Link to home
Start Free TrialLog in
Avatar of adoughe
adougheFlag for United States of America

asked on

How Can I Add and Remove Workstations in a Different Domain Through a VPN Tunnel?

We have a client who wants us to manage their laptops, running our custom application, through a site-to-site VPN tunnel. We will create a DNS zone hem for them in our internal DNS with some of their servers.  One of their servers is machineA.companyB.com, and another is machineB.northamerica.companyB.com.  Their domain is northamerica.companyB.com.  After creating the second one in Microsoft DNS as a host record DNS automatically created a subzone, northamerica, and placed machineB in it.  My problem is this.  I went to create a host record in companyB.com called "northamerica" and assign it the IP address of one of their domain controllers. Microsoft DNS told me the host record was successfully created but I can
not see it.  The goal was to make "northamerica.companyB.com" resolve to a DC so when joining the northamerica.companyB.com domain the managed laptop will find the DC. So I have two questions. One, is this the recommended way to setup DNS so a laptop can find a DC for a different domain over a site-to-site VPN tunnel? Two, if it is, how do I overcome the apparent inability to creat a host record called "northamerica.companyB.com" if a subzone "northamerica" exists?
ASKER CERTIFIED SOLUTION
Avatar of Chris Hudson
Chris Hudson

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of adoughe

ASKER

chrishudson123, thanks for your reply. It was necessary though to do more than you describe. I basically had to duplicate much of what is present in our own DNS for our domain for the CompanyB domain. This included creating the "_msdcs" and other structures in DNS. I will give you credit for answering the question with that caveat. Thanks again...
Avatar of Chris Hudson
Chris Hudson

That's why I recommended forwarder configuration in case of DC loacte process.U can configure secondary DNS zone or forwarder for this.If you just duplicate the zone details ,now it will be fine.But in future when they add/remove the new DC,U have update the records