Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN Established How about DNS/WINS/Network Browsing?

Status
Not open for further replies.

Spitz

IS-IT--Management
Mar 28, 2001
5
0
0
US
We have established VPN with our PIX using just PPTP for now. I would like to be able to browse the remote network from the clients. We have defined DNS and WINS in the PIX and the IP is dynamically given with this info to the client. Still no network browsing. Any ideas?

Thanks
 
Yes we have made the access-lists and the NAT (or nonat for remote pptp). What I can't seem to figure out is how to get the network browse capability with Windows 98 once connected. Hmmmm must be missing something here.
 
Do you have a WINS server on the remote locations? In order to get browsing to work properly, we had to have WINS servers in each end of a 4 network internet (joined by IPSEC PIX VPN's) with the WINS servers being push and pull partners with all of the other WINS servers. There is no reason why you should have any problem with DNS however.
 
I made this today using Pix 6 with Cisco VPN Client version 3. With Cisco Secure VPN Client 5.2 and with 5.x version of Pix you cannot browse Windows Network.
I actually extend a Windows NT domain over a IPSEC Tunnel. And it works ok. Without a domain you will see computers in Network Neighborhood apearing after a long time. But you can map any share from any computer using net use... or Map Network Drive...
With Windows NT domain you can browse with Network Neighborhood.
I didn't use any Wins server or lmhosts file. Just a DNS server. And I push it with vpngroup from Pix
 
Ive just completed a remote access VPN using the Cisco client and a 1720VPN router. I cannot browse per se either. However, in my TCP/IP settings, I did specify my internal (private) WINS and DNS servers (different IPs). My main subnet is 192.168.0.xxx, and I use a range of 172.16.xx.xx for my local pool on the router. My workgroup name is the same as my main network.

What I CAN do is search for a computer by name through the tunnel. From what I can tell, all of the name resolution stuff is broadcast, and so it is blocked/dropped at the router. (right?) A specific search, however, has an originating, and thus a target, IP address. I can telnet/SSH/remote administrate like mad through the tunnel by IP address, and even ping by name using internal DNS, but I have, so far, had to use the Find Computer function (right-click Network Neighborhood) to access remote shared folders and printers.

On our site to site, we were able to get browsing working by setting one machine as the master browser for their subnet, and then diligently keeping an updated lmhosts file therein. It's a chore, but it cuts down on the service calls.

HTH

Nedstar1
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top