Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Can't join domain using Cisco AnyConnect VPN

Posted on 2010-08-19
7
Medium Priority
?
1,997 Views
Last Modified: 2012-05-10
I got a cisco ASA5505 that uses anyconnect to create a vpn. I'm trying to get a remote laptop to join the domain. I have configured the vpn to start before login, so the computer boots up, the user hits ctrl+alt+del and the cisco vpn box comes up and asks them for the vpn credentials. They enter the credentials then it takes them to the normal login screen, where they are logging on to the local machine at the moment. I try to join the join the laptop to the domain by clccking on computer name on the laptop and clicking on change then entering the domain name. Then I get this error:
A domain controller for the domain *name* could not be contacted. Ensure that the domain name is typed correctly. If the domain name is correct click details for troubleshooting information. So I click details and get this:

The domain name *name* might be a NetBIOS domain name.  If this is the case, verify that the domain name is properly registered with WINS.

If you are certain that the name is not a NetBIOS domain name, then the following information can help you troubleshoot your DNS configuration.

The following error occurred when DNS was queried for the service location (SRV) resource record used to locate a domain controller for domain nrsc:

The error was: "DNS name does not exist."
(error code 0x0000232B RCODE_NAME_ERROR)

The query was for the SRV record for _ldap._tcp.dc._msdcs.*name*

Common causes of this error include the following:

- The DNS SRV record is not registered in DNS.

- One or more of the following zones do not include delegation to its child zone:

*name*
. (the root zone)

For information about correcting this problem, click Help.

I think the problem may be with the cisco router. Because when I connect to the vpn I get a valid ip address for the network I  am trying to connect to, but I can't ping the router itself or any computers by name, I can ping them by ip address though (except the router I can't ping that at all). Any suggestions?
0
Comment
Question by:FreeRangers
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
7 Comments
 
LVL 5

Accepted Solution

by:
workga earned 2000 total points
ID: 33477502
As far as I can see, your DNS does not get passed down to the vpn connection.  You might have to open the appropriate port for DNS on the router and make sure your dns settings are getting passed down to the computer.  You can try to add dns server ip to you vpn connection on the laptop to see if you can add the laptop to the domain.  IF that is successful you have to modify your router config to include that dns server.
0
 

Author Comment

by:FreeRangers
ID: 33477789
Now I can't ping anything. which means I can't remote access the router, or any other machine on the domain. I can't really go to the physical location of the router as it is several hours away and in an un maned office right now. I s there a way I can fix it remotely?
0
 
LVL 10

Expert Comment

by:Casey Herman
ID: 33477878
Were you able to ping before? Cisco generally kills all ICMP traffic to help prevent DoS attacks.

Try setting the DNS on the network interface of the client to the IP of your domain controller as the primary and the local internet or what have you as the secondary. This may get you past joining the domain. You should probably also statically assign the WINS server.
0
Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

 

Author Comment

by:FreeRangers
ID: 33477904
I could ping other computers on the domain by ip address, but not by name, and could ping the router at all. Now I can't ping any computer on the domain (by IP address or name)
0
 

Author Comment

by:FreeRangers
ID: 33477964
I can't even ping google, but I can get internet. Setting the dns on the client didn't do anything.
0
 

Author Comment

by:FreeRangers
ID: 33478130
I can ping google now (just restarted the laptop) but still can't ping any domain computers, meaning can't get to the cisco router to fix whatever I broke.
0
 

Author Comment

by:FreeRangers
ID: 33480313
Is there any way to remotely fix the router? I was able to access it earlier, but then I (thought) I opened up the dns port as that may have solved my initial problem, but now I can't get access to any network computer.
0

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question