---
title: "Endpoint Compatibility Guidelines"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35404661/Endpoint%20Compatibility%20Guidelines"
format: markdown
---
This topic provides guidelines when you use <span style="color: #172b4d">Infoblox</span> Endpoint in conjunction with third-party software. When using certain VPN software, you might need to take extra steps or considerations to ensure compatibility with <span style="color: #172b4d">Infoblox</span> Endpoint. 

> 📝 - The Infoblox Endpoint Compatibility Guidelines apply only to **Mac and Windows platforms**. The **Infoblox Endpoint for Linux is not compatible with VPNs** as described in the [Linux Client Application Deployment](https://docs.infoblox.com/space/BloxOneThreatDefense/297666539/Linux+Client+Application+Deployment) documentation.
> 📝 - <span style="color: #000000">The provided information is for reference only. This information represents the results of lab testing in a controlled environment focused on individual protocol services. Enabling additional protocols, services, cache hit ratio for recursive DNS, and customer environment variables will affect performance. This information does not serve as an official list of supported or unsupported software for </span><span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint. To design and size a solution for a production environment, please contact your Infoblox Solution Architect.</span>
> 📝 - When you use Infoblox Endpoint with a VPN client, ensure that the VPN connection is established in the split-tunnel mode for every network protocol (IPv4 or IPv4/IPv6 for dual stack). If you have internal domains that are served by your local DNS servers and you want to reach them without interruption, you can consider adding them to the bypassed internal domain list, so that the DNS queries for these internal domains are sent to the local DNS servers instead of Infoblox Threat Defense. For more information about Infoblox Endpoint, see [Managing Endpoint.](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35374260)

<span style="color: #000000">The following table contains a list of commonly-used third-party VPN software and the compatibility information with </span><span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint.</span>

| ### **Third-Party Software** | ### **Compatibility Description** | ### **Known Issues** |
| --- | --- | --- |
| <span style="color: #292a2e">**Accops VPN**</span> | Infoblox Endpoint is compatable with Accops Workspace Client 7.1.0.1039 <span style="color: #292a2e">and above</span> | <span style="color: #292a2e">Users running versions earlier than </span>**7.1.0.1039**<span style="color: #292a2e"> may encounter issues resolving internal domains due to a DNS response query type mismatch issue identified in Accops.</span> |
| <span style="color: #000000">**Akamai Enterprise Applications Access (EAA) VPN**</span> | <span style="color: #172b4d">Infoblox</span> Endpoint is compatible with Akamai EAA VPN in the split-tunnel mode.<br>**Note**: Support for Akamai EAA VPN was verified only for Windows. | N/A |
| **Appgate VPN** | <span style="color: #172b4d">Infoblox</span> Endpoint is compatible with Appgate VPN in the split-tunnel mode.<br>**Note**: <span style="color: #172b4d">Infoblox</span> Endpoint supports Appgate SDP v5.3.2 or higher. | N/A |
| **AWS Client VPN Endpoint** | <span style="color: #172b4d">Infoblox</span> Endpoint is **not** compatible with AWS Client VPN Endpoint because when y<span style="color: #000000">our VPN configuration is set up to modify the DNS server on the network interface, </span><span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint cannot provide proper protection to your network.</span> | **Issue**: When AWS Client VPN Endpoint with DNS server IP address is configured, it modifies the DNS server IP configured on the network interface of the Client machine. As a consequence, <span style="color: #172b4d">Infoblox</span> Endpoint will not be able to provide proper protection as designed. |
| <span style="color: #172b4d">**Azure Client VPN Endpoint**</span> | <span style="color: #172b4d">Infoblox Endpoint (windows/mac) is compatible with Azure VPN client. For information on configuring Azure VPN, see </span><span style="color: #172b4d">*[Azure VPN Client Compatibility with Infoblox Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/1371734058/Azure+VPN+Client+Compatibility+with+Infoblox+Endpoint)*</span><span style="color: #172b4d">.</span> | N/A |
| **Check Point VPN** | <span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint is compatible with Check Point VPN in the split-tunnel mode.</span><br><span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint is </span><span style="color: #000000">**not**</span><span style="color: #000000"> compatible with Check Point VPN in the full-tunnel mode.</span> | N/A |
| **Cisco AnyConnect VPN** | <span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint is compatible only with the Internet portion of AnyConnect VPN in the split-tunnel mode.</span><br><span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint is </span><span style="color: #000000">**not**</span><span style="color: #000000"> compatible with AnyConnect in the full-tunnel mode. </span> | <span style="color: #000000">N/A</span> |
| **CloudFlare WARP** | Infoblox Endpoint is compatible with Cloudflare WARP (Traffic only mode enabled)<br>In the Cloudflare UI, the following settings must be enabled:<br>1. Click **Zero Trust**.
