02-13-2020 10:37 AM
Hello...
Many of my end users are now reporting that after approximately 10 minutes of logging to VPN using the GlobalProtect client they lose DHS resolution to internal and external resources. For example, when this happens. Users cannot access or even ping a server, by either its FQDN or by IP number. In addition, users also report they cannot access external resources such as Google. However, the GP client will still show "Connected." If the user disconnects/reconnects the GP client DNS resolution is restored. Then this cycle starts over again. This started several weeks ago and to my knowledge we have not made any changes to either the GP client or the FW. A support case, so far, has not resulted in a solution.
02-14-2020 06:39 AM
Yes we are allowing split tunneling. Nothing in the traffic logs found so far. Tech support suggests putting the firewall into debug mode, Wireshark a client and see if we can recreate the issue.
02-15-2020 05:51 AM
Hi @aimsnss ,
Which DNS server you have configured under global protect settings? Is it internal?
Mayur
02-16-2020 10:47 AM
Yes, confirmed. Internal DNS address is in play.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!