DNS lookup takes a long time with GP

Showing results for 
Show  only  | Search instead for 
Did you mean: 

DNS lookup takes a long time with GP

L1 Bithead

GlobalProtect Gateway is being used, and all traffic is being routed to the firewall except for some network.


DNS lookup takes a long time when I input the domain (website which not in the PC DNS table) that the browser accesses first while connected to a VPN

- DNS Lookup time takes about 5-10 seconds


The DNS server is using an internal server, and the network is belong to split tunneling exceptions.


I am wondering why DNS lookup processing is delayed.

Or is it correct that DNS lookup takes a long time during VPN connection?


L7 Applicator

If you are using wireshark then what happens to the packet captures when the DNS replies in summary 3.  does it pause or do you see connection attempts to the correct address.


This packet is a capture of DNS query with nslookup command on PC's origin NIC(not VPN NIC).

The first second query is the result of a query against the DNS suffix, and the last is the correct query result.


Further confirmation

The VPN NIC also sends query packets to the internal DNS.
(Packets come into the Paloalto firewall. It doesn't seem to apply to the split-tunneling exception.)


1. Not all queries are requested, but only a few packets request duplicate DNS queries using Origin NICs and VPN NICs.
2. Packets requested by the VPN NIC only have a request and no response.
3. If the DNS lookup in the web browser takes a long time and the web page is displayed normally, the query packet is only sent to the PC NIC, and the packet is not generated from the VPN NIC.

It seems to be because the DNS query is being called concurrently with the PC NIC and VPN NIC.




L1 Bithead

The issue was resolved as follows.


Cause: Querying queries to all NICs that have DNS Lookup enabled, so lookup time increases while waiting for results from VPN NIC


Resolution: Register in paloalto registry to run batch script after VPN authentication.
The script content deletes the DNS Server settings of the VPN NIC to set DNS queries to use only the primary NIC of the PC.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!