通过VPN接入Azure对等网络时DNS解析失败问题
Alright, let's break down why you're hitting this name resolution problem with your Azure VPN setup. The core issue here is that your VPN-connected laptop isn't using your domain controller (My1stVM) as its DNS server—instead, it’s likely relying on Azure’s default DNS or your home network’s DNS, neither of which can resolve your internal Azure VM names/FQDNs. Here’s how to fix it step by step:
1. Verify Your VPN Client’s DNS Configuration
First, confirm what DNS server your laptop is using when connected to the VPN:
- Open Command Prompt on your home laptop and run:
ipconfig /all - Look for your VPN adapter (usually named something like "Azure VPN Connection") and check the "DNS Servers" field. If it doesn’t show the internal IP of My1stVM, that’s the root cause.
2. Update vNet2’s DNS Server Settings
Since your VPN gateway is attached to vNet2, you need to point vNet2 to your DC/DNS server (My1stVM) instead of Azure’s default DNS:
- Go to the Azure Portal, navigate to your Resource Group 2 and select vNet2.
- In the left-hand menu, click DNS servers under "Settings".
- Switch from "Default (Azure-provided)" to Custom, then enter the internal IP address of My1stVM.
- Save the configuration.
3. Validate vNet Peering DNS Forwarding
Your vNet1-vNet2 peering needs to allow traffic to flow between vNet2 (and VPN clients) and the DNS server in vNet1:
- In the Azure Portal, go to vNet2’s Peerings settings.
- Select the peering connection to vNet1, and confirm:
- "Allow virtual network access" is set to Yes for both directions.
- "Allow forwarded traffic" is enabled (this lets VPN clients send DNS queries to vNet1’s DNS server).
- If any of these are disabled, toggle them on and save.
4. Refresh VPN Connection and Test Resolution
After updating the above settings:
- Disconnect your VPN connection on your laptop, then reconnect it.
- Test name resolution with these commands:
nslookup My2ndVM nslookup My2ndVM.yourdomain.local # Replace with your actual domain suffix - If the queries return the correct internal IP of My2ndVM, you should now be able to RDP using the computer name/FQDN.
5. Bonus: Ensure DNS Records Are Registered
Double-check that My2ndVM has registered its record with My1stVM’s DNS server:
- RDP into My1stVM (using its internal IP), open DNS Manager.
- Navigate to your domain’s forward lookup zone and confirm there’s an A record for My2ndVM pointing to its internal IP.
- If the record is missing, you can either restart My2ndVM to trigger automatic registration, or manually add the record in DNS Manager.
内容的提问来源于stack exchange,提问作者Jeffrey

