Solved

2 Offices with DNS replication worked until moved from MPLS to site to site VPN cisco

Posted on 2014-03-13
6
307 Views
Last Modified: 2014-03-26
Hello EE,
I used to have replication of DNS working between all DCs in my branch office.
Repadmin /Replsum came back clean.
Now when I moved one of my branches behind a Site to Site VPN tunnel with Cisco ASA5525 on one side and Cisco 5505 on the other I am getting errors that that server "RPC server is unavailable"

I even went into sites and services and tried replicate now and got controller: DC1 (behind the site to site) "The RPC Server is Unavailable"  I ran dcdiag and got

[Replications Check,DC2] A recent replication attempt fail
   From DC1 to DC2
   Naming Context: DC=bergquistcompany,DC=com
   The replication generated an error (1722):
   The RPC server is unavailable.
   The failure occurred at 2014-03-13 09:10:00.
   The last success occurred at 2014-03-10 17:34:07.
   273 failures have occurred since the last success.
   The source remains down. Please check the machine.

The last success is the date before we moved them to the site to site VPN tunnel.  Is there something I need to add to allow RPC to pass?
0
Comment
Question by:bergquistcompany
  • 4
6 Comments
 
LVL 22

Expert Comment

by:Matt V
Comment Utility
Make sure the required traffic is allowed across the tunnel.

UDP port 53 for sure.
0
 

Author Comment

by:bergquistcompany
Comment Utility
All ports between the two networks /16 is allowed
0
 

Author Comment

by:bergquistcompany
Comment Utility
Found out that tunnel is not allowing fragmentation.
tried ping -f -l 1472 dc2 and getting
packet needs to be fragmented but DF set
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 39

Expert Comment

by:footech
Comment Utility
I don't think that it's the tunnel that is not allowing fragmentation.  You specified in your ping command not to allow fragmentation.  What the message indicates is that the packet size was too big to pass through unfragmented.

You could try adjusting the packet size that is sent through the tunnel.
I would test with prtqry.exe to make sure traffic is not being blocked by a firewall.
0
 

Accepted Solution

by:
bergquistcompany earned 0 total points
Comment Utility
found the firewall needed a crypto to enable fragmentation
0
 

Author Closing Comment

by:bergquistcompany
Comment Utility
heard from Cisco
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now