IPv6 DNS Questions with DirectAccess

Hey,
I'm hoping someone can answer some fundamental questions that I am having around DirectAccess for a customer that I'm working with.  We are putting in Direct Access with a more complicated scenario, but there are some fundamental questions about IPv6
that I cannot quite get answered.  We have the tunnel established over IPHTTPS, however, I am not able to resolve internal resources.
We have a red x next to the DNS Monitoring in the Operations Console.  DNS64 is green. 
1) I know that you don't need IPv6 on our internal servers to use DirectAccess.  However, in this situation they have IPv6 unbound from the NICs on all the servers except for the DA server (and the Windows 7 clients).
2) Brings me to the DNS question.  Internal DNS servers do not have IPv6 bound to the NIC and they do not register AAAA records in DNS.  Does that pose any issues with the NRPT?
Thanks for your help!
Bob

Hello,
After talking with Microsoft support here was the actual issue.
First, the issue around the DNS going red:
Set-DAClientDnsConfiguration -DnsSuffix '.internal.company.com' -DnsIPAddress @('ipv6 address of the DA server') -Verbose -ComputerName 'DAServer.internal.company.com’
That fixed that issue, however, we were still having issues with the routing to internal servers. 
We did the following further troubleshooting with Microsoft,
We checked if client was able to get to the IPv6 address of the server – failed
Checked if the client was able to get to the IPHTTPS address of the server – worked
On the DA server itself, we were unable to ping the IPv6 address of the server      (fd58:c2f1:4a56:5555::1). We tried pinging this IP address using the IPHTTPS address on the DA server and that failed
as well.
Since we were unable to get to the IP address on the server itself, we just removed and re-added      the IPv6 address of the server, on the Internal NIC, and we were then able to ping the server’s IPv6
address.
But, clients were still unable to connect.
So we realized that the forwarding must have not been enabled on the NICs.
We checked for Forwarding being enabled on the IPHTTPS and Internal interface of the DA server
and found that this was not enabled on the Internal interface.
Once we enabled this, client machine was then able to connect to internal resources over Direct Access.
To enable forwarding on the NIC we ran the below command,
netsh int ipv6 set int <interface_id> forwarding=enabled
Thanks,
Bob

Similar Messages

  • External DNS name with Transversal Firewall

    Have have one server RedHat 4.0 with SGD 4.1 with this names in diferrent
    IP:
    server1.company.com (peer dns name)-> IP1
    server2.company.com (Bind in another IP2 with external dns name and
    firewall forewarding in port 443, the customca is server2.company.com)
    Question:
    Can I configure SGD 4.1 to respond with two external dns name with
    firewall forewarding ?
    https://server1.company.com/tarantella
    https://server1.company.com/sgd
    https://server2.company.com/tarantella
    https://server2.company.com/sgd
    The client user can works with two names ?
    Client prefer to choose access with server1 or server2.
    Best Regard�s
    Marcelo Moreira Martins
    [email protected]
    Technical Consultant - Tarantella Systems Engineer
    SE- Systems Engineer - M3 System Integrator.
    Sun Microsystems do Brasil - Authorized Campus Dealer
    +55-51-3333-2644 - Office
    +55-51-9962-6536 - Mobile Phone
    Visit the EduSoft web site: http://www.sun.com/edu/edusoft/

