Re: DNS over NAT on separate subnets

Tech-Archive recommends: Speed Up your PC by fixing your registry



Maybe a Site to Site VPN between the DCs.

Doug Sherman
MCSE, MCSA, MCP+I, MVP

"ablack@xxxxxxxxxxx" <ablackcarneyscom@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:72E6225C-EE3B-45D8-B35A-AF1851EB883B@xxxxxxxxxxxxxxxx
I don't believe that this is possible, but I thought I would check. The
scenario is this.

Subnet 1 206.15.87.x/24 Multiple W2K3 AD domain controllers and other
windows boxes. All work correctly and ultimately NAT via Cisco ASA to
internet (no problems at this site all OK DNS stable)

Subnet 2 connected over wireless radio to the inside of network
206.15.87.x
not through outside internet line our over Cisco ASA. This site has IP's
11.50.200.x/24 and is NAT'd for security reasons to 206.15.87.10. with
another Cisco ASA at subnet 2 site. This segment can browse all of
206.15.87.x network and can hit internet via the NAT'd Cisco ASA at subnet
1

The problem I want to add a W2K3 domain controller at subnet 2 If I do,
it
will report it's DNS as 11.50.200.200 since this is its actual IP. This
will
work for subnet 2, but will cause problems at subnet 1 since this subnet
knows nothing about the 11.50.200.x network. If I change the DNS entry for
the server at subnet 2, then subnet 1 will be able to find the server, but
clients at subnet 2 will fail, since the address is the outsid NAT'd
address.

Really don't know how to get around this, or if I should even try!


.



Relevant Pages

  • Re: Floating Computer between domains
    ... Just make sure that only the DCs use that router for that specific subnet, you can do that by adding persistent routes to the DCs. ... Active Directory communication fails on multihomed domain controllers ...
    (microsoft.public.windows.server.active_directory)
  • Re: Computer Account Creation
    ... I created a new site and subnet within AD sites and services, ... >> I have a new VLAN which has its own subnet, which I have put in AD. ... >> computer and domain controllers DHCP and DNS work ok, ... >> a hassle rather than a major problem. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Correct Setup of Active Directory
    ... by rounters and there are no domain controllers or member servers at these ... subnet and another site less than 10 miles away with about 100 people ...
    (microsoft.public.windows.server.active_directory)
  • Re: User authenticates, skips logon script
    ... It contains my six domain controllers. ... controller has NTDS settings which include a Connections Property ... I recommend setting up an IP Subnet Object for each subnet in each remoet location. ... You'll also want to specify local DCs as DNS servers for clients and the DCs themselves as the first entry, to reduce DNS queries.over the WAN. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Logon to a Site vs Subnet
    ... "The client sends a DNS Lookup query to DNS to find domain ... of each domain controllers on the site, ... subnet, each subnet have a domain controller. ...
    (microsoft.public.windows.server.active_directory)