通过点到点VPN加入Azure中域控制器VM的AD失败,提示DNS问题但诊断显示正常
我最近碰到个挺头疼的问题:用Azure Gateway VPN搭配Azure VPN Client建立了点到点连接后,想把Windows Server 2019的机器加入Azure上的AD域fcp.local,结果失败了——系统提示DNS服务器没响应,但我做的各项诊断测试却都显示DNS服务明明是正常运行的。
错误详情
The following error occurred when DNS was queried for the service
location (SRV) resource record used to locate an Active Directory
Domain Controller (AD DC) for domain "fcp.local":The error was: "This operation returned because the timeout period
expired." (error code 0x000005B4 ERROR_TIMEOUT)The query was for the SRV record for _ldap._tcp.dc._msdcs.fcp.local
The DNS servers used by this computer for name resolution are not
responding. This computer is configured to use DNS servers with the
following IP addresses:
10.0.0.4Verify that this computer is connected to the network, that these are
the correct DNS server IP addresses, and that at least one of the DNS
servers is running.
诊断测试结果
我跑了几个诊断命令,结果全都是正常的:
1. 查询SRV记录(nslookup)
nslookup -type=SRV _ldap._tcp.dc._msdcs.fcp.local Server: fcp-ad.internal.cloudapp.net Address: 10.0.0.4 _ldap._tcp.dc._msdcs.fcp.local SRV service location: priority = 0 weight = 100 port = 389 svr hostname = fcp-ad.fcp.local fcp-ad.fcp.local internet address = 10.0.0.4
2. 测试LDAP端口(389)连通性
Test-NetConnection 10.0.0.4 -p 389 ComputerName : 10.0.0.4 RemoteAddress : 10.0.0.4 RemotePort : 389 InterfaceAlias : FCP-AD-vnet SourceAddress : 10.1.0.130 TcpTestSucceeded : True
3. 测试DNS端口(53)连通性
Test-NetConnection 10.0.0.4 -p 53 ComputerName : 10.0.0.4 RemoteAddress : 10.0.0.4 RemotePort : 53 InterfaceAlias : FCP-AD-vnet SourceAddress : 10.1.0.130 TcpTestSucceeded : True
环境信息
- 客户端和域控制器均为Windows Server 2019系统
- 使用Azure Gateway VPN + Azure VPN Client构建点到点VPN连接
- 网络配置涉及NSG安全规则
备注:内容来源于stack exchange,提问作者Automate

