<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split-DNS value not passing to Mac OS X IPSec client in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313153#M952261</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When an ISP's DNS server is included in the Split Tunneling Network List and Split DNS Names are configured, all DNS queries to domains other than those in the Split DNS Names list are not resolved. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By definition, split DNS is used so that only certain domains get resolved by corporate DNS servers, while rest go to public (ISP-assigned) DNS servers. To enforce this feature, the VPN Client directs DNS queries that are about hosts on the Split DNS Names list to corporate DNS servers, and discards all DNS queries that are not part of the Split DNS Names list. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem occurs when the ISP-assigned DNS servers are in the range of the Split Tunneling Network List. In that case, all DNS queries for non-split-DNS domains are discarded by the VPN Client. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To avoid this problem, remove the ISP-assigned DNS server from the range of the Split Tunneling Network List, or do not configure split DNS (CSCee66180). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Jun 2009 20:29:15 GMT</pubDate>
    <dc:creator>smalkeric</dc:creator>
    <dc:date>2009-06-29T20:29:15Z</dc:date>
    <item>
      <title>Split-DNS value not passing to Mac OS X IPSec client</title>
      <link>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313152#M952260</link>
      <description>&lt;P&gt;I have a MacOS X IPSec client that isn't receiving the split-dns setup from my ASA 5505.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the relevant data from my ASA device:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy vpnpolicy attributes&lt;/P&gt;&lt;P&gt; wins-server none&lt;/P&gt;&lt;P&gt; dns-server value 192.168.1.3&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec l2tp-ipsec svc webvpn&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value split_tunnel_list&lt;/P&gt;&lt;P&gt; default-domain value workdomain1.com&lt;/P&gt;&lt;P&gt; split-dns value workdomain1.com workdomain2.com.local &lt;/P&gt;&lt;P&gt;tunnel-group myvpn type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group myvpn general-attributes&lt;/P&gt;&lt;P&gt; address-pool vpnpool&lt;/P&gt;&lt;P&gt; authentication-server-group vpn&lt;/P&gt;&lt;P&gt; authentication-server-group (inside) vpn&lt;/P&gt;&lt;P&gt; default-group-policy vpnpolicy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second domain isn't being passed to the client.  Here's the resolv.conf before/after IPSec connection:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mark-petersons-macbook-pro:~ peterson$ more /etc/resolv.conf&lt;/P&gt;&lt;P&gt;domain myhomedomain.net&lt;/P&gt;&lt;P&gt;nameserver 68.94.156.1&lt;/P&gt;&lt;P&gt;nameserver 151.164.8.201&lt;/P&gt;&lt;P&gt;/etc/resolv.conf (END) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mark-petersons-macbook-pro:~ peterson$ more /etc/resolv.conf&lt;/P&gt;&lt;P&gt;domain workdomain1.com&lt;/P&gt;&lt;P&gt;search workdomain1.com&lt;/P&gt;&lt;P&gt;nameserver 68.94.156.1&lt;/P&gt;&lt;P&gt;nameserver 151.164.8.201&lt;/P&gt;&lt;P&gt;/etc/resolv.conf (END) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas what the problem could be?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:31:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313152#M952260</guid>
      <dc:creator>petersonmd</dc:creator>
      <dc:date>2020-02-21T11:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Split-DNS value not passing to Mac OS X IPSec client</title>
      <link>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313153#M952261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When an ISP's DNS server is included in the Split Tunneling Network List and Split DNS Names are configured, all DNS queries to domains other than those in the Split DNS Names list are not resolved. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By definition, split DNS is used so that only certain domains get resolved by corporate DNS servers, while rest go to public (ISP-assigned) DNS servers. To enforce this feature, the VPN Client directs DNS queries that are about hosts on the Split DNS Names list to corporate DNS servers, and discards all DNS queries that are not part of the Split DNS Names list. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem occurs when the ISP-assigned DNS servers are in the range of the Split Tunneling Network List. In that case, all DNS queries for non-split-DNS domains are discarded by the VPN Client. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To avoid this problem, remove the ISP-assigned DNS server from the range of the Split Tunneling Network List, or do not configure split DNS (CSCee66180). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jun 2009 20:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313153#M952261</guid>
      <dc:creator>smalkeric</dc:creator>
      <dc:date>2009-06-29T20:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Split-DNS value not passing to Mac OS X IPSec client</title>
      <link>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313154#M952262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not quite sure I understand.  My home ISP is assigning me two DNS servers - 69.94.156.1 and 151.164.8.201.  My corporate DNS server - as configured by my VPN settings on the ASA - is 192.168.1.3.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no overlap between my split-tunnel list and the 2 ISP-assigned DNS servers.  The split-tunnel list includes 192.168.1.x, 192.168.2.x, 192.168.10.x, and 192.168.99.x.  That's it.  The problem is that the second domain that I've specified in my search list isn't being passed on to the client.  I've even tried switching the order of the domains - no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jun 2009 20:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313154#M952262</guid>
      <dc:creator>petersonmd</dc:creator>
      <dc:date>2009-06-29T20:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Split-DNS value not passing to Mac OS X IPSec client</title>
      <link>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313155#M952263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you get any solutions for this problem? I am experiencing similar issue trying to configure split-dns for my sslVPN users using anyconnect vpn client version 2.3.2016.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Oct 2009 19:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313155#M952263</guid>
