GlobalProtect users cannot access excluded domains when split tunnel is configured
6058
Created On 10/21/20 02:22 AM - Last Modified 01/06/25 19:59 PM
Symptom
- GlobalProtect has been deployed with split tunnelling traffic to exclude a list of domains.
- The GlobalProtect logs shows the excluded domains are correctly excluded.
- Few of the users cannot reached these excluded domains.
- On browser Google Chrome, the error displayed is "ERR_ADDRESS_INVALID".
- When GlobalProtect is disabled, users can access to the excluded domains.
Environment
- Palo Alto Firewalls
- Supported PAN-OS
- GlobalProtect (GP) App
- Split-tunnel configured with domain exclusion
Cause
- The client is located in a IPv6 native network.
- DNS Server is in the IPv4 Network.
- The client is trying to reach the IPv4 DNS Server over the IPv6 network.
- To check, disconnect the GP App on client and ping one excluded domain to see the IP contacted is IPv4 or IPv6 format.
Resolution
- The resolution is to enable the Split DNS feature.
- When Split tunnel feature is enabled, the excluded domains / URLs are resolved using the public DNS server.
Additional Information
IPv4 format: 32 bits represented by 4 decimal number separated by dots.
IPv6 format: 128 bits represented by up to 8 hexadecimal numbers separated by colons.