Re: DNS question with VPN



Hi Walter,

Thank you very much for your reply.

> Are the two DNS servers on the same LAN, or is one perhaps on the outside?

The 2 DNS servers are on the same LAN "inside".

> :crypto isakmp client configuration group access
> : key Password_Here
> : dns 192.168.180.14
> : wins 192.168.180.14
>
> I notice you only specify one of the two DNS servers here?

Yes, that's the original VPN configuration, with the first DNS server,
I have not added the new, 2nd DNS server yet.

The first DNS server has not been modified, either.

> :Hosts listed below in the router config will respond with 67.x.x.x IP,
> :while hosts not listed here respond with 192.168.180.x IP address.
>
> :ip nat inside source static 192.168.180.106 67.x.x.8 extendable
>
> At a guess -- the other DNS server is "outside' and has been
> configured with the 67.x.x.* IPs. If so then you want to enable
> automatic DNS translation on the reply packets coming back from it.
> I do not know how you specify that under IOS; on the PIX, it would
> be a matter of adding a 'dns' keyword to the static command.

No, all the DNS servers are inside.
The host names exist only with LAN IP addresses (foo.domain.com =
192.168.180.x), they were never intended to be visible with a public IP
address.

Again, thank you for your kind reply.

Regards,
Art

.



Relevant Pages

  • Re: When I use DialUp and LAN at same time, I cannot access LAN.
    ... >>network is CHECKED. ... PING doesnt work as DNS servers are inaccessible. ... > Your computer's LAN IP address is in the 10.91.194.x subnet. ... > overrides the LAN default gateway, preventing access to the LAN's DNS ...
    (microsoft.public.windowsxp.network_web)
  • Re: Cant resolve server names once Im VPNed in
    ... assumptions as to where you DNS servers are. ... The DHCP server does not give out leases to the VPN clients. ... > setup for my LAN (the workstations on the LAN have the correct settings). ...
    (microsoft.public.windows.server.security)
  • Re: Question about sendmail...
    ... > Craig White wrote: ... >>my own DNS servers inside the LAN so that the name resolution is ... >>instead of a name which loops the connection outside of the trusted LAN. ...
    (Fedora)
  • Internet access
    ... Everyone in my LAN, started to have a problem browsing the internet. ... I have 2 internal DNS servers (domain controllers), ...
    (microsoft.public.windows.server.dns)
  • Terrible Web Surfing Speed
    ... I switched to SBC/Yahoo DSL a few months ago. ... My LAN hosts thus have manually set DNS servers. ... Win2k inside a VMware on this Linux box surfs normally. ...
    (comp.os.linux.networking)