    Marcelo,
    It is possible to have more that one external DNS name. Please see:
    Array Manager - Array - <server> - General - Properties
    In here you can map ip-addresses (of clients) to dns names.
    However, a user will not be able to dynamically choose which server to
    access - the
    server will be selected on the first matching IP pattern.
    Regards
    "Marcelo M. Martins" <[email protected]> wrote in message
    news:dhu1c0$u5m$[email protected]..
    Have have one server RedHat 4.0 with SGD 4.1 with this names in diferrent
    IP:
    server1.company.com (peer dns name)-> IP1
    server2.company.com (Bind in another IP2 with external dns name and
    firewall forewarding in port 443, the customca is server2.company.com)
    Question:
    Can I configure SGD 4.1 to respond with two external dns name with
    firewall forewarding ?
    https://server1.company.com/tarantella
    https://server1.company.com/sgd
    https://server2.company.com/tarantella
    https://server2.company.com/sgd
    The client user can works with two names ?
    Client prefer to choose access with server1 or server2.
    Best Regard�s
    Marcelo Moreira Martins
    [email protected]
    Technical Consultant - Tarantella Systems Engineer
    SE- Systems Engineer - M3 System Integrator.
    Sun Microsystems do Brasil - Authorized Campus Dealer
    +55-51-3333-2644 - Office
    +55-51-9962-6536 - Mobile Phone
    Visit the EduSoft web site: http://www.sun.com/edu/edusoft/

  • Setting static IPv6 DNS on EA2700/smartwifi

    I have OpenDNS and Google set for IPv4. Is it possible to add static IPv6 DNS on the router? Not sure because of the format of "IP" address for IPv6 DNS. I have IPv6 and IPv4 DNS set on my end devices.

    External DNS servers won't work with Smart Wifi firmware unfortunately.
    Please remember to Kudo those that help you.
    Linksys
    Communities Technical Support

  • How do I reset my apple id security question with out a rescue email

    How do I reset my apple id security question with out a rescue email?

    You need to ask Apple to reset your security questions; ways of contacting them include clicking here and picking a method for your country, phoning AppleCare and asking for the Account Security team, and filling out and submitting this form.
    They wouldn't be security questions if they could be bypassed without Apple verifying your identity.
    (101013)

  • I am having a DNS problem with my computer. My laptop connects to the internet and my skype works normally but when i try to surf the web it says "DNS Look up failed".

    MY PROBLEM
    I am having a DNS problem with my laptop. It connects normally to th e wifi internet but when i try to surf the net it says "DNS Look up failed"
    This problem only occurs when with the internet at my house. whenever i connect elsewhere my computer works normally. My ipod, iphone, tablet and other friends computers work normally when they are connected to my internet. i use dmy neigbours nework a couple of times from my house and it wrks normally.
    Also when i turn my laptop on or off i can browse for a few minutes or seconds before it fails again. My skype works like there is no problem
    WHAT I HAVE TRIED TO RESOLVE IT
    I have tried changing the DNS, i used open DNS and google free DNS and it still didnt make a difference.
    I have rebooted router many times, nothing
    I have changed my home router, nothing
    I backed up my computer, resored everything it to factory setting and put everything back on; still nothing
    Run a diagnostics at 'Best buy' and they say nothing is wrong; but i know there is something wrong with the DNS
    I have tried different "sudo" type of codes on my comupter from stuff i got online and nothign has proved fruitful yet.
    i tried using safari, Google chrome and firefox, all not loading
    WHAT DO I DO TO FIX THIS?

    You are correct.  Syncing should transfer any purchased media, including videos, from your device to your iTunes library provided your computer is authorized for the Apple ID used to make these purchases.  You mentioned that you have uninstalled iTunes before, but if you didn't follow this guide exactly, uninstalling iTunes and all of its components in the order specified, it may not have been successful so you should try again:  Windows XP or Windows Vista/7.

  • Basic questions with respect to ABAP WebDynpro Application

    Hi All,
    I have two basic questions with respect to an ABAP WebDynpro application :
    a) If an ABAP WebDynpro application has been developed, how could it be made available to the end user?
    b) Can an ABAP WebDynpro application be developed in ECC or is it only applicable for version 4.6c?
    Thanks & Regards,
    Sushanth Hulkod

