DNS routing issue - OpenVPN inside GlobalProtect VPN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

DNS routing issue - OpenVPN inside GlobalProtect VPN

L1 Bithead

Hi,

 

We are running on a setup today where the client connects through L2TP to a Mikrotik-router and then connects with OpenVPN to the next environment.

 

Just now we are switchning to PA440 and GlobalProtect VPN IPSec instead of L2TP, and we have a problem now that the DNS lookup is not working when on the OpenVPN-tunnel inside the GlobalProtect VPN-tunnel (it was working out of the box in the L2TP and OpenVPN setup).

 

What am I missing? Some kind of static route in the GlobalProtect settings?

 

I can see on the client when I compare the different routing tables, that the traffic for the environment on the OpenVPN side is differently routed than before.

 

Thanks for the help!

4 REPLIES 4

Cyber Elite
Cyber Elite

you may need to configure split tunneling so the subnets reached through openvpn are not routed to globalprotect, else you'll get conflicts

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi Reaper,

 

Thanks for the reply.

 

Will that work, since we are whitelistening the IP on the GlobalProtect VPN-tunnel end site in the next environment, to be able to OpenVPN there? Maybe I lack a bit of knowledge here.

IP xxx.xxx.xxx.xxx => GP VPN yyy.yyy.yyy.yyy => OpenVPN zzz.zzz.zzz.zzz (yyy.yyy.yyy.yyy whitelisted)

Hello NisseNilson,

 

At that point, I think you need to play directly with the routing on the OS client.

Otherwise, you can set a VM in the host machine : the host machine with the GP client, the VM with the openVPN client and set the VM network to use the GP interface.

 

Olivier

PCSNE - CISSP

Best Effort contributor

Check out our PANCast Channel

Disclaimer : All messages are my personal ones and do not represent my company's view in any way.

Hi,

 

Thanks for the reply!

 

That's interesting, but maybe you are right about the routing table on the OS client. It is not that user friendly, but maybe I am able to find a way.
Do you have any insights or examples?

  • 902 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!