[Last Call] Learn how to a build a cloud-first strategyRegister Now


selective DNS when using VPN

Posted on 2012-09-12
Medium Priority
Last Modified: 2012-10-10

i am looking for a way to control where DNS lookups are going when my users are connected to a VPN with my checkpoint firewall.

we use a Web security solution provider in the cloud (hosted web security).
this provider uses the DNS server location to determine the closest datacenter they have in the world.

my problem is, when my users connect to the VPN, all DNS traffic is routed to my HQ in Europe, even when i am in the APAC or the US, and thus returning a DC in europe.

can i enforce my windows 7/xp clients or my VPN settings to use the standard OS DNS server (from my ISP) for a particular domain, lets call this providerdomain.com and use the DNS server from the VPN connection for all other lookups to ensure intranet traffic keeps working?

i have full control in configuring settings on the windows client and the Checkpoint VPN client, so suggestions both ways will be fine.

I also CANNOT use the selective DNS option on my windows DNS servers, as this will still initiate the connection from the HQ in europe, and thus not solving the issue.

Thanks in advance for all the suggestions.
Question by:joash_herbrink
LVL 71

Expert Comment

ID: 38389977
Windows client OS does not support "split DNS" or "DNS forwarding". Servers do, but as you stated correctly, this is useless for your purpose.
SecuRemote / SecureClient of CP-1 seems to allow for split DNS, see https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=skI2065 for details - but that info might be outdated already.
LVL 81

Expert Comment

ID: 38390291
It depends on your VPN configuration.
You can set what Dns servers for the VPN with the search domain.
Is the VPN using slit I.e. it only sends remote/corporate LAN destined traffic or does your VPN policy is to secure all networks directing all external traffic through the VPN.

Author Comment

ID: 38390661
Hi Arnold,

the setup is allwing split VPN, as internet bound traffic exits directly from the client, and is not backhauled to the VPN concentrator.
is this searchdomain config setting somewhere specified in the CP manuals? i could not find any reference to it.

 The Evil-ution of Network Security Threats

What are the hacks that forever changed the security industry? To answer that question, we created an exciting new eBook that takes you on a trip through hacking history. It explores the top hacks from the 80s to 2010s, why they mattered, and how the security industry responded.


Author Comment

ID: 38390665
Thanks Qlemo, will check out the link.
LVL 59

Expert Comment

ID: 38473707
I've requested that this question be deleted for the following reason:

Not enough information to confirm an answer.

Accepted Solution

joash_herbrink earned 750 total points
ID: 38473637
it seems the solution proposed by Qlemo is only valid for an older version of CP.
i have been told by CP engineers this is no longer possible with the more recent versions of the CP products.

unfortunatly, that's it :-( so thread closed.
LVL 71

Expert Comment

ID: 38473708
Objecting, as the answer has been posted now by the asker: "You can't do that". http:#a38473637 should be accepted.

Featured Post

Vote for the Most Valuable Expert

It’s time to recognize experts that go above and beyond with helpful solutions and engagement on site. Choose from the top experts in the Hall of Fame or on the right rail of your favorite topic page. Look for the blue “Nominate” button on their profile to vote.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup" or a blinking cursor with black screen. A loop for Auto repair will start but fix nothing.  You will be panic as there are no back…
There are many software programs on offer that will claim to magically speed up your computer. The best advice I can give you is to avoid them like the plague, because they will often cause far more problems than they solve. Try some of these "do it…
This Micro Tutorial will teach you how to change your appearance and customize your Windows 7 interface to your unique preference. This will be demonstrated using Windows 7 operating system.
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
Suggested Courses

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question