Solved

cant resolve DNS over site-to-site VPN

Posted on 2009-05-04
3
763 Views
Last Modified: 2012-05-06
I have a Linksys WRVS4400N Wireless Router w/ VPN configured to VPN into our main offices PIX. The VPN is up, and working, I can connect to anything from our remote office to our main office, so long as I use the IP.

remote office is 192.168.x.x
main office is 192.168.y.y

if I point my laptop's DNS to our main office DNS server, I can query places like google.com, and yahoo.com, no problem. I cannot however query srv01.domain.biz, assuming domain.local as my main offices internal domain.

did a nslookup with "set norecurse" and it spits back our external DNS servers as ns records, rather than the server we queried, which is authoritative for domain.biz

Any ideas on why our remote office isn't getting proper responses?
0
Comment
Question by:mnswhit
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 1

Expert Comment

by:George Lau
ID: 24301171

 Let's assume you have your numbers correctly set, and your internal NS records are in order at your business. Perhaps the laptop is holding on to the residual NS numbers?

Start-->Run
cmd [click ok]
ipconfig /flushdns [enter]
(You should see a message about successfully flushing the DNS resolver cache.)
ipconfig /registerdns [enter]
(...another message about DNS registration.)

Try pinging srv01.domain.biz...


This is the easy solution. The next could possibly be your VPN concentrator is overriding DNS to the client...let's not go there unless we need to. :) I'd need to know a little more about the far end.

Good luck,
T

0
 
LVL 2

Expert Comment

by:e3user
ID: 24304789
hey there

I dont know if did this but in the group-policy you should put the ip of the DNS servers:

group-policy vpnpolicy attributes
     dns value 78.xxx.xxx.xxx  79.xxx.xxx.xxx

if it is possible to show run and display it here
0
 
LVL 2

Accepted Solution

by:
mnswhit earned 0 total points
ID: 24309437
I did try the ipconfig /flushdns and all. I ended up calling Cisco and Linksys in a conference call. After monitoring traffic on the PIX, we discovered that DNS was not going through the VPN. Running a sniffer on the laptop, it appears that the Linksys WRVS4400N was responding to the DNS queries even though it was not the DNS that was queried. Linksys now has a bug report on the issue.

Their suggestion was to utilize LMHOSTS file, which we are now doing. Thank you for your responses though.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco Licensing for Wi Fi 4 82
Cisco ACS Adding Root and Intermediate Certs 2 64
CISCO WIFI 6 73
Cisco ACS second root certificate 3 11
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question