nslookup

  • Thread starter Kevin D. Goodknecht [MVP]
  • Start date
K

Kevin D. Goodknecht [MVP]

In
William Luiz de Souza said:
I'm trying to add a computer to my domain, however I have a firewall
between the computer and the DC (they are in separated networks).
I've opened the ports according with this article 179442. I can
connect using telnet in 53 port, however I can resolve names.
NSLOOKUP DOES NOT WORK.

Can anyone help me?

You should set up a VPN link between the client and the DC rather than
opening all the ports needed for domain membership.
 
W

William Luiz de Souza

I'm trying to add a computer to my domain, however I have a firewall between
the computer and the DC (they are in separated networks). I've opened the
ports according with this article 179442. I can connect using telnet in 53
port, however I can resolve names. NSLOOKUP DOES NOT WORK.

Can anyone help me?
 
M

Michael Johnston [MSFT]

Port 53 is only part of this. Telnet also only tests tcp port 53. Most dns queries will use udp port 53. If NSLOOKUP doesn't work,
then something is preventing udp 53 from getting through. Is the firewall natting between the client and the server? If so, this will
never work. You will need to create a VPN tunnel through the firewall and then add the client to the domain. This is probably a
better solution anyway as you don't want to open up the firewall as this will expose you unnecessarily.
Thank you,
Mike Johnston
Microsoft Network Support
--

This posting is provided "AS IS" with no warranties, and confers no rights. Use of included script samples are subject to the
terms specified at
http://www.microsoft.com/info/cpyright.htm

Note: For the benefit of the community-at-large, all responses to this message are best directed to the newsgroup/thread from
which they originated.
 
W

William Luiz de Souza

Can I set up the VPN only to add the machine to domain? Persistent VPN
connection is a bad option to me.

Michael Johnston said:
Port 53 is only part of this. Telnet also only tests tcp port 53. Most
dns queries will use udp port 53. If NSLOOKUP doesn't work,
then something is preventing udp 53 from getting through. Is the firewall
natting between the client and the server? If so, this will
never work. You will need to create a VPN tunnel through the firewall and
then add the client to the domain. This is probably a
better solution anyway as you don't want to open up the firewall as this will expose you unnecessarily.
Thank you,
Mike Johnston
Microsoft Network Support
rights. Use of included script samples are subject to the
terms specified at
http://www.microsoft.com/info/cpyright.htm

Note: For the benefit of the community-at-large, all responses to this
message are best directed to the newsgroup/thread from
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top