- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-15-2022 02:51 AM
Hi Team,
one of our customers has configured spit tunnel with include routes (doesn’t configured domain and application)
issue was for windows user working as expected but for MAC user DNS not resolving ( Global produced state was connected )
Action Taken from our side :
++ We suggested update the global product version ( from 5.2.9 to 5.2.12)
++ Reinstalled global product with all extensions
++ confirmed split tunnel working as expected
++ Modied the configuration as per blow steps
1. split tunnel option bot network and DNS (windows only)= Yes
2.incloud routes and include domain and application
3.uppend local search dns to tunnel dns suffix (mac only ) = no
after above configuration windows user also not able to resolve dns
Thanks in advance....
11-15-2022 02:37 PM
Hello,
While I am sure the customer has reasons for configuring split tunnel, I highly recommend against it as you lose visibility as well as compliance.
Regards,
11-16-2022 02:56 PM
My recollection is that split-tunnels are not currently working in the Mac GP client, that there is a known limitation for this in the current GP releases. Unforutnately, it looks like the PA release notes server is currently down, just giving me errors back trying to pull the release notes.
11-16-2022 04:42 PM
Hi @sujithGovindaraj ,
I remember split-tunneling working fine on macOS with older GP clients, but split DNS did not. All DNS requests went through the tunnel. GP 5.2 now supports split DNS. https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-rele...
You may want to confirm on your GP client whether the issue you are encountering is split tunneling or split DNS.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!