Global Protect - Problem with name resolution DNS/WINS

Reply
L3 Networker

Global Protect - Problem with name resolution DNS/WINS

Dears,

 

We are facing a strange problem... sometimes external users connected via global protect cannot resolve names without the sufrix domain... 

 

Example:

\\NAMESERVER

or

http://netflow:8080

 

Strange behavior below: when we ping that name we see that it is not being resolved...

But when we do a nslookup we see the name resolution is OK

 

ScreenShot162.jpg

ScreenShot163.jpg

 

browsing problems

ScreenShot161.jpg

 

 

Usually user has to disconnect global protect and connect again until the problem is solved by itself...

 

 

sometimes disable and reenable the PANGP virtual network card solves the problem as well

ScreenShot164.jpg

 

Does anyone seen that problem before ?

 

 

 

L7 Applicator

Do you have the domain DNS (and WINS if you use this) setup with the domain name suffixes on your global protect settings.

 

Nework > Global Protect Gateway > network settings

 

Screen Shot 2015-09-02 at 5.42.46 PM.png

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
L3 Networker

Hello my friend!

 

thanks for your help.. I have already done that....

 

I am very confused about that behavoir where user can resolve at "nslookup" but cannot resolve when pinging

 

 

L4 Transporter

hi,

 

this is (to 99% sure) not a GP problem.

In the past (some years ago) we also had a simular problem. Its a client problem.

 

check this out:

http://superuser.com/questions/495759/why-is-ping-unable-to-resolve-a-name-when-nslookup-works-fine

http://superuser.com/questions/220471/dns-resolution-issue-nslookup-works-but-web-ping-doesnt

http://www.fencepost.net/2009/11/dns-fails-nslookup-works-fix/

 

I'm sorry but I can't remember the correct solution but may you will find the way :)

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!