Windows server AD trough IPSec VPN

Aballo
Aballo Posts: 13  Freshman Member
First Comment First Anniversary

Hello,

We've got 2 sites linked trough an IPSec VPN. We used USG Flex at each side.

In the simpliest way, what can i do for users to be able to login on the domain, whatever site it is on?

Many thank's

L.

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,635  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Aballo,

    I assume you just need the client to login AD domain, not the firewall needs to join your AD and authentication. Below is the solution based on what I assume.

    Main concept:

    Your client need to know what IP is you domain.

    You can set your AD DNS server IP as DNS server for your clients. Or set a domain zone forwarder so the clients can resolve the domain and connect to your AD. Below is the example for domain zone forwarder.

    image.png

    Since your firewalls are connected by VPN, the firewall will route the traffic to AD via VPN tunnel and your client can reach the AD.

    Zyxel Melen


  • Aballo
    Aballo Posts: 13  Freshman Member
    First Comment First Anniversary

    Hello,

    Many thank's for your answers.

    The domain controller is behind on USG (main site) and all users on this side can already logon.

    The other side (the "agency") is new.

    I thought IPSec allowed these ports (53, 88, 389, and 445) by default…

    Regards

    L.

  • Aballo
    Aballo Posts: 13  Freshman Member
    First Comment First Anniversary

    Hello Melen,

    I add the record in the Domain Zone Forwarder:

    image.png

    I can't still not ping srv-ad by the name, only by its IP.

    The second line is for DNS provider (added by the router itself)

    Thank's for your help.

    Lilian

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,635  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Aballo

    I checked with our engineer and found that Windows AD can't authenticate the remote site clients since they are under the different subnet from the AD. This is the Windows AD's limitation and you need to have a RODC in the remote site/site B for authentication.

    Zyxel Melen


  • Aballo
    Aballo Posts: 13  Freshman Member
    First Comment First Anniversary

    Hello,

    We just add Active directory server IP in the remote site Zyxel DHCP (1st place, Zyxel in 2nd, 1.1.1.1 in 3rd)

    We were able to add PC in the domain and we were able to do exactly the same as on the main site…

    Not a Windows limitation…

    Regards.

    L.

  • valerio_vanni
    valerio_vanni Posts: 157  Master Member
    5 Answers First Comment Friend Collector Third Anniversary
    edited 11:25AM

    1st place is correct

    2nd is correct, as long as in Zyxel you have conditional forwarder

    3rd is wrong: on a pc joined to a domain, there shouldn't be set any DNS server that doesn't contain domain zones (and 1.1.1.1 doesn't for sure)