Netskope is not compatible with Google or Cloudflare public DNS servers (8.8.8.8, 8.8.4.4, 1.1.1.1). This is well known and prevents resolution by NPA for all our configured private apps.
Based upon our testing (and trial and error) the following public DNS servers are working with NPA for our users and we must update our fleet of Macs as needed.
- Comcast (Xfinity): 75.75.75.75, 75.75.76.76
- AT&T: 68.94.156.1, 68.94.157.1
- Frontier: 185.228.168.168, 185.228.169.168
- Quad9 Public DNS Servers: 9.9.9.9, 149.112.112.112
- Fortinet Public DNS servers : 208.91.112.52 , 208.91.112.53
I would like to suggest Netskope maintain a list of known good public DNS servers that work with NPA. This would include updating the list when necessary, due to services not working anymore, etc. In a Work From Home (WFH), traveling, or foreign work force environment, we consistently run into problems with access to private apps due to this issue.
As a final resolution I would like to recommend Netskope deploy and maintain public DNS servers that the NS Client would automatically use, with the option to disable as needed. Thoughts?