      <dc:creator>ajamua</dc:creator>
      <dc:date>2009-10-28T19:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Split-DNS value not passing to Mac OS X IPSec client</title>
      <link>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313156#M952264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Split dns is not supported on Anyconnect...&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/vpngrp.html#wp1135689" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/vpngrp.html#wp1135689&lt;/A&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Nov 2009 21:38:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313156#M952264</guid>
      <dc:creator>fashour</dc:creator>
      <dc:date>2009-11-04T21:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: Split-DNS value not passing to Mac OS X IPSec client</title>
      <link>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313157#M952265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is now on AnyConnect 2.4.  From the release notes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New Feature Overviews&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following sections describe the new features in Release 2.4:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢Split DNS Fallback &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Split DNS Fallback&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the group policy on the security appliance specifies the names of the domains to be tunneled, AnyConnect tunnels only DNS queries that match those domains. It refuses all other DNS queries. The DNS resolver receives the refusal from the client and retries, this time using the public interface instead of AnyConnect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This feature requires that you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢Configure at least one DNS server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;â&amp;#128;¢Enable split-tunneling &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 21:02:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313157#M952265</guid>
      <dc:creator>tunderhay</dc:creator>
      <dc:date>2009-11-05T21:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Split-DNS value not passing to Mac OS X IPSec client</title>
      <link>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313158#M952266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seeing a similar issue with AnyConnect 2.4.1012.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config I have on a IOS device works perfectly on a Windows client, but on a Mac OS X 10.5 client it's not playing ball.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In terminal, I can do a 'host' on a server that resides at the other end of the SSL VPN, but if I try and ping it, it's replying that the host is unknown:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(host names changed)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acid:~ drew$ ping www.internal.server.com&lt;/P&gt;&lt;P&gt;ping: cannot resolve &lt;A href="www.internal.server.com:" target="_blank"&gt;www.internal.server.com:&lt;/A&gt; Unknown host&lt;/P&gt;&lt;P&gt;acid:~ drew$&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;acid:~ drew$ host www.internal.server.com&lt;/DIV&gt;&lt;DIV&gt;www.server.com is an alias for host.server.com.&lt;/DIV&gt;&lt;DIV&gt;host.server.com has address 192.168.1.1&lt;/DIV&gt;&lt;DIV&gt;host.server.com mail is handled by 0 mx1.server.com.&lt;/DIV&gt;&lt;DIV&gt;host.server.com mail is handled by 10 mx2.server.com.&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;resolv.conf looks fine:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;domain server.com&lt;/DIV&gt;&lt;DIV&gt;search loc.server.com loc2.server.com server.com loc3.server.com loc4.server.com&lt;/DIV&gt;&lt;DIV&gt;nameserver 192.168.1.1&lt;/DIV&gt;&lt;DIV&gt;nameserver 192.168.1.2&lt;/DIV&gt;&lt;DIV&gt;nameserver 139.130.4.4 (external DNS)&lt;/DIV&gt;&lt;DIV&gt;nameserver 139.130.4.5 (external DNS)&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;All the configs on the IOS router are just using split dns svc's for the domains in the search so it should be happy.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;As mentioned, works perfectly in windows but not in mac. Anyone have any ideas?&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;*edit*&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I've updated to the 2.5 beta for intel and it's working now. Apparently there's some problem with 2.4 release not working with the IP stack for the lookup zones and dns servers. I'll stick with the beta until the official one is released.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Mar 2010 03:30:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313158#M952266</guid>
      <dc:creator>Drew T</dc:creator>
      <dc:date>2010-03-24T03:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Split-DNS value not passing to Mac OS X IPSec client</title>
      <link>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313159#M952267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any progress on this issue?&amp;nbsp; I have a MAC user that is experiencing the Split-DNS problem using the IPSEC client as well - only queries for names in the first domain in the Split-DNS list is actually being tunneled to the corporated DNS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone opened a TAC case to work this issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 15:23:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313159#M952267</guid>
      <dc:creator>charrellc011699</dc:creator>
      <dc:date>2010-06-02T15:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Split-DNS value not passing to Mac OS X IPSec client</title>
      <link>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313160#M952268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not having an issue with 2.5.0217 client now. They recently released this from Beta. Have you tried that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 01:38:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/split-dns-value-not-passing-to-mac-os-x-ipsec-client/m-p/1313160#M952268</guid>
      <dc:creator>Drew T</dc:creator>
      <dc:date>2010-06-03T01:38:45Z</dc:date>
    </item>
  </channel>
</rss>

