- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-16-2023 09:51 AM
Hi Team,
I configured DNS proxy Interface e1/1 - 192.168.29.245 to clientless vpn.
DNS-Proxy resolves as,
Note:
DNS-Proxy interface is the interface that act as a proxy and queries for dataplane traffic instead of management interface setup-->service-->DNS.
so the question is why my management interface 192.168.29.250 queries for amazon.forest.in to the DNS server when the application is accessed by a user in clientless-vpn instead of my DNS-Proxy Interface 192.168.29.245.
I have attached both pcaps from server and the firewall.
02-20-2023 01:22 AM
If you have correctly also attached the DNS proxy under the "Proxy" tab in the Clientless VPN then it could be a bug because you have the managment ip address in the same subnet as the data interface and I think that there was such an issue but I can't say for 100%.
Test if also configuring the service route for DNS to use the data plane interface will help or if possible to place the data plane interface in seperate subnet than the managment interface.
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/service-routes
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!