CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-12
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 582
Rep Power: 10
BarryStiefel has disabled reputation
Default DCPROMO/AD over VPN

DCPROMO/AD over VPN



Sunday, July 20 2003 @ 01:56 PM EST Contributed by: stoked

Short Story: DNS traffic to home site not being encrypted and as it was to and from private IP space, was being dropped at the router.

Resolution: Specific encrypt rule for DNS traffic to home site.

Long Story: I had quite a time trying to get AD replication going between two sites over a site-to-site vpn. Was working with Microsoft and the remote DC couldn't find the domain. Other symptoms were that the File Replication Service wasn't replicating with DNS errors. Looking at the remote site's firewall logs I finally noticed that the DNS queries that were coming from the remote DC were being allowed by rule 0 when all of the other traffic (ldap, kerberos etc) destined for the home site was allowed by rule 1, the encryption rule. I turned off udp dns in the Global Properties and created a specific encryption rule for DNS to the home site and everything was sunshine with DCPROMO/AD.

FAQForm FAQs.Class: EncryptionFAQs FAQs.OS: OsWindows FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:44.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0