Networking Forums

Networking Forums > Computer Networking > Windows Networking > Domain controlers between NAT

Reply
Thread Tools Display Modes

Domain controlers between NAT

 
 
maddhaze@gmail.com
Guest
Posts: n/a

 
      08-24-2005, 02:21 PM
I have DC's at two different sites (CA and NY). Both used to have
public addresses. Now I had to change the address on the server in CA
to a NAT address because we put in a firewall and everything needs to
be behind it. The server in CA does have a coresponding outside
address, however, because of AD the server in NY is seeing the
non-routable address of the CA server. This is causing replication to
blow up. I tried placing a host entry for the CA server on the NY
server but replication traffic is still trying to go over the NAT
address. Is there a way to fix this so the NY sever and CA server can
talk properly? Over the outside addresses? Any ideas?

Thank you.

 
Reply With Quote
 
 
 
 
Yaytay
Guest
Posts: n/a

 
      08-24-2005, 02:31 PM
<(E-Mail Removed)> wrote in message
news:(E-Mail Removed) ups.com...
>I have DC's at two different sites (CA and NY). Both used to have
> public addresses. Now I had to change the address on the server in CA
> to a NAT address because we put in a firewall and everything needs to
> be behind it. The server in CA does have a coresponding outside
> address, however, because of AD the server in NY is seeing the
> non-routable address of the CA server. This is causing replication to
> blow up. I tried placing a host entry for the CA server on the NY
> server but replication traffic is still trying to go over the NAT
> address. Is there a way to fix this so the NY sever and CA server can
> talk properly? Over the outside addresses? Any ideas?


What is the connectivity between the two sites?
Are/were you doing your synchronisation directly over the Internet?

I think you probably could reconfigure the firewalls in both sites to enable
replication, I think you should be looking at a VPN between them.
Once you have a VPN in place the two servers will be able to see the
internal networks of both sites (assuming it's suitably configured).
Is that the sort of thing you are after?

J.T.


 
Reply With Quote
 
Manny Borges
Guest
Posts: n/a

 
      08-24-2005, 02:56 PM
You have lots of options depending on how you are set up.

How many public IPS do you have on the out side of the NAT?

"(E-Mail Removed)" wrote:

> I have DC's at two different sites (CA and NY). Both used to have
> public addresses. Now I had to change the address on the server in CA
> to a NAT address because we put in a firewall and everything needs to
> be behind it. The server in CA does have a coresponding outside
> address, however, because of AD the server in NY is seeing the
> non-routable address of the CA server. This is causing replication to
> blow up. I tried placing a host entry for the CA server on the NY
> server but replication traffic is still trying to go over the NAT
> address. Is there a way to fix this so the NY sever and CA server can
> talk properly? Over the outside addresses? Any ideas?
>
> Thank you.
>
>

 
Reply With Quote
 
maddhaze@gmail.com
Guest
Posts: n/a

 
      08-24-2005, 03:27 PM
I'm thinking VPN may be the answer (MS VPN). There is a T1 between the
sites and both have Cisco firewalls, but I have no more interfaces on
the CA pix or else I would just keep that box on a routable address.
Haven't had to setup the VPN before, is there a way to make it a
permanant link?

 
Reply With Quote
 
Yaytay
Guest
Posts: n/a

 
      08-24-2005, 03:50 PM

<(E-Mail Removed)> wrote in message
news:(E-Mail Removed) oups.com...
> I'm thinking VPN may be the answer (MS VPN). There is a T1 between the
> sites and both have Cisco firewalls, but I have no more interfaces on
> the CA pix or else I would just keep that box on a routable address.
> Haven't had to setup the VPN before, is there a way to make it a
> permanant link?
>


My first consideration would be for a VPN between the pixes, rather than an
MS VPN.
For the MS VPN to work the pixes will have to be configured to allow that
VPN traffic through no matter where it is from, whereas a pix to pix VPN can
be guaranteed to come from the appropriate box - it just keeps the decision
a bit further away from the servers.

J.T.


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
hostname domain different from Active Diretory domain - kerberos problems Blake Windows Networking 4 07-27-2008 10:21 PM
Unable to browse domain list for primary domain on any server or P Fraser Simpson Windows Networking 6 09-15-2006 03:39 PM
Have Domain Controlers and Users connect to port 389 instead of 636? Egbert Nierop \(MVP for IIS\) Windows Networking 0 11-12-2005 12:33 PM
VPN: unable to connect to the shares in a Win2003 Domain Server of a child domain Stefano Del Furia Windows Networking 5 11-02-2005 06:23 PM
Connecting 2000 to 2000 Domain Controlers Mohammed Windows Networking 3 06-29-2004 06:21 PM



1 2 3 4 5 6 7 8 9 10 11