HEITOR
24 September 2026 15:14
1
I have the need to use Norton VPN with my company VPN simultaneously.
The problem is that Norton forwards all DNS resolution requests to its own VPN DNS server, which is a problem because it does not know the internal server names of my company and cannot resolve them.
The solution, from what I have found, is to implement split DNS in Norton VPN or allow the client to set which DNS server they want to use as primary.
So I am creating this topic to suggest that Norton implement this, please.
1 Like
bjm
24 September 2026 17:52
2
HEITOR:
I have the need to use Norton VPN with my company VPN simultaneously.
The problem is that Norton forwards all DNS resolution requests to its own VPN DNS server, which is a problem because it does not know the internal server names of my company and cannot resolve them.
The solution, from what I have found, is to implement split DNS in Norton VPN or allow the client to set which DNS server they want to use as primary.
So I am creating this topic to suggest that Norton implement this, please.
Hello @HEITOR
Welcome to the Norton Community!
Respectfully, may I inquire – Why you have the need to use Norton VPN with your company VPN simultaneously?
++++++++++++++++++++++++++++++++++++++++++++++
fwiw ~ as per AI:
Feature Request: Split DNS / Running Norton VPN with Corporate VPN
You have accurately diagnosed the exact symptom of this problem. You are 100% correct that Norton intercepts all DNS resolution requests and forwards them to its own public servers, which naturally have zero visibility into your company’s private internal network layout.
However, while your diagnosis of the DNS roadblock is flawless, implementing Split DNS or allowing a custom primary DNS within Norton will not fix the underlying issue. DNS is just the phone book; once you bypass that hurdle, you will immediately crash into the structural limitations of running nested tunnels (“a tunnel inside a tunnel”) on a standard operating system:
It’s a Routing War, Not Just a DNS Issue: Operating systems like Windows and macOS are built to handle exactly one primary network gateway. When you run Norton VPN and a corporate VPN simultaneously, both software clients aggressively fight for absolute control over your system’s routing table. Even if Norton allowed you to look up the correct corporate IP address via Split DNS, the two VPN protocols would still conflict when trying to route the actual data packets. This inevitably results in dropped connections, massive latency, or severe data loss.
Conflicting Security Designs: Norton VPN is a consumer tool built on an “all-or-nothing” privacy rule, while your corporate VPN (such as Cisco Secure Client/AnyConnect or Palo Alto GlobalProtect) is a highly sophisticated enterprise security suite built on a “total control” rule. Enterprise clients are intentionally designed by IT administrators to enforce strict network monopolies. They actively scan your system’s memory and active network adapters. The moment they detect a commercial VPN like Norton attempting to manipulate network sockets or run an unauthorized secondary tunnel, they will flag the device as non-compliant and shut down the connection to prevent data leaks.
Specialized Tools are Required: Successfully nesting or chaining VPN tunnels is possible, but it cannot be achieved by stacking automated applications on top of each other. It requires advanced, open-source networking tools (like raw OpenVPN or WireGuard configurations managed through custom virtual machines or specialized routers) where routing metrics and MTU sizes can be manually adjusted. Consumer-grade security suites simply aren’t built for this.
If your primary goal is to keep personal browsing private from your company’s network monitoring, the only reliable solution is physical separation: use your corporate VPN exclusively for work tasks, and handle personal browsing (using Norton VPN) on a separate personal device. Trying to force both clients to coexist on the same OS will inevitably lead to an unstable connection.
Running any two VPNs simultaneously is a recipe for chaos , regardless of the brand.
When you activate a single VPN, it fundamentally rewrites how your operating system talks to the outside world. It creates a virtual network adapter, changes your default internet gateway, and overrides your DNS settings.
If you introduce a second VPN, it tries to do the exact same thing to the exact same files. They end up in an immediate tug-of-war:
The Packet Loop: Traffic gets sucked into VPN A, which tries to route it through VPN B, which then tries to push it back into VPN A. The computer gets confused, and data packets just end up spinning in a loop until they expire.
The Disconnect Race: As each VPN client detects the other one trying to change the computer’s network settings, their built-in security features (“kill switches”) trip, causing both connections to repeatedly drop and reconnect.
Unless you are a network engineer manually configuring raw protocols (like WireGuard or OpenVPN) line-by-line inside virtual machines or specialized hardware routers, trying to run two commercial VPN apps at the same time will always be a frustrating, unstable mess!
AI sourced content may make mistakes
HEITOR
24 September 2026 18:53
3
The reason that I need to use both simultaneously is to protect my connection to non-corporate websites, since the corporate VPN uses split tunneling. So, it protects my navigation only for corporate services, while other services use my personal network adapter.
When I’m working on a private network connection, it is not a problem, but when I need to use public Wi-Fi, it becomes a problem!
1 Like
HEITOR
24 September 2026 18:57
4
I forgot to mention that, as a workaround, I added the names and IP addresses of my corporate services to the Windows hosts file, so I can enable both VPNs and work normally.
1 Like
bjm
24 September 2026 18:57
5
HEITOR:
The reason that I need to use both simultaneously is to protect my connection to non-corporate websites, since the corporate VPN uses split tunneling. So, it protects my navigation only for corporate services, while other services use my personal network adapter.
