Re: DNS With VPN

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Ace Fekay [MVP] (PleaseSubstituteMyActualFirstName&LastNameHere_at_hotmail.com)
Date: 03/03/04


Date: Wed, 3 Mar 2004 17:21:48 -0500

In news:06GdnRmqZpavUNjdSa8jmA@karoo.co.uk,
MadCrazyNewbie <test@nospam.com> posted their thoughts, then I offered mine
> Hey There Many thanks for your reply, please see comments below:
>>
>> No, DNS does not use broadcasts.
>>
>> We'll need more info about your configuration and topology, such as:
>>
>> 1. Are the clients using their respective local DNS or they pointing
>> to a DNS across the WAN?
>
> The sites are pointing to a DNS accross the Wan (10.10.210.10 &
> 10.10.210.20)
>
>> 2. Are the clients using an ISP's DNS?
>
> No
>
>> 3. If DNS is distributed among your locations, is it AD Integrated,
>> or Primary/Secondaries?
>
> AD Intergraded
>
>> 4. While you were testing this (assumed you are trying to resolve
>> it), have you tried specifying a different DNS in the client, such
>> as one that is across the WAN in a different location (assuming your
>> DNS infrastructure is distributed).
>
>> 5. Any errors in the Event viewer on a client and/or the DNS server
>> or any other errors or observations that seem amiss?
>
> No everything looks good on the client side and on the server side
>
>>
>> Can we see an ipconfig /all of a client that is not resolving please?
>>
> Windows IP Configuration
>
> Host Name . . . . . . . . . . . . : it-pc-04
> Primary Dns Suffix . . . . . . . : JRRIX.INT
> Node Type . . . . . . . . . . . . : Unknown
> IP Routing Enabled. . . . . . . . : No
> WINS Proxy Enabled. . . . . . . . : No
> DNS Suffix Search List. . . . . . : JRRIX.INT
>
> Ethernet adapter Local Area Connection:
>
> Connection-specific DNS Suffix . :
> Description . . . . . . . . . . . : Intel(R) PRO/1000 CT
> Network Connection
> Physical Address. . . . . . . . . : 00-0C-76-43-5F-FF
> Dhcp Enabled. . . . . . . . . . . : No
> IP Address. . . . . . . . . . . . : 10.10.220.3
> Subnet Mask . . . . . . . . . . . : 255.255.0.0
> Default Gateway . . . . . . . . . :10.10.210.1
> DNS Servers . . . . . . . . . . . : 10.10.210.10
> 10.10.210.20
>
> Many Thanks
> Merlin

Hi Merlin,

Thanks for posting that information.

It seems, looking at that client's ipconfig, it appears that the DNS
addresses shown are in the same subnet, based on the subnet mask. But you
said they are in a different subnet? The mask is telling me that it's
local??

If the mask is incorrect, and if so, I'm going to assume it should be
255.255.255.0 (class C or /24), then I'm going to assume, that the DNS
servers are in another location and that all resolution has to go over the
WAN. If there is any excessive traffic or the link is down, this can cause
majore issues, besides Internet resolution, you'll have directory services
resolution issues, which can result in lack of connectivity to resources.

I would suggest to put a DNS server in the remote subnets local to the
clients. I am going to assume you have a DC in the respective local subnets
to facilitate logons instead of traversing the WAN. If the case, I would
suggest to install DNS on it and set the zone AD Integrated. This way at
least the DNS server will be available.

Let me know if this helped.

-- 
Regards,
Ace
Please direct all replies to the newsgroup so all can benefit.
This posting is provided "AS IS" with no warranties.
Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
Microsoft Windows MVP - Active Directory
-- 
=================================


Relevant Pages

  • Re: DNS dfs issue
    ... You say that some clients are OK. ... The domain controllers for SiteA are named: ... No matter which dns server I use on clientB1 its %logonserver% is always ...
    (microsoft.public.windows.server.dns)
  • Re: newbie lost in trying to setup NAT
    ... That is what you have DHCP for. ... You set the clients to obtain an IP ... address automatically and to obtain their DNS server automatically. ...
    (microsoft.public.windows.server.networking)
  • Re: windows 2003 active directory and slow logons
    ... so WHY not create a subnet in AD that covers that. ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... DHCP provided by linux box and clients get ip addresses from the ... The remote site has a local DC that is also a DNS for the AD DNS ...
    (microsoft.public.windows.server.active_directory)
  • Re: Creating my first user accounts
    ... I am trying to log onto the domain with the clients to have access to shared ... files and access the internet. ... DNS is almost always the cause of authentication errors -- ... Did you alter the DNS server settings, ...
    (microsoft.public.windows.server.active_directory)
  • Re: applying computer settings takes a lot of time
    ... PC and DNS/DC are in the 192.168.10.x subnet ... Add a DNS/DC to the site where the computers are located and let the clients use that machine as preferred DNS on the NIC and another site DNS as secondary for redundancy. ... So is there a DNS server in there subnet available? ... Connection-specific DNS Suffix. ...
    (microsoft.public.windows.group_policy)