Global Protect and AXON fleet 3 Dashboard

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Global Protect and AXON fleet 3 Dashboard

L1 Bithead

Good afternoon,

 

 

I am having trouble with connecting to this fleet 3 dashboard, with GP. It appears to be a a DNS issue, because it will find the local network when GP is disabled. The virtual adapter takes over, and uses our  DNS server, so it is not on a local network at that point. I have tried changing the DNS addresses, in the adpater and in GP, and it did not fix the issue. Thanks for any help.

 

Luke

 

8 REPLIES 8

Community Team Member

Hi @LukePowell ,

 

Sounds like your GP is configured to not allow split tunneling and send all traffic inside the tunnel.

Ask your admin to check the GP gateway configuration at Network > GlobalProtect > Gateways > Agent > Client Settings > Split Tunnel

 

kiwi_0-1714118687033.png

 

Hope this helps,

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L1 Bithead

wanted to share that when the axon body cameras are plugged back into the laptops to upload the data, they create a new network adapter. we tried split tunneling but lack of documentation from axon and their support didn't help. 

 

ended up doing a process based split tunnel for just for a specific user-id group that was using them with the 3 processes

 

axon fleet.exe, axon-agent.exe, axon evidence upload xt v2.exe 

L1 Bithead

Hello,

We are currently having a conflict with the free version of Global Protect VPN shutting down Fleet 3 dashboard on dash cameras on the MDC's  (Laptops), it appears to be a DNS issue. This issue started after we did an update on the Global Protect VPN from version 6.1.2-83 to current version 6.2.7-1047. Prior to this update we had no issues. I believe its a DNS issue, where GP is configured to not allow split tunneling and send traffic inside the tunnel. Please help on how to configure the free version GP? or a solution?

Thank you

Community Team Member

Hi @MtnV-IT ,

 

Please take a look at the techdocs for reference to GP features that require licensing. Split DNS is a feature on GP that requires a license. A work around would be to disable split tunneling. This would force all your traffic, including DNS, through your tunnel. 

 

With that being said, you will still want to ensure DNS is configured correctly internally. Is the fleet 3 application hosted internally? Is the URL you are trying to reach returning a public address or private address? 

 

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

Hello Jay,
thank you for your response. Our Fleet 3 aplication is hosted internally because we have a Cradle Point (Router) in between, So we made our WAN into a LAN to view the cameras with our Laptops (MDC's) when connected to the Cradle Point in each patrol unit. It sounds like we need to configure our DNS settings in the Cradle Point? and also disable split tunneling in the Cradle Point if we want to continue with the unliscensed version of Global Protect VPN? 
Thank You

Morning,

Im sorry for the slow response, just busy IT over here. Anyway, we ended up excluding the IP address scheme in the client settings under split tunnel. The only other thing we did was add axoncar.local in the app settings to allow traffic for that FQDN. Everything is working so far, I have not heard about the new updates causing issues. I will keep a eye out.

 

 

Luke

Good Morning,

just so you know we are using the unlicensed version of Global Protect VPN and I believe that what you just described, you can only do it on the licensed verision. Is that correct?

Thank you

Afternoon,

We don't pay any extra for a subscription use, like to use GP on a phone. It might be included in our license for the whole Firewall package. I would have to double check.

 

 

  • 1644 Views
  • 8 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!