<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AnyConnect MAC OSX exclude/include DNS not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5309133#M1121812</link>
    <description>&lt;P&gt;Ok, I think this fixed it.&lt;/P&gt;&lt;P&gt;Thanks for your help.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jul 2025 14:58:03 GMT</pubDate>
    <dc:creator>the-lebowski</dc:creator>
    <dc:date>2025-07-14T14:58:03Z</dc:date>
    <item>
      <title>AnyConnect MAC OSX exclude/include DNS not working</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308002#M1121753</link>
      <description>&lt;P&gt;I am trying to get this working to no avail.&amp;nbsp; Whether I exclude the domain I want to resolve locally or include the domain I want to resolve through the tunnel the client sends all requests through the tunnel.&amp;nbsp; I am specifying a DNS server on the group policy, 100.64.64.64 and it appears that regardless of whatever domain I try to dig 100.64.64.64 is always the responder.&amp;nbsp; &amp;nbsp;When I split exclude the users local DNS should be giving the answer but it isn't.&amp;nbsp; &amp;nbsp;"Send All DNS lookups through the tunnel" is set to no and I can see the domains on the include/exclude via AnyConnect client when either attribute is applied to that GP.&amp;nbsp; &amp;nbsp;But neither work to send a specific domain locally or a specific domain through the tunnel.&amp;nbsp; All DNS is still being sent through the tunnel no matter what.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea why this is?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thelebowski_0-1752178339822.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248024iA44776919E3B3470/image-size/medium?v=v2&amp;amp;px=400" role="button" title="thelebowski_0-1752178339822.png" alt="thelebowski_0-1752178339822.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;PRE&gt;group-policy test-GP attributes
 dns-server value 100.64.64.64
 vpn-idle-timeout 240
 vpn-session-timeout 840
 vpn-tunnel-protocol ssl-client
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value tunnel-networks
 client-bypass-protocol enable
 msie-proxy lockdown disable
 anyconnect-custom dynamic-split-include-domains value inside-domain&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;anyconnect-custom-attr dynamic-split-exclude-domains description dynamic dns split tunneling
anyconnect-custom-attr dynamic-split-include-domains description dynamic include tunneling\n

anyconnect-custom-data dynamic-split-exclude-domains outside-domain outside.test.com
anyconnect-custom-data dynamic-split-include-domains inside-domain inside.test.com&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 20:16:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308002#M1121753</guid>
      <dc:creator>the-lebowski</dc:creator>
      <dc:date>2025-07-10T20:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect MAC OSX exclude/include DNS not working</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308005#M1121754</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/116016-technote-AnyConnect-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client/116016-technote-AnyConnect-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Not all OS behaive same for DNS&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check this link&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 20:18:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308005#M1121754</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-10T20:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect MAC OSX exclude/include DNS not working</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308006#M1121755</link>
      <description>&lt;P&gt;I saw that link but not clear on how that helps, Its MAC OSX v4 only...and I think this section applies?&amp;nbsp;Only using v4 and no v6 configured anywhere.&amp;nbsp; If so it should work but it doesn't.&amp;nbsp; &amp;nbsp;I am really just trying to send a single domain across the tunnel and allow everything else to resolve locally.&amp;nbsp; &amp;nbsp;Can I do that with AC and OSX?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Split-DNS (tunnel-all DNS disabled, split-include configured)

If split-DNS is enabled for both IP protocols (IPv4 and IPv6) or it is only enabled for one protocol and there is no address pool configured for the other protocol:
True split-DNS, similar to Windows, is enforced. True split-DNS means that request which matches with the split-DNS domains are only resolved via the tunnel, they are not leaked to DNS servers outside the tunnel.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 20:23:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308006#M1121755</guid>
      <dc:creator>the-lebowski</dc:creator>
      <dc:date>2025-07-10T20:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect MAC OSX exclude/include DNS not working</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308021#M1121756</link>
      <description>&lt;P&gt;Hi friend&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The config you share in your real post is for dynamic split traffic not split dns&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For split dns you need such as below&amp;nbsp;&lt;/P&gt;
&lt;P&gt;group-policy MY-GP internal&lt;BR /&gt;group-policy MY-GP attributes&lt;BR /&gt;split-tunnel-policy tunnelspecified&lt;BR /&gt;split-tunnel-network-list value MY_ACL&lt;BR /&gt;split-dns value company.local internal.company&lt;BR /&gt;dns-server value 10.1.1.1 10.2.2.2&lt;/P&gt;
&lt;P&gt;The ACL of split must inlcude the internal dns server IP&lt;/P&gt;
&lt;P&gt;Here your Mac OS will send to resolve this internal.company via internal DNS server&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 21:20:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308021#M1121756</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-10T21:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect MAC OSX exclude/include DNS not working</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308459#M1121790</link>
      <description>&lt;P&gt;Ok&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;group-policy DNS-GP attributes
 dns-server value 100.64.64.64 100.64.64.65
 vpn-idle-timeout 240
 vpn-session-timeout 840
 vpn-tunnel-protocol ssl-client
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value Tunnel-VPN
 split-dns value inside.test.com
 split-tunnel-all-dns disable
 client-bypass-protocol enable
 msie-proxy lockdown disable&lt;/LI-CODE&gt;&lt;P&gt;That should do it or nah?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 22:31:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308459#M1121790</guid>
      <dc:creator>the-lebowski</dc:creator>
      <dc:date>2025-07-11T22:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect MAC OSX exclude/include DNS not working</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308550#M1121792</link>
      <description>&lt;P&gt;correct&lt;/P&gt;
&lt;P&gt;the domain inside.test.com must resolve by internal DNS server&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jul 2025 12:17:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308550#M1121792</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-12T12:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect MAC OSX exclude/include DNS not working</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308616#M1121801</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321108"&gt;@the-lebowski&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;It sounds like the DNS split tunneling isn’t working as expected on your Mac. A few things to double-check:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Make sure “Send All DNS Lookups Through the Tunnel” is set to No everywhere (group policy and profile).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Confirm your split DNS domains are correctly set and pushed in the AnyConnect profile.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;macOS can be tricky with DNS caching—try flushing the DNS cache or rebooting the device.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Also, check if the DNS server (100.64.64.64) is reachable and responding properly.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Split DNS on Mac can be a bit finicky, so testing on a Windows client might help narrow down the issue.&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jul 2025 16:42:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5308616#M1121801</guid>
      <dc:creator>wajidhassan</dc:creator>
      <dc:date>2025-07-12T16:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect MAC OSX exclude/include DNS not working</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5309133#M1121812</link>
      <description>&lt;P&gt;Ok, I think this fixed it.&lt;/P&gt;&lt;P&gt;Thanks for your help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 14:58:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-mac-osx-exclude-include-dns-not-working/m-p/5309133#M1121812</guid>
      <dc:creator>the-lebowski</dc:creator>
      <dc:date>2025-07-14T14:58:03Z</dc:date>
    </item>
  </channel>
</rss>

