Solved

DNS - Deny a single DNS-record on RODC

Posted on 2013-11-26
3
472 Views
Last Modified: 2013-11-27
Hi,

We have a RODC in a remote site. Between our site and this remote site, there is established a VPN tunnel, but with only restricted access.

Because of this restricted access and one single DNS-record that Direct Access uses to see if it's  on our local network or outsite, Direct Access doesn't work when users from our primary site connects their computer in our remote site, because it sees this special dns records, that tells it that it's on our local network.

Is it possible to restrict access to this single DNS-record on our remote site or remove it, so when they connect their laptop in our remote site, it will establish an Direct Access connection to our primary network through the internet instead of our VPN tunnel.
0
Comment
Question by:Sum Wum
  • 2
3 Comments
 
LVL 36

Expert Comment

by:Mahesh
ID: 39677392
Since record is created in AD integrated Domain DNS zone, that can't be hide from RODC

Any records if you have in standard primary zone, that can be hide from other DCs

Mahesh
0
 
LVL 1

Author Comment

by:Sum Wum
ID: 39679923
MaheshPM: How do I hide it from other DC's?
0
 
LVL 36

Accepted Solution

by:
Mahesh earned 500 total points
ID: 39679957
i believe these records are IPV6 records
Correct me If wrong please

You can try below on RODC
Open registry on RODC and navigate to below registry path
HKLM\SYSTEM\CurrentControlSet\Services\DNS\Parameters and open "GlobalQueryBlocklist" REG Multi string value.
Add there host (AAAA) special DNS record which is used by Directaccess
Restart DNS service

Above modification should block name resolution of perticlular DNS record from RODC
Then You can try to resolve the record from RODC, it should fail.

same can be achieved through Dnscmd tool
http://technet.microsoft.com/en-us/library/ee649250(v=ws.10).aspx

Mahesh
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to setup 3 isps on a redundant mode? 3 33
AD Sites/AD Replication 11 42
Exchange 2010 to 2013 8 75
Device browser and/or dns client cache update through web page 7 26
Remote Desktop Shadowing often has a lot of benefits. When helping end users determine problems, it is much easier to see what is going on, what is being slecected and what is being clicked on. While the industry has many products to help with this,…
This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question