Windows server AD trough IPSec VPN
Best Answers
- 
            1st place is correct 2nd is correct, as long as in Zyxel you have conditional forwarder 3rd is wrong: on a pc joined to a domain, there shouldn't be set any DNS server that doesn't contain domain zones (and 1.1.1.1 doesn't for sure) 1
- 
            Thank's for your precision… 0
All Replies
- 
            Hi @Aballo, I assume you just need the client to login AD domain, not the firewall needs to join your AD and authentication. Below is the solution based on what I assume. Main concept: Your client need to know what IP is you domain. You can set your AD DNS server IP as DNS server for your clients. Or set a domain zone forwarder so the clients can resolve the domain and connect to your AD. Below is the example for domain zone forwarder. Since your firewalls are connected by VPN, the firewall will route the traffic to AD via VPN tunnel and your client can reach the AD. Zyxel Melen0
- 
            Hello, Many thank's for your answers. The domain controller is behind on USG (main site) and all users on this side can already logon. The other side (the "agency") is new. I thought IPSec allowed these ports (53, 88, 389, and 445) by default… Regards L. 0
- 
            Hello Melen, I add the record in the Domain Zone Forwarder: I can't still not ping srv-ad by the name, only by its IP. The second line is for DNS provider (added by the router itself) Thank's for your help. Lilian 0
- 
            Hi @Aballo I checked with our engineer and found that Windows AD can't authenticate the remote site clients since they are under the different subnet from the AD. This is the Windows AD's limitation and you need to have a RODC in the remote site/site B for authentication. Zyxel Melen0
- 
            Hello, We just add Active directory server IP in the remote site Zyxel DHCP (1st place, Zyxel in 2nd, 1.1.1.1 in 3rd) We were able to add PC in the domain and we were able to do exactly the same as on the main site… Not a Windows limitation… Regards. L. 0
- 
            1st place is correct 2nd is correct, as long as in Zyxel you have conditional forwarder 3rd is wrong: on a pc joined to a domain, there shouldn't be set any DNS server that doesn't contain domain zones (and 1.1.1.1 doesn't for sure) 1
- 
            Thank's for your precision… 0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 199 Nebula Ideas
- 125 Nebula Status and Incidents
- 6.3K Security
- 492 USG FLEX H Series
- 322 Security Ideas
- 1.6K Switch
- 83 Switch Ideas
- 1.3K Wireless
- 47 Wireless Ideas
- 6.8K Consumer Product
- 285 Service & License
- 455 News and Release
- 89 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 95 Security Highlight

 Freshman Member
  Freshman Member 
          
         
 Master Member
  Master Member 
          
          
          Guru Member
  Guru Member 
          
          
          
         

 
                     
                     
                     
                    