弱端端配置在已启用的窗口上,用于连接到的WiFi适配器帖子 GP

弱端端配置在已启用的窗口上,用于连接到的WiFi适配器帖子 GP

29404
Created On 06/10/20 13:18 PM - Last Modified 04/19/21 16:41 PM


Symptom


  • GP连接后,通过视窗电源壳的弱端/弱收款状态从禁用更改为启用状态。
  • 禁用时电源壳输出 GP :
PS C:\WINDOWS\system32> Get-NetIPInterface | ft interfacealias,weakhostreceive,weakhostsend

interfacealias WeakHostReceive WeakHostSend
-------------- --------------- ------------
Bluetooth Network Connection Disabled Disabled
Local Area Connection* 2 Disabled Disabled
Local Area Connection* 1 Disabled Disabled
Loopback Pseudo-Interface 1 Disabled Disabled
WiFi Disabled Disabled
Bluetooth Network Connection Disabled Disabled
Local Area Connection* 2 Disabled Disabled
Local Area Connection* 1 Disabled Disabled
Loopback Pseudo-Interface 1
Disabled Disabled
WiFi Disabled Disabled
  • 连接时电源壳输出 GP :
PS C:\WINDOWS\system32> Get-NetIPInterface | ft interfacealias,weakhostreceive,weakhostsend

interfacealias WeakHostReceive WeakHostSend
-------------- --------------- ------------
Ethernet 4 Disabled Disabled
Bluetooth Network Connection Disabled Disabled
Local Area Connection* 2 Disabled Disabled
Local Area Connection* 1 Disabled Disabled
Loopback Pseudo-Interface 1 Disabled Disabled
WiFi Disabled Enabled
Ethernet 4 Disabled Disabled
Bluetooth Network Connection Disabled Disabled
Local Area Connection* 2 Disabled Disabled
Local Area Connection* 1 Disabled Disabled
Loopback Pseudo-Interface 1 Disabled Disabled
WiFi Disabled Enabled <======


 


Environment


全球保护客户端 5.0 + 5.1

Cause


启用优化拆分隧道功能时(即不启用基于域的拆分隧道或基于应用程序的拆分隧道),则 GP 5.x 将启用所有适配器上的"弱主持人"和"弱收款"(物理和虚拟)。

Resolution


RECOMMENDED RESOLUTION:
 
  1. 管理员 GP 可以配置基于域的假拆分隧道(例如,example.org),这将确保所有适配器上都禁用了弱座功能
  2. 除此之外,启用弱旅端引起的问题之一是 DNS 延迟解决。 (请参阅下面的注释)

NOTE:
在 DNS 5.2引入拆分隧道功能 GP 后, DNS 无论弱端功能的状态如何,分辨率都不应延迟。


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g0000008UNoCAM&lang=zh_CN&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language