Solved

DNS - Deny a single DNS-record on RODC

Posted on 2013-11-26
3
473 Views
Last Modified: 2013-11-27
Hi,

We have a RODC in a remote site. Between our site and this remote site, there is established a VPN tunnel, but with only restricted access.

Because of this restricted access and one single DNS-record that Direct Access uses to see if it's  on our local network or outsite, Direct Access doesn't work when users from our primary site connects their computer in our remote site, because it sees this special dns records, that tells it that it's on our local network.

Is it possible to restrict access to this single DNS-record on our remote site or remove it, so when they connect their laptop in our remote site, it will establish an Direct Access connection to our primary network through the internet instead of our VPN tunnel.
0
Comment
Question by:Sum Wum
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 37

Expert Comment

by:Mahesh
ID: 39677392
Since record is created in AD integrated Domain DNS zone, that can't be hide from RODC

Any records if you have in standard primary zone, that can be hide from other DCs

Mahesh
0
 
LVL 1

Author Comment

by:Sum Wum
ID: 39679923
MaheshPM: How do I hide it from other DC's?
0
 
LVL 37

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39679957
i believe these records are IPV6 records
Correct me If wrong please

You can try below on RODC
Open registry on RODC and navigate to below registry path
HKLM\SYSTEM\CurrentControlSet\Services\DNS\Parameters and open "GlobalQueryBlocklist" REG Multi string value.
Add there host (AAAA) special DNS record which is used by Directaccess
Restart DNS service

Above modification should block name resolution of perticlular DNS record from RODC
Then You can try to resolve the record from RODC, it should fail.

same can be achieved through Dnscmd tool
http://technet.microsoft.com/en-us/library/ee649250(v=ws.10).aspx

Mahesh
0

Featured Post

Now Available: Firebox Cloud for AWS and FireboxV

Firebox Cloud brings the protection of WatchGuard’s leading Firebox UTM appliances to public cloud environments. It enables organizations to extend their security perimeter to protect business-critical assets in Amazon Web Services (AWS).

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question