GlobalProtect Split DNS configuration

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

GlobalProtect Split DNS configuration

L0 Member

I'm looking to configure split tunneling and DNS in the following way:

 

If the DNS request is from a defined list, send the query to the tunnel DNS servers, if not, send through local adapter DNS. If the resulting reply contains an IP in the defined route, send it through the tunnel, otherwise out the local adapter.

 

Every configuration I have tried either binds the connection to the tunnel adapter if its in the domain list regardless of route config, or sends every request to every adapter until it gets a result.

3 REPLIES 3

Cyber Elite
Cyber Elite

just to make sure we're on the same page, did you set the app config Split-tunnel option to "Both Network Traffic and DNS"?

reaper_0-1714386139144.png

secondly: you need the GlobalProtect addon license for this to work, have you checked if it's installed/still valid ?

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L0 Member

Yep, license is valid, and we have that option set. Also have experimented with the "Resolve All FQDNs Using DNS Servers Assigned by the Tunnel" and either way doesn't give us the desired outcome.

 

Re-reading all the docs I'm thinking what I want is not possible and I will be forced to either tunnel all DNS traffic and not define domains (so that the access routes actually work), or define domains and excluded domains (which is a large dynamic list for us). To be clear this is required because we have hosts in our defined domains that we do not want to go through the tunnel (like cloud hosted websites).

L0 Member

Thanks for the information; I will keep it in mind. Are tight deadlines making you anxious? domypaper is here to help. Their service has been a game-changer for me. The writers are experienced, and the quality of their work is top-notch. I’ve used their https://domypaper.com/ service for several assignments, and they have always delivered on time. Their customer support is also very responsive and helpful. If you need reliable and professional writing assistance, this service is definitely worth considering.

  • 1100 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!