<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site-to-Site VPN random issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-random-issue/m-p/172969#M54514</link>
    <description>&lt;P&gt;Thanks for the response. Only internal subnets are routed over the tunnel. Internet (and public DNS) go out the outside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The tunnel is established because some resources are available at the same time. It's a very weird issue. If I hardcode the internal DNS on the windows client, it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's almost as if PAN is doing round robin with the DNS&lt;/P&gt;</description>
    <pubDate>Thu, 24 Aug 2017 01:40:52 GMT</pubDate>
    <dc:creator>ce1028</dc:creator>
    <dc:date>2017-08-24T01:40:52Z</dc:date>
    <item>
      <title>Site-to-Site VPN random issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-random-issue/m-p/172948#M54510</link>
      <description>&lt;P&gt;I have Site A setup with a site-to-site VPN with Site B. &amp;nbsp;Site A contains all the resources (DC, email, fileserver, etc). The firewall in site B is configured as DHCP for the local clients. Primary DNS is setup for internal AD DC/DNS server. Secondary is public DNS servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We noticed randomly clients can not access certain local resources. Unable to ping them by hostname. If you run nslookup, they do resolve, but unable to ping or traceroute to them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you ping the device by IP, it will ping and then it will also ping by hostname.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm seeing a lot of traffic in the logs for the secondary DNS server, but it should really only use that if the primary is down (which it is not).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone ever seen this behavior?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 21:27:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-random-issue/m-p/172948#M54510</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2017-08-23T21:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN random issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-random-issue/m-p/172966#M54513</link>
      <description>&lt;P&gt;Is the secondary (public) DNS server also available over the vpn or directly from the clients?&lt;/P&gt;&lt;P&gt;When this problem occurs, is the tunneö then already established?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But to answer your last question, I haven seen this behaviour before. I have a similar setup in place with 2 palos connected over a s2s vpn. But in my case everything is routed over vpn. Every connection from site b has to go over the tunnel to site a.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 22:39:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-random-issue/m-p/172966#M54513</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-08-23T22:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN random issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-random-issue/m-p/172969#M54514</link>
      <description>&lt;P&gt;Thanks for the response. Only internal subnets are routed over the tunnel. Internet (and public DNS) go out the outside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The tunnel is established because some resources are available at the same time. It's a very weird issue. If I hardcode the internal DNS on the windows client, it works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's almost as if PAN is doing round robin with the DNS&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 01:40:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-random-issue/m-p/172969#M54514</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2017-08-24T01:40:52Z</dc:date>
    </item>
  </channel>
</rss>