    Sushanth Hulkod wrote:
    > a) If an ABAP WebDynpro application has been developed, how could it be made available to the end user?
    >
    > b) Can an ABAP WebDynpro application be developed in ECC or is it only applicable for version 4.6c?
    a) If an ABAP WebDynpro application has been developed, how could it be made available to the end user?
    Answer - By providing direct link of the WD application created in SE80, creating iView for webdynpro abap application in the portal environment and  NWBC environment
    b) Can an ABAP WebDynpro application be developed in ECC or is it only applicable for version 4.6c?
    Answer - Yes it can be developed in ECC. Webdynpro ABAP is introduced in NW 2004s (SAP NetWeaver 7.0 or ECC 6.0)
    Thanks,
    Chandra

  • I cannot purchase anything at the itunes store because I am being ask for my security questions, but I don't remember them. How do you change you security questions with out knowing them?

    I cannot purchase anything at the itunes store because I am being ask for my security questions, but I don't remember the answers. I tried going to appleied.apple.com but I won't allow me to change my security answerswithout answering the original questions. How do you change you security questions with out knowing them? I need help.

    Welcome to the Apple Community.
    Start here, and reset your security questions, you will receive an email to your rescue address, use the link in the email and reset your security questions.
    If that doesn't help or you don't have a rescue address, you might try contacting Apple through iTunes Store Support

  • How do you resets your apple I'd security question with out calling apple

    How do you resets your apple I'd security question with out calling apple

    See Kappy's great User Tips.
    See my User Tip for some help: Some Solutions for Resetting Forgotten Security Questions: Apple Support Communities https://discussions.apple.com/docs/DOC-4551
    Rescue email address and how to reset Apple ID security questions
    http://support.apple.com/kb/HT5312
    Send Apple an email request for help at: Apple - Support - iTunes Store - Contact Us http://www.apple.com/emea/support/itunes/contact.html
    Call Apple Support in your country: Customer Service: Contacting Apple for support and service http://support.apple.com/kb/HE57
     Cheers, Tom

  • I need some more interview question with answer on modeling,reporting.

    i need some more interview question with answer on modeling,reporting.

    Hi,
    You may find tons of topic about interview question. Please try to search forums before opening a post next time.Take a look at the link below.
    https://www.sdn.sap.com/irj/sdn/advancedsearch?cat=sdn_all&query=bwinterviewquestions&adv=true&adv_sdn_all_sdn_author_name=
    Regards,
    ®

  • DNS forwarder with 2 real DNS servers, querying them simultaneously

    DNS forwarder with >2 real DNS servers, querying them simultaneously and ignoring "server can't find" errors
    Hi. When I connect to VPN, my normal DNS isnt queried, and DNS given by VPN answers: "server can't find"
    An extract from 'man resolv.conf'
    If there are multiple servers, the resolver library queries them in the  order  listed.
    I need another logic. All servers should be queried at the same time, and the soonest positive reply should be used.
    The algorithm  used  is to try a name server, and if the query times out, try the next, until out of name servers, then repeat trying all  the  name  servers  until  a  maximum number of etries are made.
    So, if I get "server can't find" error, the next DNS server not queried. I want the DNS forwarder to ignore such answers and wait for replies from other servers.
    What software can do this? Maybe dnsmasq? I plan to add 'nameserver 127.0.0.1' to the top of my resolv.conf and configure my scripts to add other nameservers below.

    All servers should be queried at the same time
    --all-servers
    dnsmasq: ignoring nameserver 127.0.0.1 - local interface
    good.
    How to tell dnsmasq to completely disable dhcp? List all interfaces like this?
    no-dhcp-interface=eth0
    no-dhcp-interface=tun0
    no-dhcp-interface=vboxnet0
    no-dhcp-interface=wlan0

  • HT201303 Have forgotten my apple I'd security questions with respective answers

    Have forgotten my apple I'd security questions with respective answers

    Forgotten security questions - https://discussions.apple.com/message/18402551
    More involved forgotten question issues - https://discussions.apple.com/thread/3961813
    Frequently asked questions about Apple ID - http://support.apple.com/kb/HE37

