Ask the community

NPA and DNS resolution issues

jschuele
New Contributor II
Netskope is not compatible with Google or Cloudflare public DNS servers (8.8.8.8, 8.8.4.4, 1.1.1.1). This is well known and prevents resolution by NPA for all our configured private apps.
 
Based upon our testing (and trial and error) the following public DNS servers are working with NPA for our users and we must update our fleet of Macs as needed.
  • Comcast (Xfinity):  75.75.75.75, 75.75.76.76
  • AT&T:   68.94.156.1, 68.94.157.1
  • Frontier:  185.228.168.168, 185.228.169.168
  • Quad9 Public DNS Servers: 9.9.9.9, 149.112.112.112
  • Fortinet Public DNS servers : 208.91.112.52 , 208.91.112.53

 

I would like to suggest Netskope maintain a list of known good public DNS servers that work with NPA. This would include updating the list when necessary, due to services not working anymore, etc. In a Work From Home (WFH), traveling, or foreign work force environment, we consistently run into problems with access to private apps due to this issue. 
 
 As a final resolution I would like to recommend Netskope deploy and maintain public DNS servers that the NS Client would automatically use, with the option to disable as needed. Thoughts?
3 Replies 3
qyost
Contributor III

That seems very peculiar, especially since the config docs reference opening access through your firewall to the Google DNS servers.   Is this just with NPA that you're seeing the issue?   If so, where are you doing the resolution, on the client or on the publisher? 

--
-Q.
jschuele
New Contributor II

We see this with NPA specifically. I have had multiple tickets open for this issue and the fix has always been to switch DNS providers on the Client side, which will over ride network based settings (router)..

Curious
New Contributor II

Hi @jschuele,

Great article, thank you so much for posting it. We also have an issue with name resolution when some of our employees work remotely and use NPA. As we are gradually reducing our VPN usage, the NPA usage is gaining momentum but so are the intermittent DNS issues.

I have an active support case but they haven't yet been able to identify the cause.

You have provided some valuable information. Thank you!

Subscribe

In order to view this content, you will need to sign in to your account. Simply click the "Sign In" button below

Sign In