Solved

DNS issues Cannot resolve to domain controller from site B to site A

Posted on 2011-09-26
3
330 Views
Last Modified: 2012-06-27
Hello

I have two site locations A and B.  I have an AD domain in site A.  I am trying to extend the domain from site A to site B.  The two sites are connected via VPN site to site connection using NAT over VPN as both sites unfortunately are using the same subnet.  (10.0.0.x).  So Site A is 10.0.0.x with NAT as 172.17.0.x.  Site B is also 10.0.0.x with NAT as 172.16.0.x.  I set the DNS on site B to point to site A using the NAT address.  The site A Domain is address 10.0.0.6 which id NAT as 172.17.0.6.  I added the 172.17.0.6 as a primary DNS entry on site B systems and I am able to resolve site A DNS hostnames by running nslookup on a site B machine.  Problem is that I cannot join a machine from site B to the site A domain.  I have added Host A records to the site A DNS that point the domain with the NAT IP.  It does not seem to help.  Any help would be greatly appreciated!
0
Comment
Question by:biz1it
  • 2
3 Comments
 
LVL 9

Accepted Solution

by:
Bill_Fleury earned 500 total points
ID: 36600885
Microsoft does not support using Active Directory over NAT.  Please see:

http://support.microsoft.com/kb/978772

Even unsupported, I don't think you can solve this problem with NAT'ing,  Issues come into play with clients needing to do lookups of the several automatically provisioned records in an active directory DNS structure, which will not be available in a situation like you've presented here.  There are several problems that you'll run into along the way.

My suggestion would be to change the addressing at one site.  I know this is a daunting/almost impossible task in some environments, but it's a necessity if you're trying to use active directory between the two networks.
0
 

Author Closing Comment

by:biz1it
ID: 36931861
Yes unfortunately I had to bite the bullet and change the IP's on one site.  It's been a fun week....It is now working OK except for ironing out some issues with SQL jobs failing.

Thanks for your response!
0
 
LVL 9

Expert Comment

by:Bill_Fleury
ID: 36932136
Sounds like a fun week.  Keep plugging away, I'm sure there will be a few things to iron out after having to change the addresses, but it will be well worth it in the end.
0

Featured Post

Free camera licenses with purchase of My Cloud NAS

Milestone Arcus software is compatible with thousands of industry-leading cameras for added flexibility. Upon installation on your My Cloud NAS, you will receive two (2) camera licenses already enabled in the software. And for a limited time, get additional camera licenses FREE.

Join & Write a Comment

Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now