  • DNS Issues with Hyper-V 2012 R2 VDI Pooled Desktop Deployment

    Good afternoon all!
    We are running a POC VDI deployment on a Nutanix system, and I am having a DNS issue. I would appreciate some help trying to figure this out. Two situations that are causing issues that I can see:
    1. VMs go into a saved state if not being used: This in itself is not an issue, and I see it as a way to save resources not being used; however, if a VM is saved for a few days, the DHCP address often gets reassigned. Now if users are connecting, and that
    saved VM with the stale address is called to wake up, the VM is not found.
    2. Recreating the pool after updating the golden image: This is the bigger issue. After a couple days of running smoothly, I was asked by my pilot users to add Firefox. I installed it and recreated all the VMs in the pool. When this happened, they all got
    new IPs, but the old DNS records were not updated. This made the broker unable to find a single VM in the pool. I could not ping a single one.
    Has anybody else run into these DNS issues with a VDI deployment? If so, what did you do to resolve it? If not, have any ideas on what is going on here?
    Thank you in advance!
    Eric

    Hi Eric,
    As per my research, I can say that the default behavior. When we will recreate the VM it will change the IP address dynamically. But from your description it seems the DNS record is not getting update and due to that you can’t find your VM with hostname or
    IP. But for this you can set one option under DNS server with which DNS record can update the new IP address. The option you need to set is “Dynamic updates>Nonsecure and Secure” under general properties in sites. You can check below snap.
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Trying to teach self Java-question with arrays

    I have a question with arrays. I have a simple inventory program that I am writing(very simple). I have declared and created my array. Is this the time I should build a new class outside of my main in order to hold my array? I am still trying to sort through classes and when to create them. My thought is that because it is a hierarchy I should have a new class. For example, Albums is at the top and then there are specific types of albums, like TributeAlbum, PremiereAlbum, etc. Do I need a class for each of these? When I create the class, do I use the same name as the array?
    More info, just in case: My original class is AlbumInventory. I have created an array to hold 25 TributeAlbums which has 4 instance variables.
    Question 2: Why can I not refer to an album variable like TributeAlbums[0].itemNumber?
    Thanks in advance for your input.
    Denise

    I have a question with arrays. Okay.
    I have a simple
    inventory program that I am writing(very simple). I
    have declared and created my array. Is this the time
    I should build a new class outside of my main in
    order to hold my array? In an OO language classes are usually a good idea.
    I am still trying to sort
    through classes and when to create them. My thought
    is that because it is a hierarchy I should have a new
    class.This sounds a bit confused. You should have a new class when it is appropriate to do so.
    For example, Albums is at the top and then
    there are specific types of albums, like
    TributeAlbum, PremiereAlbum, etc. Do I need a class
    for each of these? Not sure. Why is the type not an attribute of the Album class? This (attribute) seems at first glance to be the way to do it.
    When I create the class, do I use
    the same name as the array?
    ? I am going to say no but I'm not following what you are really asking here.
    More info, just in case: My original class is
    AlbumInventory. I have created an array to hold 25
    TributeAlbums which has 4 instance variables.
    Can you please post some of your actual formatted code? It would also be helpful to know what the attributes for an Album are as you have them.

  • Upgrade from 2012 to 2012 R2 with DirectAccess

    I have read a few posts here and there about doing an in-place upgrade of 2012 to 2012 R2 with DirectAccess.  I'm wondering what people in the forum have to say about doing an in-place upgrade.  I realize that there are no new features but I would
    like to make sure most of our servers are 2012 R2 instead of 2012 since it is much friendlier.
    What I was hoping to do was just mount the 2012 R2 ISO and run setup.  I have done this with AD and it worked in my home lab but I have not tried DA hence me asking.
    Thank you,
    Kent

