Re: DNS and Domain problem

From: Ace Fekay [MVP] (PleaseSubstituteMyActualFirstName&LastNameHere_at_hotmail.com)
Date: 04/03/04


Date: Sat, 3 Apr 2004 12:46:19 -0500

In news:14fc601c419a2$992ff5b0$a601280a@phx.gbl,
Natasha <anonymous@discussions.microsoft.com> posted their thoughts, then I
offered mine
> Hello, I'm having a little problem with a test domian I've
> just built, but problem could simply be with firewall
> access that wasn't setup correctly but here is what I can
> and cannot do.
>
> I have a domain with three W2000 servers. Had no problems
> setting up the first DC. Setup DNS fine, only one server
> hosting AD Integrated for secure updates and replication
> and zone info storing within AD.
> I added the other two servers to the domain without
> problems and they added themselves into DNS. All these are
> on the asame subnet.
>
> Onm another subnet I have a W2000, on a different V-lan
> and seperated by a firewall. IP routing and port UDP 53 are
> open and avialable. I'm able to ping from this server to
> all server on the other subnet. I can even do NSlookups
> from this seperate server and it returns the result of the
> DNS server's IP and domain name. I specified this on the
> NIC's DNS entry.
> THough I can see, ping the DC and the other servers on the
> other subnet, I can't add this server to the Domain.
>
> I get the error that this could be a DNS problem, or there
> could be a problem with DNS lookup.
>
> Have I missed something out on the firewall access...?
>
> Please advise if you know....I guess there could be a mis-
> config on the firewall
>
> thanks
>
> Nat

Hi Nat,

You did everything perfect. The issue is the firewall. There are about 30
ports that need to be allowed pass thru. Read these articles below to
describe what ports need to be opened. However, on another note, if you can
possibly create a Tunnel Mode VPN between the subnets, that would be your
better bet, since opening all these ports for AD communication can lead to
security issues.

Active Directory Replication over Firewalls - Microsoft Service Providers:
http://www.microsoft.com/serviceproviders/columns/config_ipsec_P63623.asp

Download details Active Directory in Networks Segmented by Firewalls:
http://www.microsoft.com/downloads/details.aspx?displaylang=en&familyid=c2ef3846-43f0-4caf-9767-a9166368434e

Q289241 - A List of the Windows 2000 Domain Controller Default Ports:
http://support.microsoft.com/default.aspx?scid=KB;EN-US;Q289241&

Restricting Active Directory Replication Traffic to a Specific Port
(Q224196):
http://support.microsoft.com/?id=224196

My take on it is to use a VPN so as to allow all traffic between the VPN
endpoints (each router between the VPNs). Much more secure.

I hope this helps.

-- 
Regards,
Ace
Please direct all replies to the newsgroup so all can benefit.
This posting is provided "AS-IS" with no warranties and confers no
rights.
Ace Fekay, MCSE 2000, MCSE+I, MCSA, MCT, MVP
Microsoft Windows MVP - Active Directory
-- 
=================================


Relevant Pages

  • Re: For Microsoft Partners and Customers Who Cant Download or Access
    ... to reconfigure the firewall, but to use a static IP on your client ... and to make sure that the DNS server entries on the client are ... Microsoft for msdn2.microsoft.com. ... use a static IP and set the DNS server addresses to the DNS ...
    (microsoft.public.dotnet.general)
  • Re: loss of SOME connectivity
    ... I "think" it is DNS. ... Yes, I can ping the router, AND the ISP DNS. ... I cannot connect the inet cable directly to the server because the inet is ... MS firewall not started. ...
    (microsoft.public.windows.server.sbs)
  • Re: E-Mail Address Cant Receive E-Mail from *Some* External Organizations
    ... The fact that _some_ messages are delivered is because they are sent from different IPs, so double-check your firewall settings. ... So, that looks right to me, anyway; both resolve to the proper IP address of the external interface for our firewall, and the only difference is that for "company.org" our ISP's mail server acts as a backup server in case our internal mail server is down. ... However, if I send a message to "me@xxxxxxxxxxxxxxxx" from my Yahoo e-mail account, I get an NDR returned to my Yahoo account. ... I have checked with our ISP who handles our DNS settings, and they indicate that all appears to be in order with our DNS and MX records. ...
    (microsoft.public.exchange.admin)
  • Re: RE:IP Security in a stand alone Win2003 Standart Server
    ... I have the DNS port open because it is a DNS Server. ... > Firewall which has been enhanced in SP1 to be like the XP Pro Windows ... > all the opened IP ports? ...
    (microsoft.public.windows.server.security)
  • RE: Firewall Rule Set not allowing access to DNS servers?
    ... I changed the DNS rules as you suggested, and the firewall works perfectly - ... > # Allow out access to my ISP's Domain name server. ... > so your udp packets never match this rule and default to ...
    (freebsd-questions)

Loading