cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
477
Views
0
Helpful
4
Replies

Site to Site VPN

nofori1382
Level 1
Level 1

I have created a site to site vpn tunnel between the main office and one of our branch office. At the branch office I have configured the ASA 5505 to serve as a dhcp server. Clients at the branch office are able to ping and rdp into the the dns server and the dhcp server at the main office but when am trying to add a computer to the domain from the branch office its unable to do that.

Now I am wondering instead of configuring the ASA at the branch office as the dhcp server, I want to configure it to be a relay agent to receive IP address from the main office DHCP Server so I can add the computers to the domain.

 

Please help here if you have any step by step configuration method.

4 Replies 4

Here is an example of a DHCP-relay on the ASA:

dhcprelay server 10.10.10.10 outside
dhcprelay enable inside
dhcprelay setroute inside

More con be found in the config-Guide:

http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/basic_dhcp.html#wp1226581

http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/asdm70/configuration_guide/asdm_70_config/basic_dhcp.html#pgfId-1249374

Karsten has provided good information about DHCP relay on ASA. But I wonder if using a different DHCP server will really solve the problem. What is preventing joining the domain now?  Is it that the domain controller does not recognize the subnet as valid? Is there some other issue that prevents joining the domain?  It seems to me that you need to identify the current problem. Then you can figure whether a different DHCP server will resolve the problem. 

 

HTH

 

Rick

HTH

Rick

Thank you Richard. I am able to ping the domain controller as well as remote desktop into the server but when I try joining it to the domain I am unable to do so. If I join the computer to the domain from the head office and send it to the branch office I am able to authenticate perfectly.

 

For now I feel its a Microsoft issue and I am going to contact them for help. I will let the community know what the out come will be.

Hello, nofori1382.

Maybe you have the same problem as me before. Try look at this: http://windowsitpro.com/networking/single-label-domain-dns-resolution