Solved

DNS issues Cannot resolve to domain controller from site B to site A

Posted on 2011-09-26
3
336 Views
Last Modified: 2012-06-27
Hello

I have two site locations A and B.  I have an AD domain in site A.  I am trying to extend the domain from site A to site B.  The two sites are connected via VPN site to site connection using NAT over VPN as both sites unfortunately are using the same subnet.  (10.0.0.x).  So Site A is 10.0.0.x with NAT as 172.17.0.x.  Site B is also 10.0.0.x with NAT as 172.16.0.x.  I set the DNS on site B to point to site A using the NAT address.  The site A Domain is address 10.0.0.6 which id NAT as 172.17.0.6.  I added the 172.17.0.6 as a primary DNS entry on site B systems and I am able to resolve site A DNS hostnames by running nslookup on a site B machine.  Problem is that I cannot join a machine from site B to the site A domain.  I have added Host A records to the site A DNS that point the domain with the NAT IP.  It does not seem to help.  Any help would be greatly appreciated!
0
Comment
Question by:biz1it
  • 2
3 Comments
 
LVL 9

Accepted Solution

by:
Bill_Fleury earned 500 total points
ID: 36600885
Microsoft does not support using Active Directory over NAT.  Please see:

http://support.microsoft.com/kb/978772

Even unsupported, I don't think you can solve this problem with NAT'ing,  Issues come into play with clients needing to do lookups of the several automatically provisioned records in an active directory DNS structure, which will not be available in a situation like you've presented here.  There are several problems that you'll run into along the way.

My suggestion would be to change the addressing at one site.  I know this is a daunting/almost impossible task in some environments, but it's a necessity if you're trying to use active directory between the two networks.
0
 

Author Closing Comment

by:biz1it
ID: 36931861
Yes unfortunately I had to bite the bullet and change the IP's on one site.  It's been a fun week....It is now working OK except for ironing out some issues with SQL jobs failing.

Thanks for your response!
0
 
LVL 9

Expert Comment

by:Bill_Fleury
ID: 36932136
Sounds like a fun week.  Keep plugging away, I'm sure there will be a few things to iron out after having to change the addresses, but it will be well worth it in the end.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question