Re: GPO's are not implemented in case of Firewall problems

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 04/30/04


Date: Fri, 30 Apr 2004 05:45:19 -0700


If you have defined sites, three of them, and placed the DCs
each in its correct site, then the clients should all each find
the DC that is within its site (its firewalled area). Since
clients will in their resolver behavior locate a preferred
DC based on site-locality, and on some other things like
preformance optimization, if the dnscache service is running
on them (that is, if they are allowed to use the DNS caching
resolver), if this is not happening, either
1. you do not have sites defined, or fully defined
2. the dns records in the sites subzones are incorrect
3. dnscache is shut off on the clients
or . . .

-- 
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCSE (W2k3,W2k,Nt4)  MCDBA
"Thomas Marti" <thomas.marti@fkd.bl.ch> wrote in message
news:%23DN6MyqLEHA.1644@TK2MSFTNGP09.phx.gbl...
> Hi
> We have a environment with 3 Sites in a Firewall-restricted Network.
> Only DC's can communicate through the firewall. if a client tries to load
> gpo, it resolves the DC by a DNS query about the domainname. It connects
> then to any DC given by DNS Round Robin. If the DC is behind the firewall,
> the policy could not be read. how can I fix the problem?
>
> A workaround is to deploy a hosts file. but there are 3500 clients in the
3
> sites.....
>
>
> thanks
>
> Thomas
>
>


Relevant Pages

  • Sendmail Conf query
    ... There is a Firewall in between two domains. ... The entry of the Firewall is existing in the DNS server ... All the HP unix clients are working ok,and are able sending mails to the mail ...
    (SunManagers)
  • Re: Using DNS & DHCP in multiple sites...
    ... > allow the clients to send requests over the VPN. ... Test that first - since you use your Firewall as VPN-Hub + DHCP-Relay ... > do I just set up DNS forwarding on each of the remote sites DNS ... DNS-Server, or to a DNS-Server in a DMZ or at your ISPs (or your ...
    (microsoft.public.windows.server.active_directory)
  • Re: DNS resolution problem
    ... MVP - Directory Services ... Normally clients will attempt to locate site-local services ... via their DNS and LDAP queries, and that is the most that you ... segregated by a firewall. ...
    (microsoft.public.windows.server.active_directory)
  • Re: IPTables Blocking Outbound by destination port.
    ... # firewall Firewall startup/shutdown script ... echo "firewall: ... # for each additional server running from 6000 to 6063. ... Clients may access remote POP-3 servers" ...
    (comp.security.firewalls)
  • SBS 2003 Strange Problem
    ... firewall. ... The clients can get onto the web, but the server cannot. ... The server is configured with DNS, ...
    (microsoft.public.backoffice.smallbiz)