Community discussions

MikroTik App
 
dorijan
Member Candidate
Member Candidate
Topic Author
Posts: 244
Joined: Fri Jun 04, 2004 12:42 am
Location: Croatia

active direcotry and mt

Tue Apr 24, 2007 1:15 pm

Hi!

I have one mt and 5 ethernet cards in it with 5 networks that are 192.168.10.x/24 and so on. In one I have Windows active directory server and I would like users to be able to connect to domanin. I know this is routerd network, and broadcasts are not going throught, and I would like to avoid bridging networs (reason I have 5 network cards is to seperate different segments)...
Thank you...
 
User avatar
janisk
MikroTik Support
MikroTik Support
Posts: 6263
Joined: Tue Feb 14, 2006 9:46 am
Location: Riga, Latvia

Tue Apr 24, 2007 2:14 pm

you can add static dns entry that will point to your server, so when asked for name it will bee forwarded to correct address
 
dorijan
Member Candidate
Member Candidate
Topic Author
Posts: 244
Joined: Fri Jun 04, 2004 12:42 am
Location: Croatia

Tue Apr 24, 2007 3:29 pm

I tried but failed..
Do know where can I find how to do it?
This is what I did:
I got domaina that is called xxx
so I set manual dns entry for xxx.local and name.xxx.local and xxx all to point to ip adress of that router... but I cannot join
So I also tried this http://www.windowsnetworking.com/articl ... lmhst.html
but it did not work :(
 
User avatar
winxp2000
Member Candidate
Member Candidate
Posts: 113
Joined: Mon Jan 30, 2006 8:57 pm
Location: China
Contact:

Clear your question at first

Tue Apr 24, 2007 3:43 pm

in a Domain

do the any client can ping to MT lan ip?

if them work

them can use the MT network

you can build a PPPOE server in you intranet by MT.

then your client can access the network you wanted

========================

on the other side

if you want it cross the different subnet access the other ip

you should build the DNS server in you Domain not in MT

when the PC look for other IP, it will ask the DNS server for the destination
 
csickles
Forum Guru
Forum Guru
Posts: 1255
Joined: Fri May 28, 2004 8:46 pm
Location: Phoenix, AZ
Contact:

Tue Apr 24, 2007 6:49 pm

winxp2000 has the answer..

Things to do:

Use 2003 / 2000 server's DHCP and DNS servers (keep AD happy or else)

Set DHCP server to update DNS. (you also want the client to do this, but bootp devices wont)(Yes it does this)

Setup DHCP Proxys on the MT to forward the DHCP requests to NT servers.

USE NT as the domain time source.
USE MT as the timesource for the AD computer (use third party code to sync the global catalog server to the MT)
sync the MT to public NTP servers (Keep AD in timesync or it will fill your logs and boy will it...)

USE NT DHCP reservations for static address devices ie printers, secondary servers.

The above WILL save you alot of headachs... (I have had them for you !)

You will probalby want to use "SPLIT DNS" for any public DNS..

DO NOT... DO NOT... expose your internal DNS server for any reason to the outside world unless you want AD to get hacked / crashed...
(Your inside / outside address for published resources is probaly different anyway and would create a management issue)

This works for me.....
7 internal networks, 100 workstations, 20+ servers 20+ printers
2 remote sites. 7 wireless networks.
All in AD, All accessable by name..

I hope this helps.....

Who is online

Users browsing this forum: contik and 102 guests