Download PDF
GlobalProtect
Configure Split DNS for GlobalProtect App on Windows and macOS Endpoints
Table of Contents
Expand All
|
Collapse All
GlobalProtect Docs
-
-
-
-
- 6.3
- 6.2
- 6.1
- 6.0
-
- 6.3
- 6.2
- 6.1
- 6.0
Configure Split DNS for GlobalProtect App on Windows and macOS Endpoints
Enable users to access applications or local resources by specifying exclusions or
inclusions and send DNS queries.
- Before you begin:
- Launch the Web Interface.Configure a GlobalProtect gatewayTo modify an existing gateway or add a new one:
- On Panorama, select NetworkGlobalProtectGateways<gateway-config>.
- On Strata Cloud Manager (Prisma Access), ConfigurationNGFW and Prisma AccessConfiguration ScopePrisma AccessGlobalProtectSetupGlobalProtect AppTunnel Settings.
- On Strata Cloud Manager (NGFW), ConfigurationNGFW and Prisma AccessConfiguration ScopeAll FirewallsDeviceGlobalProtectPortals and GatewaysGateways.
Configure a split tunnel based on the domain.Enable network traffic or both network traffic and DNS.You can enable split DNS to allow users to direct their DNS queries for applications and resources over the VPN tunnel or outside the VPN tunnel in addition to network traffic.- Select NetworkGlobalProtectPortals<portal-config> Agent<agent-config> AppSplit Tunnel Option.
- On Strata Cloud Manager (NGFW), ConfigurationNGFW and Prisma AccessDeviceGlobalProtectPortals and GatewaysAgent SettingsAgent Tunnel Settings and thenAdd Agent Tunnel SettingsSplit Tunneling.
- Select Network Traffic Only to include and exclude rules that are applied only to network application traffic and not to DNS traffic. All DNS traffic goes through the VPN tunnel irrespective of the split tunnel based on the destination domain that you specified for inclusions and exclusions. When you select Both Network Traffic and DNS the split tunnel based on the destination domain that you specified for inclusions and exclusions are applied to the DNS traffic and the associated network application traffic for that domain.
Click OK twice.Commit the configuration.