2. Click **Teams and Resources**.
3. Click **Devices**.
4. Click **Device Profiles**.
5. Configure the Device Profile (Enable the Traffic only Mode)<br>![The Cloudflare WARP configuration panel.](media://29c619c5-8451-479d-af07-775e737b986b) | CloudFlare WARP, once connected, overwrites the global resolvers with its own resolvers (127.0.2.2 and 127.0.2.3), causing Infoblox Endpoint to become unprotected. |
| **F5 VPN** | <span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint is </span><span style="color: #000000">**not**</span><span style="color: #000000"> compatible with F5 VPN in the split-tunnel mode. </span> | <span style="color: #000000">N/A</span> |
| **Fortinet FortiClient VPN** | <span style="color: #172b4d">Infoblox</span> Endpoint is compatible with Fortinet Forticlient VPN for windows devices.<br>Tested versions of Forticlient: 7.0.8.0308 Windows. | <span style="color: #000000">Infoblox recommends the following:</span><br>- <span style="color: #000000">Do not configure the client DNS address as “Same as client DNS Address".</span>
- <span style="color: #000000">Specify the DNS servers on the Fortigate server.</span> |
| **McAfee Web Gateway Proxy** | <span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint is partially compatible with the McAfee Web Gateway Proxy.</span><br><span style="color: #000000">Some of the features, such as block redirect or bypass redirect, might not function properly.</span> | <span style="color: #000000">**Issue**</span><span style="color: #000000">: When the McAfee Web Gateway proxy is enabled, all traffic goes through the proxy. Some of the features, such as block redirect and bypass redirect, might not function properly</span><br><span style="color: #000000">**Workaround**</span><span style="color: #000000">: Add the redirect IPs to the McAfee proxy bypass list. That way, the proxy is allowed to get the contents from the redirect IP during the HTTP(S) GET requests for block domains.</span> |
| **Netskope** | <span style="color: #172b4d">Infoblox</span> Endpoint is officially certified to run with Netskope client 93.0.1 and later, provided that you disable "Bypass Loopback DNS feature flag" on Netskope. As any other VPNs Netskope must be set to run as a split tunnel and also specifically in CASB mode, meaning that Netskope is only securing specified 80/443 Traffic rather than all 80/443, otherwise the redirect feature will not work.<br>For information on configuring Netskope with endpoint for Cloud applications, web traffic, or all traffic, see *[Netskope Compatibility with Infoblox Endpoint](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/1307967538)*. | **Issue**: The <span style="color: #172b4d">Redirect Page is not being displayed with the</span> IPv6 address due to the proxy.<br>**Workaround**:<br>1. Add all IPv4 and IPv6 redirect address to SSL decryption exception.
2. Add all IPv4 and IPv6 address to Traffic steering proxy by pass.
3. Enabled Treat as local address option in Traffic steering. |
| **OpenVPN** | <span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint is compatible with OpenVPN clients with the following configuration:</span><br>- <span style="color: #000000">Create an .ovpn file and import the .ovpn file into the OpenVPN client. For an example of an .ovpn file, click </span><span style="color: #000000">*[here](https://gist.github.com/renatolfc/f6c9e2a5bd6503005676)*</span><span style="color: #000000">.</span>
- <span style="color: #000000">When using an OpenVPN server, ensure that </span><span style="color: #000000">**persist-tun**</span><span style="color: #000000"> is not enabled on the server side, so that network changes are triggered during disconnect or reconnect.  </span> | N/A |
| **Palo Alto Networks GlobalProtect VPN** | <span style="color: #172b4d">Infoblox</span> Endpoint is compatible on windows with Palo Alto Networks GlobalProtect VPN using the below configuration:<br>- <span style="color: #000000">**Network**</span><span style="color: #000000"> > </span><span style="color: #000000">**GlobalProtect**</span><span style="color: #000000"> > </span><span style="color: #000000">**Portal**</span><span style="color: #000000"> > </span><span style="color: #000000">**[Portal Name**</span><span style="color: #000000">] > </span><span style="color: #000000">**Agent**</span><span style="color: #000000"> > </span><span style="color: #000000">**[Agent Name]**</span><span style="color: #000000"> > </span><span style="color: #000000">**App**</span><span style="color: #000000"> > </span><span style="color: #000000">**Split-Tunnel Option**</span><span style="color: #000000">. Do note that you have to set the "Split-Tunnel" option to "Both Network Traffic and DNS" instead of "Network Traffic Only".</span>
- <span style="color: #000000">**my-ip.debug.infoblox.com**</span><span style="color: #000000"> and </span><span style="color: #000000">**csp.infoblox.com**</span><span style="color: #000000"> must be must be resolvable from the Endpoint. You may need to add these domains to the "Include Domains" in your GlobalProtect gateway configurations.</span>
