- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-05-2024 05:21 AM
Hi,
We have circa 500 GlobalProtect clients. Setup is Always-on, network enforcement, SAML auth. In one region we also have Cisco Umbrella OpenDNS agents installed. This week we started seeing a problem localized to users in 1 country, France, where they could not connect to GlobalProtect.
Upon investigation, we narrowed it down to DNS resolution issues. DNS was set to 127.0.0.1 which is Cisco Umbrella OpenDNS agent. When we added in one of Google's DNS servers 8.8.8.8, everything started working but Cisco Umbrella would overwrite this setting back to just 127.0.0.1. It looks to me like GlobalProtect is blocking Cisco Umbrella from accessing its DNS servers. Does GP log dropped connections in any log file? I'd like to try to get the root cause of this, the workaround we have is to remove Cisco Umbrella from the clients, everything then starts to work.
I do have a called open Palo support but all I have been told is its not GlobalProtect.
Thanks
07-05-2024 12:02 PM
Hello,
The OpenDNS agent does redirect the OS DNS to itself. But the agent reaches out to OpenDNS for resolution. I would think that OpenDNS is blocking your DNS entry for your VPN for some reason? Or check the logs in the PAN to see why/if the traffic is getting blocked by it? GP shouldnt be blocking the traffic unless you have it configured that way.
Regards,
07-05-2024 11:38 PM
Hi,
Thanks for taking the time to read and respond. I am waiting for confirmation but I found a news story on OpenDNS saying that "Due to a court order in France and Portugal, the OpenDNS service is not currently available in these regions." This would explain why only our France colleagues were having problems and after uninstalling Cisco Umbrella is started working.
Thanks again!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!