[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details

VPN Client DNS Registeration Causing DNS inconsistencies

Asked by mpopal in Virtual Private Networking (VPN), Domain Name Service (DNS)

Tags: VPN, Cisco

I'm working on a new project at a client site where where the VPN clients are causing name resolution conflicts in Active Directory DNS. Here are some details:

1.The organization have servers and workstations that are configured to use IP addresses such as 192.168.1.x, and 192.168.2.x. (Obviously not good choice of IP addressing but am stuck with the current IP scheme).
2. When VPN clients connect from home, two IP addresses get registered- 1. Their local NIC (usually 192.168.1.x and the VPN address 10.x.x.x.

The problem this is creating is the DNS ends up with duplicate entries because a home users local Network Card is assigned an address like 192.168.1.x - and the same address is used at the customer site for servers and workstations. So in essence  you end up with DNS entries such as 192.168.1.10 = homeuserspc as well as 192.168.1.10 = server01.

Is there any way to block the VPN concentrator from passing through DNS registration from VPN users? Not sure if access lists can do this as the vpn concentrator is a cisco 2851. I can't have the VPN users configure their network settings to not register with DNS either because the laptops are also used on site and needs to register with DNS when at the office.

Any suggestions on how to prevent DNS registration from happening on VPN clients? Thanks.
[+][-]11/05/09 10:29 AM, ID: 25752368Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]11/05/09 11:01 AM, ID: 25752720Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091111-EE-VQP-89 - Hierarchy / EE_QW_3_20080625