<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: per client DNS Server selection in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/per-client-DNS-Server-selection/m-p/254131#M1733</link>
    <description>&lt;P&gt;I resolved this by changing the interface metric on the checkpoint mobile client to be higher.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jul 2025 18:08:48 GMT</pubDate>
    <dc:creator>Sam2</dc:creator>
    <dc:date>2025-07-28T18:08:48Z</dc:date>
    <item>
      <title>per client DNS Server selection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/per-client-DNS-Server-selection/m-p/254125#M1732</link>
      <description>&lt;P&gt;We are looking to migrate from our current recursive dns provider to a new one. Both providers provide a roaming agent that allows our sec teams to approve/deny access to specific domains by user.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We currently disable our roaming agent when the checkpoint vpn connects and force all dns to our on-premise dns servers. With our new client we are looking to keep it enabled and only send DNS traffic to the VPN if it matches our domain.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We have 3 VPN solutions deployed. SNX, Checkpoint Mobile, and Capsule Connect.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is there a way to force DNS servers by client? I want both SNX and Capsule to be provided with DNS servers via office mode but not Checkpoint Mobile.&amp;nbsp; I have looked at ipassignment.conf but that only allows for LDAP groups. We typically only use SNX for external contractors, so LDAP would apply fine, but capsule is used by employees, and if I use an LDAP group for them it will prevent the roaming agent from functioning on the users assigned to a capsule related LDAP group.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 16:51:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/per-client-DNS-Server-selection/m-p/254125#M1732</guid>
      <dc:creator>Sam2</dc:creator>
      <dc:date>2025-07-28T16:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: per client DNS Server selection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/per-client-DNS-Server-selection/m-p/254131#M1733</link>
      <description>&lt;P&gt;I resolved this by changing the interface metric on the checkpoint mobile client to be higher.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 18:08:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/per-client-DNS-Server-selection/m-p/254131#M1733</guid>
      <dc:creator>Sam2</dc:creator>
      <dc:date>2025-07-28T18:08:48Z</dc:date>
    </item>
  </channel>
</rss>

