"Non-Existent Domain" error or "No such name" DNS Response when resolving Domain names

"Non-Existent Domain" error or "No such name" DNS Response when resolving Domain names

37341
Created On 09/30/20 16:44 PM - Last Modified 02/08/21 22:26 PM


Symptom


  • When trying to resolve domain name using the External DNS server(s) (NOT pushed by the GP Gateway), the below error message is seen on the CLI. 
Nslookup output
  • "No such name" response packet is received locally on the virtual adapter.
  • These responses are not visible if the capture is taken from the Gateway.
DNS packet capture


Environment


  • Global Protect (GP) Client App 4.0.3 and higher.
  • Global Protect Portal configured to  Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only). 


Cause


  • If the "Resolve "All" FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)" option is set to YES which is located at Network > Global Protect > Portals > (name) > Agent > App Tab, then all the DNS requests go out via the tunnel interface to the server/s which is pushed by the GP Gateway.
  • This DNS configuration pushed from GP Gateway is located at  GUI: Network > Global Protect > Gateways > (name)  > Agent > Network Services.
  • All DNS requests routed through the tunnel that are destined to any DNS servers that are NOT pushed by the Gateway are locally responded to with NXDOMAIN (Non-Existing Domain or "No such name").


Resolution


Solution 1:
  1. Use the DNS servers that are pushed via GP Gateway.
  2. Go to  GUI: Network > Global Protect > Gateways > (name)  > Agent > Network Services
  3. Configure the primary and secondary DNS
Solution 2:
  1. Go to GUI: Network > Global Protect > Portals > (name) > Agent > App Tab
  2. Set  "Resolve "All" FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)" option to NO. 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HB0rCAG&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language