DNS based traffic shows incomplete when connected to GlobalProtect

Showing results for 
Show  only  | Search instead for 
Did you mean: 

DNS based traffic shows incomplete when connected to GlobalProtect

L2 Linker

Hi all


I have an issue noticed that DNS-based traffic shows incomplete when users are connected to GlobalProtect.
The same traffic is fine when we disconnect from GlobalProtect 


Cyber Elite
Cyber Elite

DNS server is public?

GlobalProtect is in separate zone?

GlobalProtect zone is in SNAT outgoing policy?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

​-Is the DNS server public? no 
​-Is GP in a separate zone and NAT outgoing policy?yes 

L2 Linker

Hey anyone with a fix for this?



Hi @Salathiwe ,

Just to clarify does your DNS actually work so user connected to GlobalProtect are able to resolve domains? Or you just noticed some DNS traffic that is incomplete, but there is no actual issues with name resolution?


If the traffic is sent to internal DNS server (that is behind your firewall) and it is incomplete, it looks like you need to troubleshoot the path from your firewall (more specifically GP IP pool range) to the internal DNS server.


And what do you mean by "same traffic is fine when GP is disconnected? Are you using GP tunnel mode when user is inside your LAN so it can still reach internal DNS?

  • 4 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!