Active Directory Controllers?

From: Matt (matth+newsgroups_at_matthoppes.org)
Date: 04/27/04


Date: Tue, 27 Apr 2004 13:17:18 -0400

Here's what our network looks like:

FIREWALL 1:
Outside: 63.174.x.x network (OUTSIDE)
AD Controllers: 10.200.1.x network (DMZ)
Clients: 172.16.1.x network (INTERNAL)

FIREWALL 2:
Outside: 63.174.x.x network (OUTSIDE)
Clients: 10.200.1.x network (DMZ)

We are trying to get the clients from behind firewall2 to behind the
INTERNAL of firewall1. The issue is that right now they are able to
authenticate and all is happy. They go from firewall2 to firewall 1
across the outside interfaces and then through a map to the DMZ to get
to the AD controllers.

When I try to move the clients behind the INTERNAL on FIREWALL1 I get
'No domain controllers are available to service your login request'.
I have a hosts file in place for the two domain controllers and have a
map going across from 172.16.1.x to 10.200.1.x. I can ping the DCs.
If I'm on a machine NOT on the domain I can connect to the DCs via
filesharing and their 172.16.1.x map. however, if I try that same thing
with a machine on the domain behind the INTERNAL I get the 'no domain
controller' message.

Any ideas?



Relevant Pages

  • Re: IP address assignment problem
    ... I have a little problem and seek for ur thoughts, let's assume I'm in a very open environment where everyone can very easily try to get his/her laptop on the network and IP addresses are assigned by a DHCP server and we are in a domain environment, how do I prevent machines that are not part of our domain to be assigned an IP address? ... This approach doesn't stop your rogue clients from connecting to other clients, but merely doesn't give them the information they normally need to do so. ... Using 802.1x, your workstations authenticate through the switch to a radius server before they are allowed any connectivity. ... This authentication can use X.509 certificates, computer account credentials from AD, or whatever else you'd normally configure radius to authenticate with. ...
    (Focus-Microsoft)
  • RE: Dropped Client Connections
    ... I understand that the SBS clients will lose ... Do all clients lose network connection at same time? ... Do you have single or double NICs on SBS? ... Modify the registry to disable Receive Side Scaling ...
    (microsoft.public.windows.server.sbs)
  • Multiple Consistent Security Event Logs
    ... to capture Audits for both the Clients n the Servers. ... enabled certain other policies relating to secure Network Communication. ... Object Access, Logon/Logoff, Account Logon, Privilege Use with 'User' varying ...
    (microsoft.public.win2000.security)
  • Re: Please help me "sell" the idea of a more secure network
    ... changes first should bring the network up a notch or two. ... Do the same thing using a wireless notebook from you company. ... show him a PO or invoice for a customer who had an AV ... products, releases, life cycles, etc, all on the individual clients. ...
    (microsoft.public.win2000.active_directory)
  • Re: Please help me "sell" the idea of a more secure network
    ... changes first should bring the network up a notch or two. ... Do the same thing using a wireless notebook from you company. ... show him a PO or invoice for a customer who had an AV ... products, releases, life cycles, etc, all on the individual clients. ...
    (microsoft.public.win2000.active_directory)