Werbung: SecurityConsole.de verwaltet Ihre Computer mit Security Essentails aus der Cloud!
30 Tage kostenfrei testen und 20% Rabatt für Ihre Bestellung mit Promocode: WBF2685582
(Promocode gültig bis 31.12.2011)

Group:  English: Windows Server » microsoft.public.windows.server.networking
Thread: DNS issues while connected to VPN

HTVi
TV Discussion Newsgroups

DNS issues while connected to VPN
newsgroups.jd[ at ]gmail.com 12/24/2008 3:36:46 PM
Just curious if anyone had seen this before...

While I am at home connected to the VPN I am trying to access an
application on the internal network. In order for this application to
work - it has to DNS query an item on another domain.

We have DNS suffix search list in place - the domain it needs to query
is number 2.

Looking at a packet capture about 25% of the time the client does not
query the second DNS suffix in the search list.

To clarrify, most of the time it queries the first item, it responds
it doesn't know and the client tries the second in the search list.
Some times however it bypasses checking the DNS suffix search list and
the application fails.

Any clue why the client would ignore the DNS suffix search list?

Thanks
Re: DNS issues while connected to VPN
"Phillip Windell" <philwindell[ at ]hotmail.com> 12/24/2008 6:59:31 PM
The DNS at work is the only one that should be associated with the VPN
connection (typically via DHCP). The work DNS then needs to use that other
DNS as a Forwarder. It can either be a Conditional Forwarder or an
Unconditional Forwarder depending on what works best in the situation.

Forget Suffixes
Forget Netbios Names
Always identify the target with the FQDN,...even if that means you have to
tweek the config within this Application you are talking about. FQDNs
eleminate the whole idea of Suffixes and will solidly identify the correct
domain,...and hence,...the correct DNS that should be "queried".


--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


<newsgroups.jd[ at ]gmail.com> wrote in message
news:35731d60-aa58-4a98-a3d1-8cd1c25fbac2[ at ]d42g2000prb.googlegroups.com...
[Quoted Text]
> Just curious if anyone had seen this before...
>
> While I am at home connected to the VPN I am trying to access an
> application on the internal network. In order for this application to
> work - it has to DNS query an item on another domain.
>
> We have DNS suffix search list in place - the domain it needs to query
> is number 2.
>
> Looking at a packet capture about 25% of the time the client does not
> query the second DNS suffix in the search list.
>
> To clarrify, most of the time it queries the first item, it responds
> it doesn't know and the client tries the second in the search list.
> Some times however it bypasses checking the DNS suffix search list and
> the application fails.
>
> Any clue why the client would ignore the DNS suffix search list?
>
> Thanks


Re: DNS issues while connected to VPN
"Ace Fekay [Microsoft Certified Trainer]" <firstnamelastname[ at ]hotmail.com> 12/25/2008 3:53:48 AM
In news:35731d60-aa58-4a98-a3d1-8cd1c25fbac2[ at ]d42g2000prb.googlegroups.com,
newsgroups.jd[ at ]gmail.com <newsgroups.jd[ at ]gmail.com> requesting assistance,
typed the following:
[Quoted Text]
> Just curious if anyone had seen this before...
>
> While I am at home connected to the VPN I am trying to access an
> application on the internal network. In order for this application to
> work - it has to DNS query an item on another domain.
>
> We have DNS suffix search list in place - the domain it needs to query
> is number 2.
>
> Looking at a packet capture about 25% of the time the client does not
> query the second DNS suffix in the search list.
>
> To clarrify, most of the time it queries the first item, it responds
> it doesn't know and the client tries the second in the search list.
> Some times however it bypasses checking the DNS suffix search list and
> the application fails.
>
> Any clue why the client would ignore the DNS suffix search list?
>
> Thanks

I agree with Phillip. The DNS servers list in IP properties is not meant to
toggle back and forth until it finds a response. If the first one doesn't
have an answer, it becomes a NULL answer, and since the client side resolver
service received an answer, albeit not the one YOU want, it is still an
answer and will look no further.

Make sure as Phillip said, that only the company DNS is listed. Make sure
the company DNS has some way of resolving it as Phillip described with his
suggestions.


--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCT
Microsoft Certified Trainer

For urgent issues, you may want to contact Microsoft PSS directly.
Please check http://support.microsoft.com for regional support phone
numbers.

Home | Search | Terms | Imprint Contact
Newsgroups Reader - provided by WiredBox.Net
Suche nach Orten, Städten, Postleitzahlen, Vorwahlen, Kfz-Kennzeichen