DirectAccess 2012 Help (DNS related)

Soldato
Joined
4 Jan 2004
Posts
7,728
Location
Nottingham
Hey Guys

Been trying to configure DirectAccess but have run into a few issues with DNS. It appears that my test client can connect but I can only ping the IPv6 representations of IPv4 addresses on the network. I literally can't do anything else.

Current setup:

Server 2012 R2 with 2 NIC's. NIC1 connected to DMZ which goes out to the net through our firewall, NIC2 connected to internal LAN. NIC1 is configured with an IPv4 address, subnet and default gateway but no DNS servers. NIC2 is configured with an IPv4 address, subnet and internal DNS servers, no default gateway is configured. NIC2 is also set as the first NIC in the list of NIC's to use. The client is running 8.1 Enterprise.

Everything is green on the DirectAccess dashboard bar DNS which seems to constantly complain no matter what I change with regards to DNS.

Under Remote Access Setup in the DNS list our external hostname is listed along with our internal CA (these were both pre-populated based on earlier settings) and also <Any Suffix> which defaults to pointing to the IP of the DirectAccess server (even though it isn't a DNS server), I presume this is for DNS64?). If I accept all of this and apply the config the dashboard complains the DNS server is not responding, but shows the IPv6 address (checking the config again I see the IPv4 address for <Any Suffix> changes to this IPv6 address).

If I add our internal DNS servers into the Remote Access Setup DNS list and publish the config, I still get a DNS error but this time it lists all the IPv6 representations of the IPv4 addresses of the internal DNS servers plus the DirectAccess server.

I can run lookup commands from the DirectAccess server with no problems so I'm completely at a loss with this one? Even the Remote Access Setup DNS list can validate the IPv4 address so I don't know why once published it's throwing up the DNS errors?

Can anyone shed some light on this or even offer advise on their DA setup?
 
DA is purely IPv6 so the actual tunnel between the client and server be IPv6. Both client and server have IPv6 addresses that aren't link local addresses
 
Back
Top Bottom