<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>DCs and Network Address Translation</title><link>http://blogs.technet.com/b/ad/archive/2009/04/22/dcs-and-network-address-translation.aspx</link><description>A lot of planning goes into the features and capabilities of each Windows release. Over the years I&amp;rsquo;ve noticed that there is not a great deal of awareness out in the general public for just how much work and labor goes into a new version of Windows</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: DCs and Network Address Translation</title><link>http://blogs.technet.com/b/ad/archive/2009/04/22/dcs-and-network-address-translation.aspx#3544901</link><pubDate>Wed, 09 Jan 2013 12:29:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3544901</guid><dc:creator>Herbert Mauerer [MSFT]</dc:creator><description>&lt;p&gt;this blog does not warn sufficiently about DCs and NAT. The MS support statement is:&lt;/p&gt;
&lt;p&gt;978772	Description of support boundaries for Active Directory over NAT&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/kb/978772/EN-US"&gt;support.microsoft.com/.../EN-US&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Cheers&lt;/p&gt;
&lt;p&gt;Herbert Mauerer&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3544901" width="1" height="1"&gt;</description></item><item><title>re: DCs and Network Address Translation</title><link>http://blogs.technet.com/b/ad/archive/2009/04/22/dcs-and-network-address-translation.aspx#3326153</link><pubDate>Mon, 19 Apr 2010 14:16:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3326153</guid><dc:creator>dsammich</dc:creator><description>&lt;p&gt;Tim,&lt;/p&gt;
&lt;p&gt;I have been working with this for a couple of days. &amp;nbsp;I have site-to-site IPSEC tunnel built and can ping everything with no issues. &amp;nbsp;The DNS piece you menioned with reg hack doesn't seem to be working and would like more information on the key and how DNS publishes.&lt;/p&gt;
&lt;p&gt;I am in a hosted environment and have to hide networks all of the time to prevent subnet overlapping. &amp;nbsp;I am able to translate the addresses properly to the outside, essentially masking the &amp;quot;real&amp;quot; ip of the domain controllers.&lt;/p&gt;
&lt;p&gt;When I attempt to connect to a DC from a box that I am trying to run DCPROMO on, the existing DC (that has your reg hack), is returning the &amp;quot;real&amp;quot; IP, not the NAT'd IP?&lt;/p&gt;
&lt;p&gt;Thoughts?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3326153" width="1" height="1"&gt;</description></item><item><title>re: DCs and Network Address Translation</title><link>http://blogs.technet.com/b/ad/archive/2009/04/22/dcs-and-network-address-translation.aspx#3280606</link><pubDate>Fri, 11 Sep 2009 18:52:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3280606</guid><dc:creator>Tim Springston [MS]</dc:creator><description>&lt;p&gt;Kerberos should not have problems with the NATted solution as long as the appropriate ports (UDP and TCP 88) are open.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3280606" width="1" height="1"&gt;</description></item><item><title>re: DCs and Network Address Translation</title><link>http://blogs.technet.com/b/ad/archive/2009/04/22/dcs-and-network-address-translation.aspx#3269067</link><pubDate>Wed, 29 Jul 2009 16:09:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3269067</guid><dc:creator>msbrianp</dc:creator><description>&lt;p&gt;Does this potentially pose problems with Kerberos authentication through the NAT device to the DC in the NATed segment? &amp;nbsp; Good artical- thanks. &amp;nbsp;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3269067" width="1" height="1"&gt;</description></item><item><title>re: DCs and Network Address Translation</title><link>http://blogs.technet.com/b/ad/archive/2009/04/22/dcs-and-network-address-translation.aspx#3232295</link><pubDate>Wed, 29 Apr 2009 07:31:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3232295</guid><dc:creator>jansenet</dc:creator><description>&lt;p&gt;I had a client with that same issue about 3 years ago. &amp;nbsp;They ended up re-arranging the network and did an IP cutover, going away from using NAT'ing to fix the issues. &amp;nbsp;I have to say that this is the best breakdown of this specific issue that I have seen to date. &amp;nbsp;Keep up the good articles!&lt;/p&gt;
&lt;p&gt;Eric Jansen&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3232295" width="1" height="1"&gt;</description></item><item><title>re: DCs and Network Address Translation</title><link>http://blogs.technet.com/b/ad/archive/2009/04/22/dcs-and-network-address-translation.aspx#3229221</link><pubDate>Wed, 22 Apr 2009 17:11:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3229221</guid><dc:creator>wilfman</dc:creator><description>&lt;p&gt;Tim.&lt;/p&gt;
&lt;p&gt;Great article. &amp;nbsp;Will remember this for next time we come across this issue.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3229221" width="1" height="1"&gt;</description></item></channel></rss>