10-13-2020 02:22 AM
I have an SFTP server. When users are inside the office they have to connect it via private IP. When they are at home they should go via public IP. I am using the same DNS server in Internal and Global Protect as well. I have excluded the private SFTP IP in Global protect split tunnel, so that users won't get connect with this IP, instead they have go over the public IP.
Now the issues, when the users are at home they have to disable / enable the global protect, then only they will be able to connect to the SFTP server via public IP. Seems the DNS entry may be still there in the cache and it is trying to use the private IP. But they won't be able to access the server because we have excluded this private IP in the split tunnel. After performing a enable / disable, the cache may get clear and prefer to go via public IP.
Is there any solution to avoid enabling / disabling the tunnel?
10-13-2020 05:23 AM
DNS Proxy will be more controlled as it will be applicable to your SFTP URL and/or the URLs only which are mentioned under DNS proxy configuration.
10-13-2020 05:30 AM - edited 10-13-2020 05:37 AM
Hi @ManuShankar ,
if the problem with DNS, what already @SutareMayur @JoergSchuetter said, DNS Proxy can be a solution for you.
but what does not make sense yet, what do you mean with enable/disable ? do they disable GP then connect to SFTP public? then re-enable VPN tunnel?
because if you mean with disable/enable = re-establishing the connection SFTP should also not work. unless the windows DNS Cache is beeing fushed here. which you can also edit cache timeout to solve your problem.
if that is the case that GP should be disabled first, i will asume you internet traffic for homeoffice users go through the tunnel, right?
the behavoir you discribed could be linked that they are going throguh the tunnel to reach your SFTP Public-ip, and when they disconnect the use the private Internet.
10-13-2020 06:34 AM
Hi @Abdul-Fattah ,
As per my understanding if I create a DNS proxy then all DNS request from the VPN clients will come to Firewall IP, which I don't want. Firewall will act in the middle for all the request.
I am with your point, re-establishing VPN connection, SFTP should also not work. unless clearing the windows DNS Cache. Actually this is told by user, honestly I couldn't check from user's machine.
do you have any idea how to edit cache timeout?
Thanks,
Manu
10-14-2020 12:56 AM
Hi @ManuShankar,
you can edit the windows registry to change the default of 1 Day.
but as far as i know windows handels DNS very well, and store only valid DNS, so that should not be the problem. but you will need to check this behavior further as i mentined the problem could be that the GP-users internet traffic going through the tunnel, because ive seen this before in my case the traffic was going thoruhg the tunnel to the internet which gave the users a Public ip that it can not reach the other service (in your case SFTP Public IP).
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!