Situation: The client has PA-850 firewall running GloableProtect for VPN connection. After they changed the DNS by going to Network>Gloableprotect>Gateway>Agent and then Network services,

Some VPN client take the change but not all. Some users still use the old DNS server.
Troubleshooting: You also need to change the DNS server under Client Settings>Network Services.

Please refer to this post for more details: How to change DNS settings for PA Firewall GloablProetc