Fun AD trouble with multiple sites

From: Chris K (AnAmoeba_at_online.nospam)
Date: 09/29/04


Date: Tue, 28 Sep 2004 17:51:01 -0700

Howdy!

Have two sites connected via T1 VPNs; all private IP addresses. However,
the VPNs terminate OUTSIDE the ISA or PIX on each LAN, so we're mapping
"external" private IPs to "internal" private IPs as follws:

Site A: Internal PC addresses 192.168.100.0/24 - mapped to "external"
addresses of 192.168.101.0/24 through ISA

Site B: Internal 192.168.150.0/24 - mapped to "external" addresses of
192.168.151.0/24 through Pix

Everyone can talk to each other, share files, etc provided we maintain split
DNS systems - with each site pointing to the "external" IPs of the other.

The problem is, Active Directory doesnt like it; each machine registers its
LOCAL PRIVATE ADDRESS in DNS - and accordingly, cant be contacted by machines
at the other site.

Should we just maintain split DNS's that include all the AD information?
Possible, but seems nasty.

Any suggestions?

Thanks!

Chris



Relevant Pages

  • Re: ISA Server inside a private network ???
    ... Effectively that is what you do with a back-to-back DMZ. ... Insert the ISA between the regular LAN and the DMZ. ... As far as the PIX is concerned the DMZ *is* the Private LAN,...it doesn't know ...
    (microsoft.public.isa)
  • Re: PIX + ISA(Please help ASAP)
    ... If you don't want to make any LAN design changes then the PIX and the ISA ... They are usually private. ... Phillip Windell ...
    (microsoft.public.isa.configuration)
  • Re: WKS outside PIX
    ... > inside an another private and very large intranet. ... > Between this network there is a pix Firewall. ... The problem is, unless you VPN through the firewall, you'll have to make the ...
    (microsoft.public.win2000.dns)
  • Re: multihome network
    ... my private IP that eventually resolves to public IP through PIX is ... what i've tried is adding route on my box ... The connection works by connecting to the public IP of the PIX (that ...
    (freebsd-questions)
  • Re: Dynamic Site to Site
    ... :But my pix in Plant C is going to have a private IP. ... the ISP is assigning a dynamic *private* IP to C's PIX? ...
    (comp.dcom.sys.cisco)