Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN - unable to browse network

Status
Not open for further replies.

rperkins

IS-IT--Management
Aug 14, 2002
18
US
Have a Pix w/ VPN concentrator setup on Network.

We can connect to VPN and attach to the Network, but that is where the issue starts.

I can use IP numbers to connect via Radmin or Terminal server and connect to the different servers, but I can't use the server name like I can when connected locally.

When I goto browse the network at home, I can only see my system on the domain with the VPN.

Windows 2000 servers, XP Professional laptop w/ dialup

VPN client on laptop is version 3.6.3a

I am also unable to use my drive mappings or Outlook because it is unable to name resolve.

We do have 2 DC w/ DNS running on the LAN.

Thanks for an information.
 
is your vpn client picking up the correct DNS server IP settings? If so, can you ping those IP's?
 
I ran a ipconfig/all and it shows the dialup using the Proper DNS server on the LAN

I am able to ping servers and workstations on the dialup.
 
OK. How about opening an NSLOOKUP session and trying to resolve some domain names? Does that work? Are you allowing DNS traffic (port 53 tcp/udp) thru the PIX?
 
From the LAN connection, this works perfect.

On the VPN connection, it comes back with the right IP numbers, but then has this.

*** DC01.royal.local can't find im01: Non-existent domain


As for the port, I am unsure. I will check on that
 
OK. What do you mean by "it comes back with the right IP numbers"? Do you mean when you start NSLOOKUP, it properly identifies the DNS server and give you a > prompt without any errors?
 
That is correct.

When I run a ipconfig /all, it will list my network DNS servers with the dialup network adapter.

 
hmm...then you just seem to have a failure locating or retrieving resource records, which definitely explains why you can't map drives or connect outlook. how about setting up logging on the PIX temporarily and sending a couple of queries through? In the meantime, if you're able to ping the relevant IP's, try using the local hosts file until you can figure out what's going on.
 
FYI... The post 53 UDP/TCP are both open

 
I have created the HOSTS file and placed in the system

This does work, is this the only solution?
 
well, it shouldn't be. the real solution involves finding out why you can't get name resolution from your DNS server...that's why i suggested the logging, or even packet sniffing, just to see where the failure is.
 
Have you tried getting the VPN user to run a Sync (Explorer>Tools>Syncronize). Worth a try.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top