<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Capsule VPN - DNS Resolving issue in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Capsule-VPN-DNS-Resolving-issue/m-p/108302#M9338</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the limitation stems from Windows limitations on third party VPN Clients.&lt;BR /&gt;We were looking for a workaround, and with help from local office we may have seem to found one, by replacing the Office Mode Domain with "."&lt;/P&gt;&lt;P&gt;Its not a very well documented limitation for the client and doesnt work very well with the "Route All" functionality that is supported from the client.&lt;BR /&gt;Currently testing the workaround in production, but so far it looks good. Its not "officially supported" by Check Point but it seems to do the trick for now&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jan 2021 13:18:23 GMT</pubDate>
    <dc:creator>PetterD</dc:creator>
    <dc:date>2021-01-20T13:18:23Z</dc:date>
    <item>
      <title>Check Point Capsule VPN - DNS Resolving issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Capsule-VPN-DNS-Resolving-issue/m-p/107704#M9336</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Im having an issue with Check Point Capsule VPN (Windows Store) Client and resolving external dns-names.&lt;/P&gt;&lt;P&gt;We have a customer that uses Check Point Capsule VPN Client and have defined Office Mode DNS-servers, internal DNS-suffix etc. Customer also uses "Route all traffic" via the VPN-gateway (required).&lt;/P&gt;&lt;P&gt;Solution has been working fine for the users that have tested this in a PoC but now the have went into production several uses complain about multiple external internet-sites that doesnt work.&lt;/P&gt;&lt;P&gt;Checking known limitations, capsule VPN Admin guide etc we find no settings that should impact this, but in sk112164 we see that:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;"Windows 8.1 Plugin and Capsule VPN app for Windows 10 can only resolve host names whose domain suffix is configured in the Office Mode Optional Param"&lt;/P&gt;&lt;P&gt;So the issue we are having is that Capsule VPN ignores the Office Mode DNS-servers for lookups to external hosts and uses each clients-local DNS-server, where some of these DNS-servers rejects DNS-queries from the Firewall they connect via..&lt;/P&gt;&lt;P&gt;This seems like a "logical flaw" in the use of Capsule VPN and "Route All" and causes us a major headache...&lt;BR /&gt;A service request has been created with TAC waiting for input.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Anyone have any experience with / any input on if we can solve this somehow without changing local DNS-servers on a few thousand users that already uses Capsule VPN for multiple Check Point gateways or switch to another client ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;BR /&gt;Petter&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 12:04:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Capsule-VPN-DNS-Resolving-issue/m-p/107704#M9336</guid>
      <dc:creator>PetterD</dc:creator>
      <dc:date>2021-01-13T12:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Capsule VPN - DNS Resolving issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Capsule-VPN-DNS-Resolving-issue/m-p/107777#M9337</link>
      <description>&lt;P&gt;Keep in mind that Capsule VPN is merely a wrapper for the VPN functionality built into Windows 10.&lt;BR /&gt;I’m guessing that’s where this particular limitation stems from.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 04:03:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Capsule-VPN-DNS-Resolving-issue/m-p/107777#M9337</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-14T04:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Capsule VPN - DNS Resolving issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Capsule-VPN-DNS-Resolving-issue/m-p/108302#M9338</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the limitation stems from Windows limitations on third party VPN Clients.&lt;BR /&gt;We were looking for a workaround, and with help from local office we may have seem to found one, by replacing the Office Mode Domain with "."&lt;/P&gt;&lt;P&gt;Its not a very well documented limitation for the client and doesnt work very well with the "Route All" functionality that is supported from the client.&lt;BR /&gt;Currently testing the workaround in production, but so far it looks good. Its not "officially supported" by Check Point but it seems to do the trick for now&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 13:18:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Capsule-VPN-DNS-Resolving-issue/m-p/108302#M9338</guid>
      <dc:creator>PetterD</dc:creator>
      <dc:date>2021-01-20T13:18:23Z</dc:date>
    </item>
  </channel>
</rss>

