Would be interested to see how that option goes when configured under the app agent... did you just put the domain url in there of you had to type in http://<website>
For me adding that domain to split tunnel did not resolve the issue, it only worked once i added to pre-logon policies.
Under the app option, we will be able to override addresses as IP based only (e.g. 18.104.22.168/32, 10.1.2.0/24).
Our initial tests suggested improved connectivity towards MS NLSA DNS resolutions www.msftconnecttest.com, we aren't convinced with the solution yet as extensive users on GP were impacted due to this it has to be tested widely to see as a workable solution.
p.s., TAC suggested a list of IP or IP's can be to a certain limit only 32 I reckon I do not have that in writing, unfortunately.
Thank you @rajjair
I've lost count of the number of hours I had sent researching this and trying to understand how I would resolve this issue. The articles you linked explained the technology well.
I too had to create the pre-logon rule allowing access to just that website, after that all works perfectly. Thanks again for sharing this solution.
Well we had to do the same on all our vsys, spinning a new pre rule to permit pre logon GP users to connect back to www.msftconencttest.com over 80 & 443 and it started to work
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!