I understand what you are saying, but I guess I've been lucky for 8 or
so years never having a problem (at least reported) with this set up.

Ralph Smith


 


-----Original Message-----
From: Ben Scott [mailto:[email protected]] 
Sent: Thursday, August 13, 2009 12:36 PM
To: NT System Admin Issues
Subject: Re: PC in domain across stable VPN tunnel?

  Be aware that having an ISP nameserver configured in addition to
internal nameservers can sometimes cause issues.

  The typical scenario is: AD domain name is not visible in the public
DNS.  One must query internal nameserver(s) to find it.  The internal
nameserver(s) are listed first in IP configuration, but some ISP
nameservers are also listed.

  The typical failure mode is: Client (AD member) queries internal
nameservers for AD domain name.  For some reason (e.g., VPN glitch),
no answer is received from the internal nameservers.  Client falls
back to the ISP nameservers.  ISP nameservers say "that domain does
not exist".  Client gets very confused, since it's just been told its
AD domain doesn't exist.  Various things on the client get farked
until reboot.

  This is especially irksome because things can work fine for months,
then suddenly half the PCs will act funny until rebooted.  Lather,
rinse, repeat.

  I'm not saying "never do this", but one should be aware of the
potential failure mode.

-- Ben

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~
Confidentiality Notice: 

----------------------------------



This communication, including any attachments, may contain confidential 
information and is intended only for the individual or entity to whom it is 
addressed. Any review, dissemination, or copying of this communication by 
anyone other than the intended recipient is strictly prohibited. If you are not 
the intended recipient, please contact the sender by reply email, delete and 
destroy all copies of the original message.

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to