Problems authenticating to domain over the WAN via VPN

Posted on 2008-06-17
Last Modified: 2010-04-12
Here's the setup.

We have 2 physical locations, approximately 20 blocks apart, connected via a gateway to gateway VPN tunnel. VPN tunnel is connected and stable, and has been for months.

At Site A, I have a Sonicwall TZ170 router at The internal LAN is 192.168.1.x. Windows Server 2003 domain controller is at Site A at DC is also the DNS, and DHCP server, though all clients except those connecting wirelessly are using static IP's.
At Site B, I have a Linksys RV082 router at The internal LAN is 192.168.10.x. Clients on this site are using static IP's. For their DNS information I have and, in that order.

All computers at both locations are members of the domain. All users have a logon script, logon.bat, which deletes, then re-maps a couple of network drives, and maps 2 printers. In the last few days, I am having a number of issues.

1. Users at Site B sometimes get "domain is not available" when trying to log on. Will usually let them on after several tries or a reboot.
2. Users at Site B are sometimes not able to access the network drives. They receive "the system detected a possible attempt to compromise security make sure you can contact the server that authenticated you"
3. Intermittently not able to ping the DNS server by name. Pinging by IP works.
4. Intermittently not able to  browse network folders by name.
5. Intermittently not able to authenticate to network folders, get "domain controller could not be contacted" message.
6. Intermittently get "An error occured while connecting to... the local device name is already in use. The connection has not been restored"

So, this all points to a DNS issue, obviously. What I'm wondering is how I should have my clients configured so I can eliminate these domain logon and shared folder issues. Also, should I set up the Linksys router at Site B to use the DNS from Site A? Currently it is using  the ISP DNS. If I do this, will it affect the users internet access at Site B?

Question by:Ivrnet
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
LVL 11

Accepted Solution

rowansmith earned 500 total points
ID: 21808989
Unless your Active Directory DNS is publicy available via the Internet then you should completely remove the entry from the DNS configuration on each client at Site B.

Clients need to be able to resolve addresses that are in the active directory namespace at all times, if they can not for any reason then services will fail as you are describing.  If your ISP DNS Server can not see your AD internal DNS (which I suspect very much that it can not) then you should remove it completely.

I would recommend running a slave DNS Server at your remote site, ideally another domain controller would be the best bet, but if not just a DNS Server that replicates all the AD specific entries to the other site using standard secondary transfers.


Author Comment

ID: 21815888
Okay, I did as you suggested. I also added a WINS entry on each client at Site B for Issue seems to be resolved for now. They are moving from that location to an office witiin the same building, so it's not feasible to put a 2nd DC there right now. Hopefully this will work until the move happens. Thanks.
LVL 11

Expert Comment

ID: 21818140
I will keep this question monitored for the next month or so.  If you have any other problems let me know.

Featured Post

U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Internet Connection -- PING testing ? 1 59
domian network access 5 31
VPN Tunnel Stops Working Cisco RV130W 18 51
auto connect vpn 17 49
Let’s list some of the technologies that enable smooth teleworking. 
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

735 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question