Solved

Cannot see other domains attached by a VPN tunnel in My Network Places

Posted on 2006-10-25
10
293 Views
Last Modified: 2010-03-19
Dear experts,

I have the following situation I have 2 VPN tunnels interconnecting 3 sites. The primary (center) site has a Netgear FVS318v3 8-port Prosafe VPN Firewall (recently changed) and the other two locations both have Linksys BEFSX41 Firewall routers. Initially the center location also had identical Linksys box.

When I had Linksys boxes I was able to go to My Network Places->Entire Netwok->Microsoft Windows Network
This would show all the domain names that were interconnected by the VPN tunnels. I could also access computers in those domains from there.

I have not changed any OS settings, just placed Netgear Firewall. So, it is gotta be a setting there.

My question is what exactly could cause the above situation?
2. How do I fix it?

Thank you in advance,

0
Comment
Question by:IvanT2006
  • 4
  • 3
  • 2
10 Comments
 
LVL 2

Expert Comment

by:HeavyWaterLTD
ID: 17806773
Did you have to recreate the DHCP scopes when you replaced your box?
If that's the case then maybe you forgot to add WINS entry when re-creating the scope
0
 

Author Comment

by:IvanT2006
ID: 17808450
Hi

The DHCP is running off Win2k3 servers in all three locations. DHCP on the routers is off. I didnt have to recreate anything.

I also copied most of the setting from the old Linksys box. For instance, I didnt have to reconfigure the VPNs, with all the same settings I was working just fine.

The only problem so far is the one I mentioned above.

Thanks,



0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 17808542
In the VPN policy configuration of the Netgear, near the bottom, there is an option "NetBIOS enable". Have you enabled that on all routers.
Browsing often doesn't work well over VPN's as NetBIOS names are not routable. If using a WINS server, that will most often allow for proper browsing. If so as HeavyWaterLTD suggested, make sure your DHCP server is assigning the WINS server's IP to all clients.
0
 

Author Comment

by:IvanT2006
ID: 17814290
Hi

I had it enabled on all the routers by default.

0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 2

Expert Comment

by:HeavyWaterLTD
ID: 17816509
Apparently your previous linksys setup played nicely with netbios but with the introduction of the netgear box this no longer works. If you have enabled netbios passthrough on all your boxes and vpn tunnels then it may be that it will never work as your previous setup.

As RobWill mentioned, netbios is not a routable protocol. for netbios name resolution through layer 3 environments a more elegant solution would be to deploy WINS servers for netbios name resolution. Once you do this, you have to have all your hosts (servers, clients) point to the WINS server to register.
0
 

Author Comment

by:IvanT2006
ID: 17863971
Hi

So what would  I have to do? I have a DC in each location among with tens of PCs. Would I have to enable WINS on each DC and then enable Netbios over TCP/IP on each machine?

Thanks
0
 
LVL 77

Expert Comment

by:Rob Williams
ID: 17864036
Are these DC's members of the same domain? If they are, and they are replicating AD there should be no problem or anything to configure, so long as replication is working properly. I would verify you have DNS configured on the remote DC's by running netdiag and dcdiag on those DC's. The utilities are available on some of the Windows install CD's, as part of the Windows resource kit, or from:
http://www3.ns.sympatico.ca/malagash/Downloads/Net/
There are different versions of these utilities, so if possible get them from your matching windows CD.
NetBIOS and WINS solutions are usually more important if you do not have a local DC, though for browsing the network, WINS is a great asset.
0
 

Author Comment

by:IvanT2006
ID: 17864189
No in fact they all are different domains. Each having its own DNS server. The problem is that without really being able to browse other domains, I cannot establish trusts. Thus the replication of DNS is impossible.
0
 
LVL 77

Accepted Solution

by:
Rob Williams earned 500 total points
ID: 17864245
Browsing relies on NetBIOS, which over a VPN pretty much requires WINS, however AD, trusts, and replication rely on DNS. I would look at "resolving" that  first. Not sure how DCdiag works between different domains, but it certainly will not hurt to run. It may point out some critical errors.
You could try making use of the LMHosts file to add the remote DC names. This might help the servers to locate one another more easily. It uses/assists with NetBIOS naming.
http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/cnet/cnfd_lmh_qxqq.mspx?mfr=true
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SD - WAN 2 45
What type of checksum is used for Cisco/Linksys RV router configurations? 18 65
slow vpn connection 9 43
Palo Alto Networks: Truly No Hit Count? 2 22
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now