Good afternoon, Robson.
In its scenario, two questions must be evaluated:
1) When we use the SSL VPN, we have the option to specify the routes that will be sent via tunnel, or we can also use a default route, which will make your browsing all sent via VPN tunnel.
If you are using specific routes, make sure that your DNS server IP is within the range of these routes that are registered to be sent through the VPN tunnel.
If you are using default route, the DNS server is already inside the range.
2) Make sure you can communicate with the DNS server.
A ping test can give you an idea if you can reach that server.
If it is dripping, but it is not yet solving names, then it may be that some IPV4 policy is missing, releasing the VPN range to communicate with your DNS server.
Remembering that DNS queries are done through port 53/UDP and also on port 53/TCP in some cases, so you need to have a policy in these characteristics allowing this communication.
Normally the forwarding policy causes the communication to occur, but in some cases you will have to add the default masking to the rule.
Att,
