Re: VPN and DNS issues



First of all, you should have your internal DNS in the VPN server and the VPN server assign the DNS to the client. Another option is setup WINS for name resolution. It is better to have WINS for VPN name resolution. If both internal DNS and WINS are not options for you, you can try mlhosts. I would not use my ISP host my A records. Or the following search results may help.

Name resolution on VPN
Name resolution is big issue in VPN access. If your VPN server doesn't setup correctly or the VPN client can't receive the VPN DNS and WINS settings, ...
www.chicagotech.net/nameresolutionpnvpn.htm - Similar pages

VPN name resolution and browsing
Q: VPN name resolution and browsing. After I successfully connect to the VPN Server remotely, I cannot browse the network, and see other computers and ...
www.chicagotech.net/Q&A/vpn1.htm


--
Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com


"Curtis" <Curtis@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:874028A1-6487-4982-845B-A70D3C8325B8@xxxxxxxxxxxxxxxx
My appologies if I am posting to the incorrect group, if I am please let me
know and I will repost to a more appropriate group.

We have a Microsoft VPN server that has been connected to a T1 for many
years now. Just recently it was switched to a new fiber connection from a
local ISP. After we switched the connection on the T1 we have been having
name resolution issues for our VPN clients. We have a 2003 Exchange server
that is accesible via the web and our internal network. When a VPN client
pings the Exchange server WHILE connected to the VPN it returns the public IP
instead of the private. No other changes have been made other than switching
the VPN server to the new ISP and updating the public DNS records for the VPN
connection. Currently the VPN server is running Windows Server 2003 SP1.

Example:
pinging s3.mydomain.net while connected to the VPN returns 65.x.x.x instead
of the correct 172.x.x.x internal address.

If a client sets their DNS servers to either the T1 or Fiber connections
default DNS servers, then the proper address is returned. However, for most
other clients, myself included, when using a default IP of the local
CABLE/DSL router it wants to return the public IP address.

A bit more info that may or may not be useful (I have replaced the actual
domain name with "mydomain"):
Current public dns records for our exchange server and VPN:
s3.mydomain.net CNAME to host155.mydomain.com resolves to Exchange server
public IP.
v1.mydomain.net CNAME to host7.mydomain.com resolves to VPN server public ip
address.

a reverse lookup of the exchange server public ip address returns
host155.mydomain.com
a reverse lookup of the VPN server public ip address returns
host7.mydomain.com.

mydomain.net is also our internal active directory name and we are using
split brain DNS.

We do not host our own public DNS servers.

No one is using vpn split tunneling.

the new ISP is a wide open connection that allows all traffic to pass with
no firewalls or filters between us and them.

If any further information is needed or anyone has any ideas for further
tests to run please feel free to ask.

Thank you!

.



Relevant Pages

  • Re: WOW - Changing Network Subnet on SBS2003 Got me crazy
    ... VPN and not able to access network shares ... I have tried all this, restarted/started dns & netlogon, cleared server Wins ... Resolve host names from a client machine to access files and map drives ...
    (microsoft.public.windows.server.sbs)
  • Re: Could someone tell me how to locate things in the network?
    ... So if you do have WINS you can enable WINS lookup on your DNS ... resolve this issue or you need to supply WINS entries tot he client. ... >> recommend doing is looking at a Client that has a VPN connection. ... >> registering into DNS properly on the internal network. ...
    (microsoft.public.isa.configuration)
  • Re: VPN server (hardware) and VPN client (Software) - both with changing IP. Can it be?
    ... How many clients will be using the VPN functionality simultanesously? ... >to have VPN server as a hardware box and client could be software. ... >For server we have registered with dyndns.org, so we have constant dns name ... what VPN server box would you recommend to buy? ...
    (comp.security.firewalls)
  • Re: Need help with naming conflict
    ... I'm talking about direct client to office VPNs from their home ... DNS naming for resolving a computer name? ... I am sending the internal DNS server to the VPN clients, ...
    (microsoft.public.win2000.dns)
  • Re: VPN Routing Problem
    ... to my company's LAN using Kerio Winroute Firewall 6 and the VPN server and client that comes with it. ... resolve to 172.16.200.0 range ip addresses. ...
    (alt.os.windows-xp)