<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect not using new DNS servers in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205715#M60384</link>
    <description>&lt;P&gt;Hmm, that is a weird one for sure. Perhaps a support ticket is in order?&lt;/P&gt;</description>
    <pubDate>Thu, 15 Mar 2018 17:14:54 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2018-03-15T17:14:54Z</dc:date>
    <item>
      <title>Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205448#M60316</link>
      <description>&lt;P&gt;Greetings!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;We recently migrated to a new DNS server in our internal network; With this, we also updated the configurations on the firewall configuration, and on the GP setup to reflect this. We have the PAN giving IP's to GP clients directly (not relayed), and whenever someone connects to the FW, they are getting the old DNS servers, not the new ones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've googled, and gone through the configuration; the only thing left with the old DNS server is an address book entry (that can be removed). I also just tested uninstalling and reinstalling the GP client, and still getting the old server IP's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone seen this before? is there a config file, registry setting&amp;nbsp;that is making the old IP's sticky?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 19:26:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205448#M60316</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-03-14T19:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205484#M60327</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Check the DHCP server config since the PAN is handing out the info:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network tab -&amp;gt; DHCP &amp;gt; DHCP Server&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 695px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14240i394510C18EA68B5B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also check the PAN config if you done have these defined:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Device tab -&amp;gt; Setup -&amp;gt; Services:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 504px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14241iA4923F2B5B8F87C9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 21:41:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205484#M60327</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-14T21:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205486#M60329</link>
      <description>&lt;P&gt;We don't have DHCP setup for this, we have the IP Pools set up in the GP configuration;&amp;nbsp; the only item we have for DHCP is our Guest VLAN, and that's on an unrelated subnet, and pointed out to public OpenDNS IP addresses.&lt;BR /&gt;&lt;BR /&gt;I've triple-checked the config, the IP of the old DNS server is only present in a legacy address book entry, but it's not tied to anything.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 21:47:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205486#M60329</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-03-14T21:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205490#M60331</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I take it you also looked at the Network Services tab?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network tab -&amp;gt;GlobalProtect -&amp;gt;Gateways -&amp;gt; Gateway Configuration -&amp;gt; Agent -&amp;gt; Network Services&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 799px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14242iAD173D002BBC3CEB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 21:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205490#M60331</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-14T21:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205491#M60332</link>
      <description>&lt;P&gt;That, and the device tab were the places we updated over this weekend;&amp;nbsp; The old DNS server IP's are completely removed from the configuration; doing a 'show | match w.x.y.z' for the old DNS IP only shows up as an address book object not linked to anything.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 22:02:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205491#M60332</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-03-14T22:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205497#M60335</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;What happens if you do a ipconfig release renew on the client when connected via VPN? I'm wondering if the clients are somehow retaining the old settings?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also you can do a global search via the gui for the IP:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 253px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14244iDA6216A4B424D322/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just thinking out loud.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 22:10:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205497#M60335</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-14T22:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205684#M60378</link>
      <description>&lt;P&gt;if I do an ipconfig&amp;nbsp;/release while connected, GlobalProtect disconnects.&amp;nbsp; when it reconnects, it still has the old settings.&lt;BR /&gt;&lt;BR /&gt;I did do a search in the GUI, and the results were the same as doing a 'show | match ip.add.re.ss' for the old DNS server IP - only match was an address book object that is not used in any network/GP configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 15:44:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205684#M60378</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-03-15T15:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205715#M60384</link>
      <description>&lt;P&gt;Hmm, that is a weird one for sure. Perhaps a support ticket is in order?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 17:14:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205715#M60384</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-15T17:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205729#M60388</link>
      <description>&lt;P&gt;I actually did, and just got off the phone with a TAC engineer.&amp;nbsp; No solution yet, but he's going to put it in their lab and test/confirm on it.&amp;nbsp; they are suggesting a commit full may reset it, because it does look to be being pushed by the FW, and that may clear out anything old that's hanging up.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;When we do get a fix on this, I'll post it up for others that have this same issue. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 17:45:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205729#M60388</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-03-15T17:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205740#M60391</link>
      <description>&lt;P&gt;Did you happen to check "GP App Config refresh interval" and &lt;SPAN&gt;"&lt;/SPAN&gt;Update DNS Settings at Connect(&lt;SPAN class="Bold"&gt;Windows Only&lt;/SPAN&gt;)" under Portal-Agent-App tab?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are your current settings for these options?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 18:32:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205740#M60391</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2018-03-15T18:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205801#M60406</link>
      <description>&lt;P&gt;Just looked at those - the GP App config refresh is set for 24 hours - the DNS change was done this past sunday, over 96 hours ago.&lt;BR /&gt;&lt;BR /&gt;The Update DNS Settings at connect had orginally&amp;nbsp;be set to no, but I did change it 2 days ago before I posted this topic up&lt;BR /&gt;&lt;BR /&gt;(appreciate the suggestions on this! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; )&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 22:30:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205801#M60406</guid>
      <dc:creator>JohPalmer</dc:creator>
      <dc:date>2018-03-15T22:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not using new DNS servers</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205972#M60461</link>
      <description>&lt;P&gt;what does it say for DNS when you CLI...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show global-protect-gateway gateway name &amp;lt;your gateway name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also.. i just modified my secondary DNS and user updated on first connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;apart from the obvious... are your settings similar to mine...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="padns.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14280iE99771DB6FA60101/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="padns.png" alt="padns.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 15:21:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-using-new-dns-servers/m-p/205972#M60461</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-16T15:21:54Z</dc:date>
    </item>
  </channel>
</rss>

