Solved

Cannot see other domains attached by a VPN tunnel in My Network Places

Posted on 2006-10-25
10
279 Views
Last Modified: 2010-03-19
Dear experts,

I have the following situation I have 2 VPN tunnels interconnecting 3 sites. The primary (center) site has a Netgear FVS318v3 8-port Prosafe VPN Firewall (recently changed) and the other two locations both have Linksys BEFSX41 Firewall routers. Initially the center location also had identical Linksys box.

When I had Linksys boxes I was able to go to My Network Places->Entire Netwok->Microsoft Windows Network
This would show all the domain names that were interconnected by the VPN tunnels. I could also access computers in those domains from there.

I have not changed any OS settings, just placed Netgear Firewall. So, it is gotta be a setting there.

My question is what exactly could cause the above situation?
2. How do I fix it?

Thank you in advance,

0
Comment
Question by:IvanT2006
  • 4
  • 3
  • 2
10 Comments
 
LVL 2

Expert Comment

by:HeavyWaterLTD
ID: 17806773
Did you have to recreate the DHCP scopes when you replaced your box?
If that's the case then maybe you forgot to add WINS entry when re-creating the scope
0
 

Author Comment

by:IvanT2006
ID: 17808450
Hi

The DHCP is running off Win2k3 servers in all three locations. DHCP on the routers is off. I didnt have to recreate anything.

I also copied most of the setting from the old Linksys box. For instance, I didnt have to reconfigure the VPNs, with all the same settings I was working just fine.

The only problem so far is the one I mentioned above.

Thanks,



0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 17808542
In the VPN policy configuration of the Netgear, near the bottom, there is an option "NetBIOS enable". Have you enabled that on all routers.
Browsing often doesn't work well over VPN's as NetBIOS names are not routable. If using a WINS server, that will most often allow for proper browsing. If so as HeavyWaterLTD suggested, make sure your DHCP server is assigning the WINS server's IP to all clients.
0
 

Author Comment

by:IvanT2006
ID: 17814290
Hi

I had it enabled on all the routers by default.

0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 2

Expert Comment

by:HeavyWaterLTD
ID: 17816509
Apparently your previous linksys setup played nicely with netbios but with the introduction of the netgear box this no longer works. If you have enabled netbios passthrough on all your boxes and vpn tunnels then it may be that it will never work as your previous setup.

As RobWill mentioned, netbios is not a routable protocol. for netbios name resolution through layer 3 environments a more elegant solution would be to deploy WINS servers for netbios name resolution. Once you do this, you have to have all your hosts (servers, clients) point to the WINS server to register.
0
 

Author Comment

by:IvanT2006
ID: 17863971
Hi

So what would  I have to do? I have a DC in each location among with tens of PCs. Would I have to enable WINS on each DC and then enable Netbios over TCP/IP on each machine?

Thanks
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 17864036
Are these DC's members of the same domain? If they are, and they are replicating AD there should be no problem or anything to configure, so long as replication is working properly. I would verify you have DNS configured on the remote DC's by running netdiag and dcdiag on those DC's. The utilities are available on some of the Windows install CD's, as part of the Windows resource kit, or from:
http://www3.ns.sympatico.ca/malagash/Downloads/Net/
There are different versions of these utilities, so if possible get them from your matching windows CD.
NetBIOS and WINS solutions are usually more important if you do not have a local DC, though for browsing the network, WINS is a great asset.
0
 

Author Comment

by:IvanT2006
ID: 17864189
No in fact they all are different domains. Each having its own DNS server. The problem is that without really being able to browse other domains, I cannot establish trusts. Thus the replication of DNS is impossible.
0
 
LVL 77

Accepted Solution

by:
Rob Williams earned 500 total points
ID: 17864245
Browsing relies on NetBIOS, which over a VPN pretty much requires WINS, however AD, trusts, and replication rely on DNS. I would look at "resolving" that  first. Not sure how DCdiag works between different domains, but it certainly will not hurt to run. It may point out some critical errors.
You could try making use of the LMHosts file to add the remote DC names. This might help the servers to locate one another more easily. It uses/assists with NetBIOS naming.
http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/cnet/cnfd_lmh_qxqq.mspx?mfr=true
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now