Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

join windows domain over vpn ipsec tunnel

Greetings, I have an ipsec interface mode vpn tunnel between a fortinet 60' s and 1000a. Everything works great except one thing. A pc at a remote site cannot join a windows domain. Once the pc is joined everything else works, including domain login and share access. I tried turning off all protection profiles on both ends and that did not work. Services on both ends are set to " ALL" Also, this is a non active directory domain and remote pc' s use an lmhosts file. This worked great when we were on frame/relay. But since the change to internet/vpn this has been an issue. So if I join a pc over the tunnel, no luck. Move the same pc to local net and it works. I' ve been fighting this one for a while so any help would be very much appreciated!!! Thanks!
5 REPLIES 5
rwpatterson
Valued Contributor III

Enable NetBIOS over TCP/IP in the advanced section of TCP/IP. Also don' t use NetBEUI. It isn' t routable. If you' ve done that already, then I have no idea.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Thanks, I thought we might have something there but I just tried with with netbios over tcp and still no.
rwpatterson
Valued Contributor III

You need to do that on both the server and the work stations. If you still have NT4 servers there may be a bit more involved.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Thanks, I will give this a try!
FortiRack_Eric
New Contributor III

You don' t need to enable NetBios. The only thing is that you need to point your DNS server to the DNS server of the network you want to join. Cheers, Eric

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors