly?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2017 08:29:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-to-gp-clients/m-p/171235#M54192</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-08-11T08:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy to GP clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-to-gp-clients/m-p/171295#M54217</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thansk for reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we dont have more time to troubleshoot this issue as lots of users are complaining about DNS resolution. Hence we revert back to old configurations which is resolving all queries in internal server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the users machine, we are getting the dns timed out in nslookup and in firewall queries are sent from dns proxy ip to external servers and less queries to internal servers. yet to collect the logs, Just posted here to check for alternative solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2017 16:12:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-to-gp-clients/m-p/171295#M54217</guid>
      <dc:creator>Javith_Ali</dc:creator>
      <dc:date>2017-08-11T16:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: DNS proxy to GP clients</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-to-gp-clients/m-p/171321#M54221</link>
      <description>Outside of the box, you could set up a bind server in dmz in caching mode, set your internal domains as forwarded to internal server, everything else as forwarded to internet dns</description>
      <pubDate>Fri, 11 Aug 2017 18:27:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-proxy-to-gp-clients/m-p/171321#M54221</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-08-11T18:27:25Z</dc:date>
    </item>
  </channel>
</rss>

