DCPROMO/AD over VPN Sunday, July 20 2003 @ 01:56 PM EST Contributed by: stoked
Short Story: DNS traffic to home site not being encrypted and as it was to and from private IP space, was being dropped at the router.
Resolution: Specific encrypt rule for DNS traffic to home site.
Long Story: I had quite a time trying to get AD replication going between two sites over a site-to-site vpn. Was working with Microsoft and the remote DC couldn't find the domain. Other symptoms were that the File Replication Service wasn't replicating with DNS errors. Looking at the remote site's firewall logs I finally noticed that the DNS queries that were coming from the remote DC were being allowed by rule 0 when all of the other traffic (ldap, kerberos etc) destined for the home site was allowed by rule 1, the encryption rule. I turned off udp dns in the Global Properties and created a specific encryption rule for DNS to the home site and everything was sunshine with DCPROMO/AD.
FAQForm FAQs.Class:
EncryptionFAQs FAQs.OS:
OsWindows FAQs.Version: