Global Protect Split tunnel dns resoleving problems in MacOS configured with Private Relay

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Global Protect Split tunnel dns resoleving problems in MacOS configured with Private Relay

L1 Bithead

hey, 

i recently got an issue with a user that got a new MacOs laptop that had an issue with connecting to internal resources, looks like Chrome and Ping and also other client application would not work because the dns is not resolved.

 

there is an Apple feature called "Private Relay" it basically acts like a "vpn" that routes traffic through some gateway so the ISP etc wont see the user's traffic. that was probably collide with the GP client. 

if this feature is enabled on the user's intune this will be enabled by default on a new device that is linked to this user's intune.

this feature can be disabled on the user MacOS

 

DorMarcovitch_0-1723010525131.png

https://support.apple.com/en-il/102602 

 

 

1 accepted solution

Accepted Solutions

Hi @DorMarcovitch ,

 

Thank you for sharing this.

 

Note that you can also prevent the use of private relay on network level by blocking the DNS resolution for these two FQDNs

mask.icloud.com
mask-h2.icloud.com

As described by Apple documentation - https://developer.apple.com/icloud/prepare-your-network-for-icloud-private-relay/

View solution in original post

1 REPLY 1

Hi @DorMarcovitch ,

 

Thank you for sharing this.

 

Note that you can also prevent the use of private relay on network level by blocking the DNS resolution for these two FQDNs

mask.icloud.com
mask-h2.icloud.com

As described by Apple documentation - https://developer.apple.com/icloud/prepare-your-network-for-icloud-private-relay/

  • 1 accepted solution
  • 418 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!