<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Resolution with global protect. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396985#M91442</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you tried source address for this setting.- &lt;STRONG&gt;You mean source address in security policy.? sorry i didn't get you&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Apr 2021 19:05:09 GMT</pubDate>
    <dc:creator>Jafar_Hussain</dc:creator>
    <dc:date>2021-04-09T19:05:09Z</dc:date>
    <item>
      <title>DNS Resolution with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396810#M91409</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I am facing some issue with DNS resolution. below is the scenerio.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_1-1617959764286.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30812i381123ED53F0B8B3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_1-1617959764286.png" alt="Jafar_Hussain_1-1617959764286.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Global Protect VPN setup.&lt;BR /&gt;after connecting global protect, i will take RDP of some internal machine.&lt;BR /&gt;RDP will take by host name example:- system1.abc.com resolved by IP address 192.168.1.15&lt;BR /&gt;system2.abc.com resolved by IP address 192.168.1.16&lt;BR /&gt;system3.abc.com resolved by IP address 192.168.1.16&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;working scenerio:&lt;/U&gt;&lt;/STRONG&gt;-&lt;/P&gt;&lt;P&gt;Client connect the global protect and will take RDP system1.abc.com the query will go first to the load balancer(192.168.1.100) and load balancer forward this query either DNS server1 and DNS server2 then i will get reply accordingly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Issue:-&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;some time what happen when i connect the global protect i am unable to take RDP by host name that time i checked by nslookup command the DNS server not able to resolved the query, for some time i am getting time out error.that time i checked i can take RDP by IP address. this issue is occur intermittently some time i can take RDP by host name and some time not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;important point:-&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;- In the global protect gateway configuration i given the load balancer IP address (192.168.1.100). in this setting i put direct DNS server IP (192.168.1.10 and 192.168.1.20) but the same issue happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_0-1617959726226.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30811i6A5AC05FB781F1F3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_0-1617959726226.png" alt="Jafar_Hussain_0-1617959726226.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;- No DNS proxy.&lt;BR /&gt;- In the split tunnel i given all IP address for load balancer and both DNS server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Troubleshooting:-&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- When i took the packet capture and run the global counter i can found the Paloalto drop some packets.&lt;BR /&gt;below is the counter detail:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Jafar_Hussain_2-1617959892551.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30813i64E340779912E538/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Jafar_Hussain_2-1617959892551.png" alt="Jafar_Hussain_2-1617959892551.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- when i checked in the capture and found some time i am not getting the answer of the DNS query and Paloalto to drop the packet.&lt;BR /&gt;- I removed the antispyware profile from the security policy. but still, i am facing the same issue.&lt;BR /&gt;- PAN-OS version - 9.1.5&lt;BR /&gt;- I checked the RDP is working fine with a hostname without connecting global protect.&lt;BR /&gt;- GP version - 5.1.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help me with this?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 09:19:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396810#M91409</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2021-04-09T09:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396821#M91410</link>
      <description>&lt;P&gt;the first test i would do is remove DNS server1 form the pool.&amp;nbsp; make a few rdp connections to different hosts to check fully and then do the same with DNS server2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does your LB NAT to the DNS servers, you may need a route back to the GP subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that you can connect OK without GP but thay may be coming from a different subnet....&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 09:50:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396821#M91410</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-04-09T09:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396839#M91412</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;he first test i would do is remove DNS server1 form the pool. make a few rdp connections to different hosts to check fully and then do the same with DNS server2. - &lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;Done but same issue.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does your LB NAT to the DNS servers, you may need a route back to the GP subnet.-&lt;STRONG&gt;&lt;EM&gt;&lt;U&gt;&amp;nbsp; Yes&lt;/U&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 11:25:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396839#M91412</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2021-04-09T11:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396896#M91423</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;So I am a huge proponent of the K.I.S.S principle. What are you load balancing DNS traffic? Have you tried to remove the Load Balancer from the equation? I have seen a lot of issues in the past with load balancers and asymmetric traffic return, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 15:03:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396896#M91423</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-04-09T15:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396942#M91438</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the global protect gateway setting i directly mention the DNS server instead of the load balancer. but no luck.&lt;/P&gt;&lt;P&gt;the most important thing is that everything working fine without GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 17:13:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396942#M91438</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2021-04-09T17:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396981#M91440</link>
      <description>&lt;P&gt;do you have persistence set on the LB, have you tried source address for this setting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit....&lt;/P&gt;&lt;P&gt;cancel that as works without GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am going to see if i get the same issue via LB.&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 18:23:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396981#M91440</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-04-09T18:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396985#M91442</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you tried source address for this setting.- &lt;STRONG&gt;You mean source address in security policy.? sorry i didn't get you&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 19:05:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/396985#M91442</guid>
      <dc:creator>Jafar_Hussain</dc:creator>
      <dc:date>2021-04-09T19:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution with global protect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/397003#M91443</link>
      <description>&lt;P&gt;No. I am talking about persistence on the LB, you may know it as sticky Sessions as i don't know what you are using as LB’s. But cancel this suggestion as it works fine you say without GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you confirm that when you had only server1 in the pool, all was ok, and then when you had only server2 in the pool that was also ok. Then, when you add both servers back in to 5he pool you see the same issue....?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 19:16:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dns-resolution-with-global-protect/m-p/397003#M91443</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-04-09T19:16:23Z</dc:date>
    </item>
  </channel>
</rss>

