Solved

Join an AWS EC2 instance to an existing domain via Amazon Virtual Private Cloud VPN

Posted on 2014-02-24
6
2,652 Views
Last Modified: 2014-11-12
I have a project group that wants to set up some temporary compute instances on AWS. Easy enough.  The trick is they want the instances to be connected to our domain so users can authenticate normally and there is no differentiation in their experience when using these systems.  I've never joined a machine to the domain through a VPN connection, but I know it's possible

We've set up a VPC with a 10.x.x.x/24 CIDR block, traffic can pass through and I can remote to the instances I've created there.  When I attempt to join the domain, it errors out, stating it cannot contact the AD DC.  I've checked firewall settings, had ITSEC check out the VPN and can't find the problem.  Can anyone help?
0
Comment
Question by:Bighoppa
  • 3
  • 2
6 Comments
 
LVL 24

Accepted Solution

by:
smckeown777 earned 167 total points
ID: 39885270
Going to ask the stupid question first...on the AWS instances have you set the DNS entries to point to your AD server? Should have a single primary DNS entry and remove the secondary one and see if that works...

Since you have connectivity normally when you can't join a domain its a dns related issue
0
 

Author Comment

by:Bighoppa
ID: 39885858
Yeah, DNS is set in the VPC options to our name servers, and I also hard-coded them into the VMs for good measure.  Can't get any traffic from them to the DNS.  Going to work with the security team and have them check the firewall rules again.
0
 
LVL 38

Assisted Solution

by:Aaron Tomosky
Aaron Tomosky earned 333 total points
ID: 39887194
I just did this with a rackspace vm using the sonicwall global vpn client. No problem, so it is possible.

BTW once you have it up, you probably want to mess with the weight and priority
http://technet.microsoft.com/en-us/library/cc816890(WS.10).aspx
http://technet.microsoft.com/en-us/library/cc794710(WS.10).aspx
0
Network it in WD Red

There's an industry-leading WD Red drive for every compatible NAS system to help fulfill your data storage needs. With drives up to 8TB, WD Red offers a wide array of solutions for customers looking to build the biggest, best-performing NAS storage solution.  

 

Author Comment

by:Bighoppa
ID: 39895301
Finally got it working.  Looks like one of the firewall guys fat-fingered the port rules.  Got them corrected last night and joined the VM to our domain this morning.
0
 
LVL 38

Assisted Solution

by:Aaron Tomosky
Aaron Tomosky earned 333 total points
ID: 39895331
Good to hear. Don't forget to uncheck "register this connection in DNS" for all the non VPN nics. Ip4 and ipv6
0
 
LVL 38

Expert Comment

by:Aaron Tomosky
ID: 39895936
one last thing, this was new to me, might be old hat to you:
server manager -> tools -> active directory sites and services
add a site for your remote stuff seperate from default-first-site and make subnets for all the sites. I called my remote site "vpn" and assigned it a /32 network (one ip) for the vpn box. this keeps it out of the rotation better than turning down the weight and priority (but I left those settings set as well).
0

Featured Post

ScreenConnect 6.0 Free Trial

At ScreenConnect, partner feedback doesn't fall on deaf ears. We collected partner suggestions off of their virtual wish list and transformed them into one game-changing release: ScreenConnect 6.0. Explore all of the extras and enhancements for yourself!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Steve Terp was featured in a video created by CRN about how "Channel Is Crucial To Market Disruption". Click on View source to see the video and article
Happy holidays! Your Ops team can pack their bags. IT management and IT management tools are dead. Or at least that’s according to a new blog from Tech Target on AWS’s new Managed Services (MS) offering.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now