When I’m working on a private network connection, it is not a problem, but when I need to use public Wi-Fi, it becomes a problem!
Hello @HEITOR
fwiw ~ as per AI:
Feature Request: Split DNS / Running Norton VPN with Corporate VPN
Thank you for clarifying! That makes total sense, and your desire to protect your personal data while working on public Wi-Fi is highly responsible.
However, because your company has configured Split Tunneling , attempting to stack Norton VPN on top of it will still result in the routing conflicts and dropped connections mentioned earlier. The two clients will continuously fight for control over your network adapter.
Fortunately, public Wi-Fi is much safer today than it used to be, and you can achieve the protection you want without breaking your connection:
HTTPS Encryption is Already Active: Even without a personal VPN, almost every modern website you visit uses HTTPS encryption. Anyone snooping on the public Wi-Fi can only see the name of the website you are visiting (e.g., bank.com), but they cannot see your passwords, data, or what you are doing on that site.
The Safe Alternative (Secure DNS): If you want to protect your personal browsing requests on public Wi-Fi without using Norton, you can enable DNS over HTTPS (DoH) directly inside your web browser (like Chrome, Edge, or Firefox). This encrypts your personal DNS requests so public Wi-Fi snoopers can’t see them, and it won’t conflict with your corporate VPN’s routing.
Use a Separate Device: The absolute safest method for personal banking or private browsing while traveling is to disconnect your personal tasks from the work machine entirely and use your phone’s cellular data hotspot.
Sticking with the corporate split tunnel and utilizing browser-based security will keep you safe on public Wi-Fi without causing your network connection to crash.
AI sourced content may make mistakes
bjm
24 September 2026 19:00
6
HEITOR:
I forgot to mention that, as a workaround, I added the names and IP addresses of my corporate services to the Windows hosts file, so I can enable both VPNs and work normally.
Hello @HEITOR
fwiw ~ as per AI:
The user has just revealed that they are manually hardcoding their corporate network layout into their local machine.
While editing the hosts file does technically bypass Norton’s DNS restriction (by telling Windows exactly where the servers are without asking Norton), they have inadvertently created a major security vulnerability and an administrative nightmare .
Here is why their workaround is highly problematic and likely to break soon:
The Security Risk (Data Leaks)
By forcing Norton VPN and a corporate VPN to run simultaneously, they are tricking the routing table. They think their personal traffic goes to Norton and corporate traffic goes to the company. In reality, routing tables do not split traffic cleanly by website name.
Depending on which VPN connected last, their sensitive corporate data packets could actually be routed out through Norton’s public servers instead of the company’s secure network.
Alternatively, their personal traffic might be leaking into the corporate network. They have created an unmonitored “bridge” between a public consumer VPN and a private enterprise network, which is a massive compliance violation.
Corporate IPs Are Not Static
Enterprise networks dynamically change server IP addresses all the time for load balancing, server maintenance, and cloud security updates. The moment their IT department shifts a corporate service to a new IP address, the user’s hardcoded hosts file will point to a dead link, and their work access will instantly break.
Flying Under the IT Radar
They are actively bypassing corporate network policies. If their IT department performs an endpoint audit and discovers a modified hosts file pointing to internal infrastructure alongside an unauthorized commercial VPN adapter, it could be flagged as a security breach or a malicious attempt to bypass network controls .
Feature Request: Split DNS / Running Norton VPN with Corporate VPN
Using the local Windows hosts file to manually map your corporate server names to their IP addresses is a clever technical workaround to bypass the DNS hurdle! By doing this, you are forcing Windows to look at a local “address book” instead of asking Norton’s DNS servers.
However, while it allows you to connect right now, this setup introduces a few hidden risks and long-term issues that you should be aware of:
Potential Data Leaks: Stacking two active VPNs creates an unpredictable routing environment. Even if the hosts file resolves the address, your operating system can still get confused about which tunnel to send the actual data packets through. There is a high risk that your corporate data is inadvertently traversing Norton’s public network, or your personal data is leaking into the corporate tunnel.
The Setup Will Break Dynamically: Enterprise IT departments frequently change internal IP addresses for server maintenance, load balancing, and cloud security updates. The moment your company changes a server’s IP behind the scenes, your hardcoded hosts file will point to a dead address, and your work access will instantly fail until you manually hunt down the new IP.
Corporate IT Violations: Modifying the system hosts file to force a commercial VPN to coexist with an enterprise network is often flagged during automated corporate security audits. IT departments design their VPNs to have a strict monopoly on the device to prevent data exfiltration; bypassing this can be seen as a policy violation.
Your technical intuition to use the hosts file is impressive, but for stability, security, and peace of mind on public Wi-Fi, the safer path remains keeping personal browsing on a separate device (like a phone or tablet) while your corporate VPN handles the work machine.
AI sourced content may make mistakes
@HEITOR As a professional suggestion, if you haven’t done so already, you should consult your corporate IT admin for suggestions with your idea. An audit could result in things not in your favor due to miscommunication issues and/or violations of policies in place.
SA
1 Like
HEITOR
24 September 2026 22:20
8
I already did it, it was them who identified the problem, that the DNS resolution requests was not being made in the corporate VPN DNS server, but in Norton VPN DNS server.
2 Likes