Here is an odd problem (I think).

I am using IPA in one environment, and want to set up a replica in another environment through natted connections. I can setup the client to the NAT server, but here is the tricky part - IPA is also DNS. So if I try to bring the DNS setup over with --

ipa-replica-install --setup-dns --forwarder=10.x.x.x --setup-ca

It fails, because when it tries to lookup the master on the other side of the NAT FW, of course it resolves incorrectly. The first failure is conn-check, so even if I --skip-conncheck, it still fails since DNS will not resolve.


FreeIPA-users mailing list --
To unsubscribe send an email to

Reply via email to