selective DNS when using VPN

Posted on 2012-09-12
Last Modified: 2012-10-10

i am looking for a way to control where DNS lookups are going when my users are connected to a VPN with my checkpoint firewall.

we use a Web security solution provider in the cloud (hosted web security).
this provider uses the DNS server location to determine the closest datacenter they have in the world.

my problem is, when my users connect to the VPN, all DNS traffic is routed to my HQ in Europe, even when i am in the APAC or the US, and thus returning a DC in europe.

can i enforce my windows 7/xp clients or my VPN settings to use the standard OS DNS server (from my ISP) for a particular domain, lets call this and use the DNS server from the VPN connection for all other lookups to ensure intranet traffic keeps working?

i have full control in configuring settings on the windows client and the Checkpoint VPN client, so suggestions both ways will be fine.

I also CANNOT use the selective DNS option on my windows DNS servers, as this will still initiate the connection from the HQ in europe, and thus not solving the issue.

Thanks in advance for all the suggestions.
Question by:joash_herbrink
    LVL 67

    Expert Comment

    Windows client OS does not support "split DNS" or "DNS forwarding". Servers do, but as you stated correctly, this is useless for your purpose.
    SecuRemote / SecureClient of CP-1 seems to allow for split DNS, see for details - but that info might be outdated already.
    LVL 76

    Expert Comment

    It depends on your VPN configuration.
    You can set what Dns servers for the VPN with the search domain.
    Is the VPN using slit I.e. it only sends remote/corporate LAN destined traffic or does your VPN policy is to secure all networks directing all external traffic through the VPN.

    Author Comment

    Hi Arnold,

    the setup is allwing split VPN, as internet bound traffic exits directly from the client, and is not backhauled to the VPN concentrator.
    is this searchdomain config setting somewhere specified in the CP manuals? i could not find any reference to it.


    Author Comment

    Thanks Qlemo, will check out the link.
    LVL 59

    Expert Comment

    I've requested that this question be deleted for the following reason:

    Not enough information to confirm an answer.

    Accepted Solution

    it seems the solution proposed by Qlemo is only valid for an older version of CP.
    i have been told by CP engineers this is no longer possible with the more recent versions of the CP products.

    unfortunatly, that's it :-( so thread closed.
    LVL 67

    Expert Comment

    Objecting, as the answer has been posted now by the asker: "You can't do that". http:#a38473637 should be accepted.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
    If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
    The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
    With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

    761 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    12 Experts available now in Live!

    Get 1:1 Help Now