- <span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint must be able to access csp.infoblox.com on TCP port 443</span>
- <span style="color: #000000">Internal domains configured in the Infoblox Platform must also be added, if the configuration allows it, as “Include domains” in all configured Palo Alto Networks GlobalProtect gateways. Do note that not all configurations permit this. </span>
- <span style="color: #000000">Do note that "Internal Domains" on the GlobalProtect Gateway configuration can be found in the Palo Alto Networks PAN-OS web UI under (</span><span style="color: #000000">**Network**</span><span style="color: #000000"> > </span><span style="color: #000000">**GlobalProtect**</span><span style="color: #000000"> > </span><span style="color: #000000">**Gatways**</span><span style="color: #000000"> > </span><span style="color: #000000">**NameOfGateway**</span><span style="color: #000000"> > </span><span style="color: #000000">**Agent**</span><span style="color: #000000"> > </span><span style="color: #000000">**Client Settings**</span><span style="color: #000000"> > </span><span style="color: #000000">**NameOfClientSetting**</span><span style="color: #000000"> > </span><span style="color: #000000">**Split Tunnel**</span><span style="color: #000000"> > </span><span style="color: #000000">**Domain and Application**</span><span style="color: #000000"> > </span><span style="color: #000000">**Include Domain**</span><span style="color: #000000">).</span>
- <span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint on MAC OS is not compatible with Palo Alto Networks GlobalProtect VPN with DNS server IP address parameter turned on</span><span style="color: #172b4d">.</span><br><span style="color: #000000">**Notes**</span><span style="color: #000000">:</span><br>- <span style="color: #000000">The </span><span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint is compatible with Palo Alto Networks GlobalProtect client version </span><span style="color: #000000">**6.0.4-c21**</span><span style="color: #000000"> and higher.</span>
- <span style="color: #000000">A configuration applicable for "Palo Alto Networks GlobalProtect VPN" should also be applicable for "Palo Alto Networks Prisma Access - Mobile User VPN" as they are the same thing except that Palo Alto Networks hosts the infrastructure for Prisma Access, while "GlobalProtect" is run on the on-prem firewalls by the customer.</span>
- <span style="color: #000000">When adding an "Internal Domain" on the GlobalProtect Gateway configuration, you must add it with a wildcard character to take effect (e.g. </span><span style="color: #000000">**.internal.domain.corp*</span><span style="color: #000000">). Without the wildcard, only the domain itself will be forwarded down the tunnel. This is different to the Infoblox "Internal Domains" list which does not require the addition of the wildcard character.</span>
- <span style="color: #000000">On the Palo Alto Networks firewall, you can configure up to 200 domains to be forwarded down the VPN tunnel when the tunnel is configured in split-tunnel ("Both Network Traffic and DNS" mode).</span>
- <span style="color: #000000">Palo Alto Networks firewall requires the GlobalProtect licence in order to include traffic to the VPN tunnel based on domain name. </span>
- <span style="color: #000000">For further information, refer to the Palo Alto Networks GlobalProtect documentation: </span><span style="color: #000000">*[Configure a Split Tunnel Based on the Domain and Application](https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-gateways/split-tunnel-traffic-on-globalprotect-gateways/configure-a-split-tunnel-based-on-the-domain-and-application)*</span><span style="color: #000000">.</span> | <span style="color: #000000">**Issue**</span><span style="color: #000000">: </span>Sometimes in an office network, the endpoint device must be restarted after the <span style="color: #172b4d">Infoblox</span> Endpoint agent installation to work properly with the Palo Alto Networks GlobalProtect client.<br><span style="color: #000000">**Issue**</span><span style="color: #000000">: </span>When Palo Alto Networks GlobalProtect VPN with DNS server IP address is configured , it modifies the DNS server ip configured on the network interface of the MAC Client machine. So, <span style="color: #172b4d">Infoblox</span> Endpoint will not be able to provide proper protection as designed on MAC OS. |
