DNS Resolution stops after ~10s after connecting with GlobalProtect

Reply
Highlighted
L1 Bithead

DNS Resolution stops after ~10s after connecting with GlobalProtect

Hello...

Many of my end users are now reporting that after approximately 10 minutes of logging to VPN using the GlobalProtect client they lose DHS resolution to internal and external resources. For example, when this happens. Users cannot access or even ping a server, by either its FQDN or by IP number. In addition, users also report they cannot access external resources such as Google. However, the GP client will still show "Connected." If the user disconnects/reconnects the GP client DNS resolution is restored. Then this cycle starts over again. This started several weeks ago and to my knowledge we have not made any changes to either the GP client or the FW. A support case, so far, has not resulted in a solution.

Highlighted
L6 Presenter

Hi @aimsnss ,

 

Is it a split VPN tunnel ? Also what do you see in the traffic logs?

 

Mayur

 

 



Mayur
Highlighted
L1 Bithead

Yes we are allowing split tunneling. Nothing in the traffic logs found so far. Tech support suggests putting the firewall into debug mode, Wireshark a client and see if we can recreate the issue. 

Highlighted
L6 Presenter

Hi @aimsnss ,

Which DNS server you have configured under global protect settings? Is it internal?

 

Mayur



Mayur
Highlighted
L1 Bithead

Yes, confirmed. Internal DNS address is in play.

Highlighted
L6 Presenter

May be packet captures during issue can help to understand the root cause.

 

Mayur



Mayur
Highlighted
L4 Transporter

Hi @aimsnss ,

 

is the issue resolved ?. mostly your DNS traffic policy might not be configured for logging, that could be the reason you don't have a traffic log entry.

Also, make sure the GP client IP is configured to access your internal DNS(as well as the network reachbilty) as you are using internal resolver IP in the GP configuration.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!