Possible DNS Issue after GlobalProtect upgrade

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Possible DNS Issue after GlobalProtect upgrade

L3 Networker

Our GlobalProtect firewalls are running version 8.1.15 and another 9.1.4. We allow Split Tunnel, and one firewall has a 0.0.0.0/0 Include Access Route, and the other does not.  Both don’t have any Excluded routes. The one firewall (9.1.4) does have a Domain and Application Entry, Excluding *.webex.com and webex.com domain for testing this feature.

 

Both firewalls, the GP App Config settings are: Split-Tunnel Option: Network Traffic Only and Resolve All FQDNs using DNS servers Assigned by the Tunnel: Yes; both are default and have not changed.

About six months ago, we upgraded our GP clients from version 2.0.2 or 4.0.x to 5.0.8, and most are now on 5.2.3. We’ve noticed some DNS issues with some specific situations since the upgrade from 2.0.2 or 4.0.x.

 

Problem 1: We have a handful of users who use GP to VPN to our network and, when needed, connect to an outside vendor’s VPN (Anyconnect) to access data at the vendor while still on our VPN (due to a vendor whitelist). When they connect to the vendor, the users cannot access their server or ours. Testing one user, we notice we can ping our internal DNS server or others, but DNS requests are not working. Using Wireshark and capturing the local, GP, and AnyConnect interfaces and filtering on port 53, there is no DNS traffic at all. At the command prompt using nslookup and using multiple DNS servers, there is no port 53 traffic. Also, checking the firewall, there is no port 53 traffic during this time. Both our VPN and the vendor have Split-tunneling allowed.

 

Problem 2: On the GP gateway with the Domain Exclusion of webex.com, when a test user connects, they can access other sites, but webex.com won’t load. Using Wireshark and capturing the GP and local interfaces, I see reply DNS traffic from our internal DNS server to the user, but I don’t see the request from the user to the DNS server. Also, I see traffic for webex.com but trying to use both the GP and local interfaces. We did upgrade the GP client to version 5.2.6.

 

Were there significant DNS behavior changes from our previous GP versions of 2.0.2 or 4.0.x to 5.0.8, which may account for the strange issues we are experiencing?

Thank you for any help.

Jeff

Passionate about network infrastructure and all things Palo Alto Networks.
3 REPLIES 3

L7 Applicator

Hi @jeff6strings 

First to your last question: yes, there were major changes in dns behaviour. So depending on the configuration of the anyconnect vpn, this might be possible that this does not work if both vpn clients are active. Do you have details about the configuration of the anyconnect firewall? Is this client also pushing dns servers to the computers? Did you try to change the setting "Resolve All FQDNs using DNS servers Assigned by the Tunnel" to no to check if this makes any difference?

 

Might be a dumb question: but on the firewall where you configured the webex exclusion, you have the global protect subscription right?

 

Regards,

Remo

@Remo

I don't have many details, except it worked until our workstations were upgraded to GP 5.2. We did some troubleshooting with this vendor. They are pushing their DNS servers, so when our users connect to this vendor, they will have their local DNS (ISP or Google), our DNS servers, and the vendor's DNS. Our next step is to test the "Resolve All FQDNs using DNS servers Assigned by the Tunnel" with one user. We do have a current subscription of GP on our firewalls.

Thanks for the reply.

Jeff

Passionate about network infrastructure and all things Palo Alto Networks.

L0 Member

It helps if  " No direct access to local network." selected under Split Tunnel configuration.

  • 9456 Views
  • 3 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!