Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Join a server from a different subnet to the domain

Status
Not open for further replies.

digitallyskilled

IS-IT--Management
Sep 23, 2004
39
US
I have a watchguard firewall that seperates 2 of my subnets

10.1.1.0/24 TRUSTED and 10.1.2.0/24(DMZ)

I want to add a server on the DMZ to the domain. I have dns, kerebos, smd and rpc and Ping opened on the firewall but the server still can not resolve the dns name to join it to the domain. any ideas
 
Try opening netbios or try when joining to the domain, the whole domain name. For example, instead of telling it to join the domain blah try blah.com.

RoadKi11
 
I have that port open as well still no luck.

I can ping the ip address fine, but i cant type in the server name and have it resolve.
 
the primary dns server for the server in the dmz is the domain controller for the domain you are trying to join correct? you dont have ISP dns address in the dmz server do ya?

RoadKi11
 
Try this, in the hosts file on the server in the dmz add an entry for your domain controller then try and join. looks at the hosts file first for resolution, this isnt a fix but it may give more info to work with.

RoadKi11
 
on new servers use LMHOST file to point the your DC.

:--------------------------------------:
fugitive.gif


All around in my home town,
They tryin' to track me down...
 
Got it sorted with the help of microsoft support. basically it is just the matter of opening the right ports here is a summary

Here is the port query tool that we used.


Here is an article that shows how to use it


Here is the article that showed us what ports to open


This is how we found the additional ports to open (see step for at the bottom of the page)


We also used the Microsoft packet analyzer but I am sure any packet analyzer would do.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top