    I have read a few posts here and there about doing an in-place upgrade of 2012 to 2012 R2 with DirectAccess.  I'm wondering what people in the forum have to say about doing an in-place upgrade.  I realize that there are no new features but I would
    like to make sure most of our servers are 2012 R2 instead of 2012 since it is much friendlier.
    What I was hoping to do was just mount the 2012 R2 ISO and run setup.  I have done this with AD and it worked in my home lab but I have not tried DA hence me asking.
    Thank you,
    Kent

  • Dns issues with one domain (Resolved)

    i'm currently having dns issues with one domain, in that it won't resolve when I use bt's dns servers.
    The domain is owned by a friend in the US who runs his own server for irc, web, and I also have a server that is on his connection, and resolves fine from other machines on different networks, and also resolves fine when I set windows to use the opendns servers, but when it's set to either my routers ip (using bt's dns), or set to automatic (using bt's dns via the homehub), this one domain will not resolve.
    I'm pretty certain it's not a windows issue, as it's a clean install of windows 7 that I did yesterday. I've tried rebooting the homehub, and also flushing my dns on windows, but this has not solved the issue.
    As I say, it resolves fine on other networks, and also when I use the opendns servers, so I know it's definately a dns issue.
    Using bt's dns servers:
    C:\Users\admin>ping chatnsn.com
    Ping request could not find host chatnsn.com. Please check the name and try agai
    n.
    Using opendns:
    C:\Users\admin>ping chatnsn.com
    Pinging chatnsn.com [68.51.24.74] with 32 bytes of data:
    Request timed out.
    Request timed out.
    Request timed out.
    Request timed out.
    Ping statistics for 68.51.24.74:
        Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
    (The timeouts are normal...he has his router set to not respond to ping requests).
    Has anyone got any ideas on how to sort this out? Preferably without having to phone the helpdesk...lets just say i've done it in the past, and according to the poeple I spoke to in india, I knew nothing about my own systems, and it was a problem at my end...which was not the case, and I proved this several times.
    Edit: This issue appears to have resolved itself, and the domain is now resolving again using the homehub for dns resolution.

    Hi,
    When NSLOOKUP starts, before anything else, it checks the computer's network configuration to determine the IP address of the DNS server that the computer uses.
    Then it does a reverse DNS lookup on that IP address to determine the name of the DNS server.
    If reverse DNS for that IP address is not setup correctly, then NSLOOKUP cannot determine the name associated with the IP address.
    http://support.simpledns.com/kb/a90/nslookup-cant-find-server-name___-default-server-unknown.aspx
    Also refer to:
    How to fix NSLOOKUP Default Server: UnKnown?
    http://www.randika.info/2013/01/how-to-fix-nslookup-default-server.html
    Regards.
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

Maybe you are looking for

  • IPod touch won't connect to computer

    my parents bought me an IPod touch for Christmas and loaded all their music on it.   I opened it up last night, charged it and it worked! Wonderfully.   This morning there's an icon showing a power cord and the iTunes logo and my computer says it nee

  • ORA-01102: cannot mount database in EXCLUSIVE mode

    Hello, I am working with an Oracle VM Template: Oracle Application Server 10g Release 3 WebCenter (x86 32-bit). In this template exists an Oracle database (version: 10.2.0.3.0), I am trying to do something operation (ie create a new user, query a sys

  • Syncing contacts across devices

    Hi I'm having issues with trying to get one set of contacts to display across all my devices. Whereabouts do I create my master set of contacts and how do I then get that to be the same on my iPhone/laptop/iCloud/iPad? Currently after much frustratio

  • Bug in QoS?

    Recently upgraded by WRT610N to an E4200. I manually entered all of the configuration parameters and it came up just fine, but afterwards, I noticed that upstream performance was terrible. I ran a speed test, and I was getting ~ 1M of upstream bandwi

  • 0.07$ on itunes store and need to find any way to be 0.00$ to change the country

    I need to select credit card payment but i must change my country first and i have didn't spend my gift card first i can't ? so now i have just 0.07$ and noway i can spend that ?? i want any way to be 0.00$ so i can change the country and put credit