| **Pulse Connect Secure VPN** | <span style="color: #172b4d">Infoblox</span> Endpoint is compatible with Windows and Mac. For Mac, see known issues.<br><span style="color: #172b4d">**Windows**</span><span style="color: #172b4d">: Infoblox Endpoint is compatible with Ivanti Secure Access VPN , but with Infoblox Endpoint  coredns running on other than 127.0.0.1. Only Infoblox Endpoint 2.4.19 is supported</span><br>**Mac**: Infoblox Endpoint is compatible. (see Known Issues). For information on configuring Ivanti Pulse Secure Access, see [Ivanti_Secure_Access_VPN.docx](https://infoblox-my.sharepoint.com/:w:/r/personal/svadada_infoblox_com/Documents/Ivanti_Secure_Access_VPN.docx?d=w320e7534d02a412e8d031425df894ace&csf=1&web=1&e=cHjdyh). | <span style="color: #000000">**Issue**</span><span style="color: #000000">: </span><br><span style="color: #000000">**Mac: **</span><span style="color: #000000">Even though split dns is configured on VPN, all the dns packets flow through the VPN interface.</span> |
| **SonicWall VPN** | <span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint is not compatible with SonicWall VPN. </span> | <span style="color: #000000">N/A</span> |
| **Symantec WSS Agent** | <span style="color: #172b4d">Infoblox</span> Endpoint is compatible with Symantec WSS Agent when you exclude the following domains and IP addresses on the agent:<br>**TCP 443:**<br>- csp.infoblox.com
- threatdefense.infoblox.com and its subdomains<br>**TCP/UDP 53 and 443**:<br>- 52.119.40.100
- 52.119.41.100
- 103.80.5.100
- 103.80.6.100 | N/A |
| **Tunnelblick VPN** | <span style="color: #172b4d">Infoblox</span><span style="color: #000000"> Endpoint is compatible with Tunnelblick VPN if you make the following changes in Tunnelblick:</span><br>- <span style="color: #000000">Allow changing of the DNS servers for the adaptor.</span>
- <span style="color: #000000">Apply DNS settings after the tunnel has been established.</span><br><span style="color: #000000">In the </span>**Connecting and Disconnecting**<span style="color: #000000"> tab of the Tunnelblick advanced configuration, ensure that the following two settings are enabled:</span><br>- <span style="color: #000000">**Flush DNS cache after connecting or disconnecting**</span><span style="color: #000000"> (default)</span>
- <span style="color: #000000">**Set DNS after routes are set instead of before routes are se**</span><span style="color: #000000">t</span><br><span style="color: #000000">In the </span><span style="color: #000000">**While Connected**</span><span style="color: #000000"> tab, change the following to </span><span style="color: #000000">**Ignore**</span><span style="color: #000000">:</span><br>- <span style="color: #000000">**DNS servers**</span><span style="color: #000000">:</span>
  - <span style="color: #000000">**When changes to pre-VPN value**</span><span style="color: #000000">: Choose </span><span style="color: #000000">**Ignore.**</span>
  - <span style="color: #000000">**When changed to anything else**</span><span style="color: #000000">: Choose </span><span style="color: #000000">**Ignore.**</span> | With some Tunnelblick versions, <span style="color: #172b4d">Infoblox</span> Endpoint is unable to properly identify the correct internal DNS servers following a VPN disconnect. To avoid this issue, change the “Set DNS/WINS” option in Tunnelblick to "set nameserver (3.1)":<br>1. Open the Tunnelblick GUI
2. Select your configuration from the right panel.
3. In the Tunnelblick GUI, click on the *Settings* tab
4. Change “**Set DNS/WINS**” option value to the “**set nameserver (3.1)**” |
| **Zscaler Private Access (ZPA)** | <span style="color: #172b4d">Infoblox</span> Endpoint is compatible with Zscaler Private Access (ZPA). ZPA works correctly with Windows and Mac versions.<br>Tested versions of Zscaler client: 3.7.0.172 for MAC OS, 3.9.0.183 for Windows.<br>- <span style="color: #172b4d">Add Infoblox anycast addresses/FQDNS, redirect IP addresses to the Zscaler bypass list under App profiles - </span>**“Hostname or IP Address Bypass for VPN Gateway".**  
  
> Macro (inline-media-image)
- If Zscaler is unable to detect Trusted Network while connected to Infoblox Endpoint, then try to configure the condition to match the DNS Search Domain or any other that is working. |  |
| **Zscaler Internet Access (ZIA)** | <span style="color: #172b4d">Infoblox</span> Endpoint is compatible with Zscaler Internet Access (ZIA). ZIA works correctly with Windows and Mac versions.<br>ZIA is supported by using Proxy Auto-Configuration (PAC) files to determine whether web browser requests (HTTP, HTTPS, and FTP) go directly to the destination or are forwarded to a web proxy server.<br>- <span style="color: #172b4d">When using </span><span style="color: #172b4d">**ZIA**</span><span style="color: #172b4d">, make sure that Zscaler does not intercept all DNS queries directed to the Infoblox endpoint. In the Zscaler App Profile, avoid configuring a wildcard </span>**'*'**<span style="color: #172b4d"> in the </span>"Domain Inclusions for DNS Requests."<span style="color: #172b4d"> Instead, specify only the DNS domains that Zscaler should intercept.</span><br>For information on how to configure PAC files, see the [Infoblox Threat Defense Integration in ZScaler ](https://insights.infoblox.com/resources-deployment-guides/infoblox-deployment-guide-bloxone-threat-defense-integration-in-zscaler-environment#page=1)deployment guide. |