We are investigating an issue where reverse DNS lookups stopped working after enabling GlobalProtect Split Tunnel (Both Network Traffic and DNS). We have verified that the GlobalProtect tunnel, routing, and DNS server connectivity are functioning correctly, and forward DNS resolution continues to work as expected. Testing confirmed that the issue is limited to reverse DNS (PTR) lookups, which return NXDOMAIN responses. We reviewed Palo Alto documentation, validated that the issue is not related to licensing, performed live troubleshooting with the customer, and are currently investigating whether DNS split-tunnel processing of PTR queries, including in-addr.arpa handling, is contributing to the behavior. Any guidance from the community on reverse lookup support with GlobalProtect DNS split tunneling would be appreciated
submitted by /u/TastyCicada8582 to r/paloaltonetworks
[link] [comments]
Source: r/paloaltonetworks · by /u/TastyCicada8582