"Help me" <> wrote in message
news:C166EC45-806A-48DA-975A-...
> Help
>
> Using Server 2003 I have my AD GC in my main server. named server.x.local
> I also have a server call server2.local at a remote office
>
> Server - 192.168.0.1
> server2 192.168.254.1
>
> I have connected the servers via a VPN and replicated the AD from Server
> to
> Sever2.
>
> DNS has 2 zones x.local and remote
> x.local is controlled by server and I would like remote to be controlled
> by
> and be part of the AD information.
>
> If server2 is not connected to server via VPN AD can not be found. I did
> notice that in remote zone on server2 it does not have _msdcs, _sites,
> _tcp
> and _udc records which I think is the problem.
>
> Do I have my DNS setup correctly give that I have 2 ip zones and how do I
> resovle my issue of server2 not finding the AD when not connected to
> server.
Why do you have two zones? Which zone is the AD zone?
Assuming that both DCs are in the same domain, and assuming that x.local is
the AD DNS domain name, then you only really need the zone. In this case,
both DCs should be GCs for two reasons, 1) confines logon requests to a GC
at that location, and 2) it's a best practice with one domain.
Assuming if the remote DC is in a child zone called remote.x.local, then you
do need the two zones. In this case, you need a GC at both locations to
allow logons at that site instead of traversing the WAN link looking for a
GC, but a GC cannot be on an IM, which each domain has one, which means that
you must (should anyway) have two DCs per domain.
If the SRV records are not showing up (those records you mentioned), then it
may likely be because the DCs are not configured to the correct DNS servers,
and/or the zone(s) are in different replication scopes, which also would be
dependent on whether the two DCs are in the same domain or not.
To better assist you, we'll need additional information to diagnose the
issue. Please post:
1. Unedited ipconfig /all from both DCs.
2. Whether both DCs are in the same domain or is it a parent-child forest.
3 .The AD zone name(s) (whether one domain or two domains).
4. An ipconfig /all from a sample client from each location.
5. If both DCs are GCs.
6. Is the VPN tunnel up 24/7?
Thank you,
--
Ace
This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.
Please reply back to the newsgroup or forum for collaboration benefit among
responding engineers, and to help others benefit from your resolution.
Ace Fekay, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007, MCSE & MCSA
2003/2000, MCSA Messaging 2003
Microsoft Certified Trainer
For urgent issues, please contact Microsoft PSS directly. Please check
http://support.microsoft.com for regional support phone numbers.