[Freeipa-users] Re: Master -> replica through NAT?

2017-06-21 Thread Kat via FreeIPA-users
AHA LOCATIONS!!! Unless I am way off here - what I need to do is set the replica to NOT be DNS, but then standup another replica inside the same "location" with DNS and make sure the hosts in that location talk to it, and in the inside location, they talk to the other host. The point is,

[Freeipa-users] Re: Master -> replica through NAT?

2017-06-21 Thread Kat via FreeIPA-users
I think I see the problem - I am really trying to do Split DNS in this configuration. So I need to keep DNS working, but somehow there must be a way to have the replica on the outside of the firewall understand that there is split DNS involved. I am having an issue figuring out if FreeIPA DNS

[Freeipa-users] Re: Master -> replica through NAT?

2017-06-21 Thread Przemysław Orzechowski via FreeIPA-users
Hi You are trying to setaup a replica behind a NAT? I will try to picture it bellow MASTER| - | NAT-DEVICE |- |REPLICA| 10.x.x.x | - |10.x.x.y 172.16.x.y|- |172.16.x.x | Is this setup somewhat correct? This makes fiew problems 1 UDP is stateles so You would ne

[Freeipa-users] Re: Master -> replica through NAT?

2017-06-21 Thread John Keates via FreeIPA-users
What you want is not possible because DNS resolves to one IP, not to a NAT’ed IP. Doing this differently is very hacky and totally unsupported. One host, one IP, one DNS record. NAT doesn’t belong in this type of networking. If you really wanted to shoot yourself in the foot, you can use Unbound

[Freeipa-users] Re: Master -> replica through NAT?

2017-06-21 Thread Kat via FreeIPA-users
Nothing? No suggestions? Is it not possible to support DNS through a NAT? -K On 6/20/17 1:32 PM, Kat wrote: Here is an odd problem (I think). I am using IPA in one environment, and want to set up a replica in another environment through natted connections. I can setup the client to the NAT