In
ping said:
Hi,
I will try to change the forwarder to the Router DNS Proxy. But
strange thing is that client is able to resolve to the correct ip
when i check with nslookup. No firewall blocking. But it just won't
connect. There are some mis-configuration of IP addressing, which I
think may be the cause too. Currently PIX firewall sits between
Router and internal network. The external interface of PIX is
assigned 192.168.1.0/24, and the internal interface DHCP is retrieved
from pix(172.16.0.0/16).
Any idea?
Honestly, with all respect to Frankster, I can't see how changing the
forwarder to the router will resolve internal client names. I wo uld leave
forwarding to the ISP to eliminate the extra query hop using the router will
cause in the resolution process, that is as long as you are allowing query
trafic thru to the DNS server.
As for internal resolution, you are saying your internal clients are
receiving a DHCP address from the PIX box? When the one client pings the
other client by name, what name gets resolved?
Why not use Windows DHCP? It works hand in hand with Microsoft DNS Dynamic
Updates (Option 080), along with using Secure Only Updates, along with the
numerous other Options available that PIX doesn't support.
If you can *please* post an ipconfig /all of your DC, one from the client
that is working, as well as one from the client that is not working. This
will help us get a better idea of your configuration on your clients and
what it's getting from the PIX DHCP, and to see if the DC matches, the
Primary DNS Suffix, Connection Spefici Suffix, and other information in the
ipconfig /all results.
--
Ace
This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.
If you are having difficulty in reading or finding responses to your post,
instead of the website you are using, I would suggest to use OEx (Outlook
Express or any other newsreader of your choosing), and configure a newsgroup
account, pointing to news.microsoft.com. This is a direct link into the
Microsoft Public Newsgroups, and it is FREE and DOES NOT require a Usenet
account with your ISP. With OEx , you can easily find your post and watch &
track threads, sort by date, poster's name, watched threads or subject.
Not sure how? It's easy and you'll enjoy it
How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164
Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Windows Server Directory Services
Microsoft Certified Trainer
Assimilation Imminent. Resistance is Futile.
Infinite Diversities in Infinite Combinations.
=================================