I have this configuration at home (for testing)
Modem -> Broadband Router -> ISA server -> DC and others
The ISA has 2 interfaces, one of them connected to the router network (192.168.x.x) the other connected to the intranet (172.20.x.x). Everything is working fine in terms of connectivity between both and in access to all allowed protocols from the workstations in the intranet.
Both the DC and the ISA server are Domain Controllers,
each of its own forest, the ISA is a stand alone server, has DNS and DNS has only its own IP, no other records. The DC has the records relative to the other machines on the internal network.
Problem: When I define the primary zone in the DC domain as a secondary zone in the ISA (not that I SHOULD... just for experimenting purposes) I manage to transfer it and everything works fine.
When I do the opposite, that is, when I define the primary zone of the ISA server as a secondary zone on the DC I cannot make the transfer
Note: I allow zone tranfers for any server, and still doesn't works in one direction.
IN ISA I allowed all protocols related to DNS (Zone transfer, Query, etc...) and still it doesen't works.
on the DC when I ping the internal zone name, the DC responds (something like DC.intranet.local) BUT I cannot ping the other zone not even in the ISA (say, ISA.dmz.local)
Any suggestions would be greatly appreciated
Modem -> Broadband Router -> ISA server -> DC and others
The ISA has 2 interfaces, one of them connected to the router network (192.168.x.x) the other connected to the intranet (172.20.x.x). Everything is working fine in terms of connectivity between both and in access to all allowed protocols from the workstations in the intranet.
Both the DC and the ISA server are Domain Controllers,
each of its own forest, the ISA is a stand alone server, has DNS and DNS has only its own IP, no other records. The DC has the records relative to the other machines on the internal network.
Problem: When I define the primary zone in the DC domain as a secondary zone in the ISA (not that I SHOULD... just for experimenting purposes) I manage to transfer it and everything works fine.
When I do the opposite, that is, when I define the primary zone of the ISA server as a secondary zone on the DC I cannot make the transfer
Note: I allow zone tranfers for any server, and still doesn't works in one direction.
IN ISA I allowed all protocols related to DNS (Zone transfer, Query, etc...) and still it doesen't works.
on the DC when I ping the internal zone name, the DC responds (something like DC.intranet.local) BUT I cannot ping the other zone not even in the ISA (say, ISA.dmz.local)
Any suggestions would be greatly appreciated