QuestionQ25

PAN-OS Networking Configuration

An administrator configures a GlobalProtect gateway to use split tunneling for network traffic according to an access route. Users report that public web browsing works, but they cannot resolve internal server names. The administrator finds that every DNS query is being sent to the public DNS servers configured on users’ endpoints.

Which GlobalProtect portal setting should be configured to resolve this issue?

  • A Split tunneling for DNS and specify the internal corporate domains in the "Domain" list
  • B DNS Proxy feature on the firewall to point clients to the gateway IP for DNS
  • C "DNS Forwarding" option on the gateway's tunnel interface
  • D NAT rule to allow DNS traffic from the GlobalProtect clients to the internal DNS servers
Explanation

Split DNS directs queries for configured internal corporate domains to the DNS servers assigned by the GlobalProtect tunnel, while DNS for other domains can continue to use the endpoint’s local/public resolvers. This provides internal name resolution when traffic is split-tunneled by access route.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!