<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Client split DNS creates timeouts on Windows client DNS  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-client-split-dns-creates-timeouts-on-windows-client-dns/m-p/821207#M960638</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nobody else having this problem? Can't be...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Feb 2008 23:39:09 GMT</pubDate>
    <dc:creator>c.schwarzfischer</dc:creator>
    <dc:date>2008-02-04T23:39:09Z</dc:date>
    <item>
      <title>VPN Client split DNS creates timeouts on Windows client DNS lookups</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-split-dns-creates-timeouts-on-windows-client-dns/m-p/821204#M960635</link>
      <description>&lt;P&gt;We have an ASA5510 with Windows VPN Clients (current stable version) connecting to it. I set up split DNS to force the clients to lookup the internal domains with the nameserver on our network.&lt;/P&gt;&lt;P&gt;Split DNS Config as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy VPN attributes&lt;/P&gt;&lt;P&gt; dns-server value 192.168.0.196&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec &lt;/P&gt;&lt;P&gt; password-storage enable&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value VPN_splitTunnelAcl&lt;/P&gt;&lt;P&gt; default-domain value myinternaldomain.de&lt;/P&gt;&lt;P&gt; split-dns value myinternaldomain.de myinternaldomain2.de&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when after connecting the clients make nslookups (on Windows XP), the internal names are looked up in no time. &lt;/P&gt;&lt;P&gt;When a public name like google.de is being looked up, nslookup runs into a timeout like this and finally answer the query.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; google.de&lt;/P&gt;&lt;P&gt;Server: [192.168.1.3]&lt;/P&gt;&lt;P&gt;Address: 192.168.1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS request timed out.&lt;/P&gt;&lt;P&gt;timeout was 2 seconds.&lt;/P&gt;&lt;P&gt;Nicht autorisierte Antwort:&lt;/P&gt;&lt;P&gt;Name: google.de&lt;/P&gt;&lt;P&gt;Addresses: 216.239.59.104, 72.14.221.104, 66.249.93.104&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tunnel traffic policy is simple:&lt;/P&gt;&lt;P&gt;access-list VPN_splitTunnelAcl standard permit our_main_private_net 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list VPN_splitTunnelAcl standard permit some_other_private_net_in_10_classA 255.128.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the MacOS Cisco VPN client, the problem doesn't exist!&lt;/P&gt;&lt;P&gt;The Setup has been tested on all different kinds of networks, wireless, DSL, anything. The issue is not limited to one computer only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-chris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:31:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-split-dns-creates-timeouts-on-windows-client-dns/m-p/821204#M960635</guid>
      <dc:creator>c.schwarzfischer</dc:creator>
      <dc:date>2019-03-11T11:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client split DNS creates timeouts on Windows client DNS</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-split-dns-creates-timeouts-on-windows-client-dns/m-p/821205#M960636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to split. If you do not have split tunneling configured for the VPN Client, you will not be able to use the DNS server of the Internet Service Provider (ISP) anymore. This is because all traffic is now encrypted and sent to the VPN server. &lt;/P&gt;&lt;P&gt;For more information on Configuring Split and Dynamic DNS on the Cisco VPN, refer to these documents&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_example09186a008015f324.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_example09186a008015f324.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2007 20:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-split-dns-creates-timeouts-on-windows-client-dns/m-p/821205#M960636</guid>
      <dc:creator>ebreniz</dc:creator>
      <dc:date>2007-11-20T20:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client split DNS creates timeouts on Windows client DNS</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-split-dns-creates-timeouts-on-windows-client-dns/m-p/821206#M960637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As can be seen in the config I posted, we DO split:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;split-tunnel-policy tunnelspecified &lt;/P&gt;&lt;P&gt;split-tunnel-network-list value VPN_splitTunnelAcl &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list VPN_splitTunnelAcl standard permit our_main_private_net 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list VPN_splitTunnelAcl standard permit some_other_private_net_in_10_classA 255.128.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All our traces show that splitting works just fine, the ISP nameserver can be contacted, only lookups take forever.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I figure this is a bug in the Windows version of the VPN client (I tried several versions), and does not occur AT ALL in the Mac version of the VPN client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now the problem is solved by not using split DNS and having everyone use the internal DNS to resolve all names - internal and public. This incurs a performace hit, of of course.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2007 21:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-split-dns-creates-timeouts-on-windows-client-dns/m-p/821206#M960637</guid>
      <dc:creator>c.schwarzfischer</dc:creator>
      <dc:date>2007-11-20T21:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client split DNS creates timeouts on Windows client DNS</title>
      <link>https://community.cisco.com/t5/network-security/vpn-client-split-dns-creates-timeouts-on-windows-client-dns/m-p/821207#M960638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nobody else having this problem? Can't be...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2008 23:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-client-split-dns-creates-timeouts-on-windows-client-dns/m-p/821207#M960638</guid>
      <dc:creator>c.schwarzfischer</dc:creator>
      <dc:date>2008-02-04T23:39:09Z</dc:date>
    </item>
  </channel>
</rss>

