We are looking to migrate from our current recursive dns provider to a new one. Both providers provide a roaming agent that allows our sec teams to approve/deny access to specific domains by user.
We currently disable our roaming agent when the checkpoint vpn connects and force all dns to our on-premise dns servers. With our new client we are looking to keep it enabled and only send DNS traffic to the VPN if it matches our domain.
We have 3 VPN solutions deployed. SNX, Checkpoint Mobile, and Capsule Connect.
Is there a way to force DNS servers by client? I want both SNX and Capsule to be provided with DNS servers via office mode but not Checkpoint Mobile. I have looked at ipassignment.conf but that only allows for LDAP groups. We typically only use SNX for external contractors, so LDAP would apply fine, but capsule is used by employees, and if I use an LDAP group for them it will prevent the roaming agent from functioning on the users assigned to a capsule related LDAP group.