Re: RRAS/NAT connected stations can't access websites

Tech-Archive recommends: Fix windows errors by optimizing your registry



If you are running a domain, all machines must use the local DNS server.

To resolve foreign URLs as well as local names, set this DNS to forward to a public DNS server or to the DNS server on the corporate LAN.

With a domain you cannot use the default setting in NAT which is to let the NAT router act as a DNS proxy. You still use the NAT router as your default gateway but use the local server for DNS because it is necessary for Active Directory.


"Thorin" <The_Mighty_Thorin@xxxxxxxxxxxxx> wrote in message news:BE5FB8CD-0A16-475C-90CB-28AD916F5CAC@xxxxxxxxxxxxxxxx
Recently it became necessary to setup RRAS on Windows Server 2003 R2 to perform NAT for a small network that is being used as a testing environment. The network had an existing domain controller that holds the roles for DHCP/DNS and Directory services. The RRAS server has just two network connections (WAN, LAN) and there it connects directly to the outside world.

The WAN NIC is set to:
Public interface connected to the Internet
Enable NAT on this interface

There are no Inbound or Outbound Filters on the connection.

Computers inside the network can ping the LAN Adapter successfully and using NSLookup from computers behind the NAT it is possible to resolve DNS Names to IP Addresses. What doesn't work is when a client tries to connect to a website using a browser all of the clients recieve an error that they cannot display the page.

Has anyone seen a document that explains setting up a simple NAT router using Windows Server 2003 R2?

Thanks.

.



Relevant Pages

  • Re: AD/DNS with NAT
    ... Our client desires to change his network infrastructure ... Datacenters host servers as Domain Controllers AD2003, DNS, Exchange ... every small offices to use NAT in order to keep the private IP range ...
    (microsoft.public.windows.server.active_directory)
  • Re: 2 DNS, one machine
    ... What I'm trying to do is set up a small home network to teach myself ... >separate DNS server for every local subnet, ... >internet connection of course, then set up a NAT (network address ... >allows one DNS server to act like it is multiple servers. ...
    (Fedora)
  • Re: AD/DNS with NAT
    ... his entire network is based on a private range. ... Datacenters host servers as Domain Controllers AD2003, DNS, Exchange ... every small offices to use NAT in order to keep the private IP range ...
    (microsoft.public.windows.server.networking)
  • Re: Can Not Ping By Name
    ... >>> Make sure there's no firewall packaged with the VPN client. ... >>DNS server is the same physical server as the Exchange, ... > Network problem solving - general advice: ...
    (microsoft.public.windowsxp.network_web)
  • Re: network has gone down again, and I cannot figure out why
    ... search dns: dns.asm.bellsouth.net ... try against the secondary DNS server address. ... up DHCP on this end and now I can email. ... DHCP just configures your side of the network with the data that the ...
    (Fedora)