<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Resolution in Checkpoint SSL Network Externder in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204834#M4091</link>
    <description>&lt;P&gt;What do you have configured as dns suffix in remote access gateway settings (if any)?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Fri, 02 Feb 2024 02:22:45 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-02-02T02:22:45Z</dc:date>
    <item>
      <title>DNS Resolution in Checkpoint SSL Network Externder</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204643#M4089</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;we have several macos clients who need to connect to customer site via ssl vpn.&lt;BR /&gt;&lt;BR /&gt;when they use our viscosity/openvpn vpn and then connect to customer vpn with snx (i.e. use connect button for native applicatins in web portal), they can access internal ressources in our company network, as viscosity/openvpn is setting up split dns, so dns query to @ourdomain.com is handled by our internal dns server.&lt;BR /&gt;&lt;BR /&gt;when their macbook is located in the company internal network, they cannot resolve anything from internal @ourdomain.com dns names anymore after connecting to customer ssl vpn&amp;nbsp; , as ssl vpn is overwriting internal dns servers and that seems to be active globally then.&lt;BR /&gt;&lt;BR /&gt;how can this be resolved ?&lt;BR /&gt;&lt;BR /&gt;how can dns be resolved selectively, i.e. by target domain ?&lt;BR /&gt;&lt;BR /&gt;regards&lt;BR /&gt;roland&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 12:22:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204643#M4089</guid>
      <dc:creator>rolandk</dc:creator>
      <dc:date>2024-01-31T12:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution in Checkpoint SSL Network Externder</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204833#M4090</link>
      <description>&lt;P&gt;You may need a hotfix for this.&lt;BR /&gt;See: &lt;A href="https://support.checkpoint.com/results/sk/sk115279" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk115279&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 02:10:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204833#M4090</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-02T02:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution in Checkpoint SSL Network Externder</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204834#M4091</link>
      <description>&lt;P&gt;What do you have configured as dns suffix in remote access gateway settings (if any)?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 02:22:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204834#M4091</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T02:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution in Checkpoint SSL Network Externder</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204877#M4092</link>
      <description>&lt;DIV&gt;&lt;P&gt;&amp;gt;&amp;nbsp; When connect to SNX from Mac OS X, name resolution fails because it does not use the Office Mode IP address for DNS Server. Instead, it uses the DNS setting from Mac OS X.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Traffic capture on Mac OS X shows that DNS traffic leaves the physical interface instead of SNX (utun0).&lt;BR /&gt;&lt;BR /&gt;&amp;gt; The issue only happens in DHCP environment, in which the Mac OS X machine obtains the IP address and DNS configuration from the DHCP Server.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;that does not apply for us, as snx changes the dns server to the customers dns server and so local name resulution in the office won't work anymore.&lt;BR /&gt;&lt;BR /&gt;we need per-domain resolution with split dns like in viscosity.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 02 Feb 2024 14:02:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204877#M4092</guid>
      <dc:creator>rolandk</dc:creator>
      <dc:date>2024-02-02T14:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution in Checkpoint SSL Network Externder</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204887#M4093</link>
      <description>&lt;P&gt;we do not have access to access gateway settings, as it is owned by customer&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 14:03:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204887#M4093</guid>
      <dc:creator>rolandk</dc:creator>
      <dc:date>2024-02-02T14:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution in Checkpoint SSL Network Externder</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204889#M4094</link>
      <description>&lt;P&gt;This is what Im referring to&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24358i2A3388DAB008A866/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 14:06:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/204889#M4094</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T14:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution in Checkpoint SSL Network Externder</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/205535#M4096</link>
      <description>&lt;P&gt;Like I said, you may need a hotfix for this, which is mentioned in the SK I linked to.&lt;BR /&gt;If your customer supports it, you can also use Endpoint Security VPN client to connect on macOS, which works correctly in this scenario.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 23:22:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/205535#M4096</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-08T23:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Resolution in Checkpoint SSL Network Externder</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/207689#M4097</link>
      <description>&lt;P&gt;I am not sure about MacOS, but in Windows, you can assign each interface a priority. The DNS server for the interface with the highest priority is used for all lookups. When you connect to SNX, it promotes the metric of that adapter (routing your DNS requests through the new CheckPoint Virtual Network adapter) to 1, but keeps the other connections at a higher value (e.g. 25, but you can check that by listing the routing table on the host).&lt;/P&gt;&lt;P&gt;If you want to use the DNS server on the LAN whilst connected to SNX, you could either promote that interface by giving it a lower metric, or you could manually configure the SNX Virtual Network Adapter to use your DNS server.&lt;/P&gt;&lt;P&gt;If you want to resolve your DNS selectively (based on target domain), you could use a DNS intercept tool, which intercepts DNS queries at the system level, and directs them to the appropriate DNS servers based on a set of predefined rules. I think on MAC, you may even be able to use DNSMASQ.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 02:07:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/DNS-Resolution-in-Checkpoint-SSL-Network-Externder/m-p/207689#M4097</guid>
      <dc:creator>JH_Ranger</dc:creator>
      <dc:date>2024-03-04T02:07:50Z</dc:date>
    </item>
  </channel>
</rss>

