Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

2 Offices with DNS replication worked until moved from MPLS to site to site VPN cisco

Posted on 2014-03-13
6
Medium Priority
?
320 Views
Last Modified: 2014-03-26
Hello EE,
I used to have replication of DNS working between all DCs in my branch office.
Repadmin /Replsum came back clean.
Now when I moved one of my branches behind a Site to Site VPN tunnel with Cisco ASA5525 on one side and Cisco 5505 on the other I am getting errors that that server "RPC server is unavailable"

I even went into sites and services and tried replicate now and got controller: DC1 (behind the site to site) "The RPC Server is Unavailable"  I ran dcdiag and got

[Replications Check,DC2] A recent replication attempt fail
   From DC1 to DC2
   Naming Context: DC=bergquistcompany,DC=com
   The replication generated an error (1722):
   The RPC server is unavailable.
   The failure occurred at 2014-03-13 09:10:00.
   The last success occurred at 2014-03-10 17:34:07.
   273 failures have occurred since the last success.
   The source remains down. Please check the machine.

The last success is the date before we moved them to the site to site VPN tunnel.  Is there something I need to add to allow RPC to pass?
0
Comment
Question by:bergquistcompany
  • 4
6 Comments
 
LVL 22

Expert Comment

by:Matt V
ID: 39927177
Make sure the required traffic is allowed across the tunnel.

UDP port 53 for sure.
0
 

Author Comment

by:bergquistcompany
ID: 39927979
All ports between the two networks /16 is allowed
0
 

Author Comment

by:bergquistcompany
ID: 39929458
Found out that tunnel is not allowing fragmentation.
tried ping -f -l 1472 dc2 and getting
packet needs to be fragmented but DF set
0
 The Evil-ution of Network Security Threats

What are the hacks that forever changed the security industry? To answer that question, we created an exciting new eBook that takes you on a trip through hacking history. It explores the top hacks from the 80s to 2010s, why they mattered, and how the security industry responded.

 
LVL 41

Expert Comment

by:footech
ID: 39935156
I don't think that it's the tunnel that is not allowing fragmentation.  You specified in your ping command not to allow fragmentation.  What the message indicates is that the packet size was too big to pass through unfragmented.

You could try adjusting the packet size that is sent through the tunnel.
I would test with prtqry.exe to make sure traffic is not being blocked by a firewall.
0
 

Accepted Solution

by:
bergquistcompany earned 0 total points
ID: 39935754
found the firewall needed a crypto to enable fragmentation
0
 

Author Closing Comment

by:bergquistcompany
ID: 39955454
heard from Cisco
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

877 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question