Skip to content
DnsLister Forum

Where domain hunters compare notes

GlobalProtect 6.2.8 — one user can’t reach external sites after connecting, HIP passes, reinstall didn’t fix it

Running GlobalProtect client 6.2.8. One user on our VPN has a weird issue: after connecting, internal company URLs resolve and load fine, but external sites (e.g. google.com) time out. HIP check passes cleanly, no compliance issues. Proxy is configured correctly per policy.

It's isolated to this one user — everyone else on the same portal/gateway config and client version works fine.

What I've checked so far:

**•** PanGPS.log shows split tunnel with exclude routes (exclusiveDefaultRoute 0), default route 0.0.0.0/0 pushed through the tunnel — routing looks correct, external traffic should tunnel the same as internal **•** Repeated HandleDnsCallback: failed to parse dns req packet entries in the log around the time of the timeouts **•** HIP report checks return clean (hip-report-needed: no) **•** Full GP client reinstall (6.2.8) — issue persists 

Has anyone seen HandleDnsCallback: failed to parse dns req packet cause this kind of selective DNS failure on 6.2.8 specifically? Trying to narrow down whether this is client-side (AV/EDR intercepting DNS on the tunnel adapter, OS network stack) or something tied to this user's group/HIP profile on the gateway side. Any known bugs on this version, or pointers on what else to check, would help.

I don’t think there is bug on this version because other user on same GP version it’s working fine.

Source: r/paloaltonetworks · by /u/Aromatic_Neck8642

Leave a Reply

Your email address will not be published. Required fields are marked *