<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS server failover not working for GP client in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-server-failover-not-working-for-gp-client/m-p/294901#M77741</link>
    <description>&lt;P&gt;Hello there...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a simple question that I would like to better understand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the split tunnel enabled, can you confirm that both DNS server entries are seen by the client machine?&lt;/P&gt;&lt;P&gt;If this is true, then my question seems to be, what happens when the first goes down... (can you run a wireshark) to confirm that, indeed, the 2nd DNS server is being properly queried by the client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would think this would be a client issue primarily.&amp;nbsp; Of course, if you can show that DNS requests are making it across the VPN to the FW and not being resolved, that is a different story (and one which I think you are attempting to believe the issue is, but let's try to confirm our theory)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Oct 2019 12:33:36 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2019-10-29T12:33:36Z</dc:date>
    <item>
      <title>DNS server failover not working for GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-server-failover-not-working-for-gp-client/m-p/294812#M77725</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have a problem with the GP client and DNS. when the primary DNS server configured on the GP gateway is down, the GP client is unable to resolve FQDNs (over the split tunnel).&amp;nbsp; Once I reversed the and made the secondary (active) DNS server the primary, the GP was able to resolve internal names.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The only global timer that I can see for DNS is under Device/Setup/Services and that is for FWDN Refresh.&amp;nbsp; I currently have the two DNS servers configured by IP addresses.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The FQDN Refresh Time is set to the default of 1800 seconds.&amp;nbsp; The PA is running v8.1.9.&amp;nbsp; We only noticed this during tests as we are progressively upgrading the Domain Controllers and DNS servers.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I see in the on-line documentation that for VMs, we can set as low as 60 seconds (1 minute).&amp;nbsp; It sounds like a shorted FQDN refresh would help this issue.&amp;nbsp; Would lowering this value significantly impact overall performance?&amp;nbsp; What should we do here to fix the issue&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 23:06:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-server-failover-not-working-for-gp-client/m-p/294812#M77725</guid>
      <dc:creator>Jatin.Singh</dc:creator>
      <dc:date>2019-10-28T23:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: DNS server failover not working for GP client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-server-failover-not-working-for-gp-client/m-p/294901#M77741</link>
      <description>&lt;P&gt;Hello there...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a simple question that I would like to better understand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the split tunnel enabled, can you confirm that both DNS server entries are seen by the client machine?&lt;/P&gt;&lt;P&gt;If this is true, then my question seems to be, what happens when the first goes down... (can you run a wireshark) to confirm that, indeed, the 2nd DNS server is being properly queried by the client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would think this would be a client issue primarily.&amp;nbsp; Of course, if you can show that DNS requests are making it across the VPN to the FW and not being resolved, that is a different story (and one which I think you are attempting to believe the issue is, but let's try to confirm our theory)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 12:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-server-failover-not-working-for-gp-client/m-p/294901#M77741</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-10-29T12:33:36Z</dc:date>
    </item>
  </channel>
</rss>

