How to bypass Prisma Access DNS Proxy configurations for specific Mobile Users

How to bypass Prisma Access DNS Proxy configurations for specific Mobile Users

5429
Created On 10/28/21 20:34 PM - Last Modified 01/21/22 02:19 AM


Objective


To instruct on creating specific dns settings that bypasses the default DNS proxy Object for Mobile Users, for troubleshooting or other use cases.



Environment


  • Prisma Access Mobile Users


Procedure


In order to have specific DNS settings for a specific user / user groups that precedes the Prisma Access DNS proxy configurations you can perform the following.

  1. Create a user/user Group specific gateway agent configuration from the following location

[Mobile_User_Template] Network > GlobalProtect > Gateways > GlobalProtect_External_Gateway > Agent

  1.   Select the Network Services tab to configure DNS settings that will are assigned to the virtual network adapter on the endpoint when the GlobalProtect app establishes a tunnel with the gateway. 

Note: This DNS setting configuration is given precedence over Prisma Access DNS configuration in Onboarding section from Mobile Users

  1. Create a security rule to allow traffic from the Mobile user subnet to the intended DNS Server in the [Mobile User Device Group] Policies > Security
 


Additional Information


Prisma Access leverages DNS Proxy and offers multiple configurations from Mobile User onboarding section as discussed in the following document

DNS Resolution for Mobile Users—GlobalProtect and Remote Network Deployment



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004MAbCAM&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language