GlobalProtect Gateway is being used, and all traffic is being routed to the firewall except for some network.
DNS lookup takes a long time when I input the domain (website which not in the PC DNS table) that the browser accesses first while connected to a VPN
- DNS Lookup time takes about 5-10 seconds
The DNS server is using an internal server, and the network is belong to split tunneling exceptions.
I am wondering why DNS lookup processing is delayed.
Or is it correct that DNS lookup takes a long time during VPN connection?
The issue was resolved as follows.
Cause: Querying queries to all NICs that have DNS Lookup enabled, so lookup time increases while waiting for results from VPN NIC
Resolution: Register in paloalto registry to run batch script after VPN authentication.
The script content deletes the DNS Server settings of the VPN NIC to set DNS queries to use only the primary NIC of the PC.
This does not happen when i do the same.
I have 1 domain in "Domain Split Tunnel" and have left my DNS servers blank in the gateway services and have set both network and DNS in portal app.
as soon as i browse to the website that is in my split tunnel it resolves instantly with my local DNS.
As you said, I call the internal DNS server and get the IP right away.
However, the browser notificate that the host is being searched, and the DNS lookup time is very long.
Looking through wireshark during this time, vpc nic are not communicating with the target website.
The chrome/edge browser issue are the same. It doesn't appear to be a browser issue.
1. vpn connect
2. connect to website domain from browser, connect to internal DNS server from pc default nic
3. get IP from internal DNS server (There seems to be no problem so far.)
4. (vpn nic) The browser is looking for the host, and this is taking a long time.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!