<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Deep Dive Into DirectAccess – NAT64 and DNS64 In Action</title><link>http://blogs.technet.com/b/edgeaccessblog/archive/2009/09/08/deep-dive-into-directaccess-nat64-and-dns64-in-action.aspx</link><description>In the previous posts my colleague Ben provided an overview of Forefront UAG DirectAccess and its NAT64 and how it is different from NAT-PT . In this post I will show a step-by-step example of how UAG DirectAccess NAT64 and DNS64 work together to provide</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Deep Dive Into DirectAccess – NAT64 and DNS64 In Action</title><link>http://blogs.technet.com/b/edgeaccessblog/archive/2009/09/08/deep-dive-into-directaccess-nat64-and-dns64-in-action.aspx#3542618</link><pubDate>Wed, 26 Dec 2012 10:54:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3542618</guid><dc:creator>Westar</dc:creator><description>&lt;p&gt;If the IPV4 address is in DMZ, is there any special configurations needed to access this website using DirectAccess? I am able to access internal website successfully.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3542618" width="1" height="1"&gt;</description></item><item><title>re: Deep Dive Into DirectAccess – NAT64 and DNS64 In Action</title><link>http://blogs.technet.com/b/edgeaccessblog/archive/2009/09/08/deep-dive-into-directaccess-nat64-and-dns64-in-action.aspx#3485857</link><pubDate>Sat, 10 Mar 2012 06:46:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3485857</guid><dc:creator>yahya</dc:creator><description>&lt;p&gt;To All.&lt;/p&gt;
&lt;p&gt;How to i get this application???&lt;/p&gt;
&lt;p&gt;i need it.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3485857" width="1" height="1"&gt;</description></item><item><title>re: Deep Dive Into DirectAccess – NAT64 and DNS64 In Action</title><link>http://blogs.technet.com/b/edgeaccessblog/archive/2009/09/08/deep-dive-into-directaccess-nat64-and-dns64-in-action.aspx#3481659</link><pubDate>Fri, 17 Feb 2012 20:36:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3481659</guid><dc:creator>Dave Ryan</dc:creator><description>&lt;p&gt;Could an NT service using IPv4 on the DirectAccess Client be able to talk to a IPv4 application on the domain or would the application have to be re-written in IPv6?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3481659" width="1" height="1"&gt;</description></item><item><title>re: Deep Dive Into DirectAccess – NAT64 and DNS64 In Action</title><link>http://blogs.technet.com/b/edgeaccessblog/archive/2009/09/08/deep-dive-into-directaccess-nat64-and-dns64-in-action.aspx#3481540</link><pubDate>Fri, 17 Feb 2012 10:40:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3481540</guid><dc:creator>Boudewijn</dc:creator><description>&lt;p&gt;With DA hosted by UAG. Are you not able to ping or reach and IPv4 IP Address directly?&lt;/p&gt;
&lt;p&gt;(with this question I mean that you don&amp;#39;t use a DNS name)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3481540" width="1" height="1"&gt;</description></item><item><title>re: Deep Dive Into DirectAccess – NAT64 and DNS64 In Action</title><link>http://blogs.technet.com/b/edgeaccessblog/archive/2009/09/08/deep-dive-into-directaccess-nat64-and-dns64-in-action.aspx#3460353</link><pubDate>Thu, 20 Oct 2011 02:38:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3460353</guid><dc:creator>Mario</dc:creator><description>&lt;p&gt;If an ISATAP entry is not created in DNS, is it safe to assume that all requests will be resolved as NAT64 addresses?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3460353" width="1" height="1"&gt;</description></item><item><title>re: Deep Dive Into DirectAccess – NAT64 and DNS64 In Action</title><link>http://blogs.technet.com/b/edgeaccessblog/archive/2009/09/08/deep-dive-into-directaccess-nat64-and-dns64-in-action.aspx#3448482</link><pubDate>Mon, 22 Aug 2011 18:43:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3448482</guid><dc:creator>Patrick</dc:creator><description>&lt;p&gt;Thanks Tom!&lt;/p&gt;
&lt;p&gt;Does NAT64/DNS64 on UAG perform any caching? &amp;nbsp;We did a DR test recently where an IPv4 address had to be changed (It points to a non-IPv6 load balancer, so no AAAA record). &amp;nbsp;Even though an NSLookup instantly &amp;nbsp;replied with the correct IPv4 address, it seemed to take a while before DA started sending traffic to the new IPv4 address.&lt;/p&gt;
&lt;p&gt;If it does cache the IPv4 address, is there a way to configure the TTL, or manually flush the cache?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3448482" width="1" height="1"&gt;</description></item><item><title>re: Deep Dive Into DirectAccess – NAT64 and DNS64 In Action</title><link>http://blogs.technet.com/b/edgeaccessblog/archive/2009/09/08/deep-dive-into-directaccess-nat64-and-dns64-in-action.aspx#3414472</link><pubDate>Mon, 21 Mar 2011 13:26:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3414472</guid><dc:creator>Thomas W Shinder - MSFT</dc:creator><description>&lt;p&gt;Hi Arun,&lt;/p&gt;
&lt;p&gt;If you don&amp;#39;t use the UAG DNS64 service, the server won&amp;#39;t have a mapping for your IPv4 hosts on the intranet, and won&amp;#39;t be able to create the NAT64 address for the intranet host. You would never use an external DNS server to resolve internal host names in a DirectAccess scenario.&lt;/p&gt;
&lt;p&gt;HTH,&lt;/p&gt;
&lt;p&gt;Tom&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3414472" width="1" height="1"&gt;</description></item><item><title>re: Deep Dive Into DirectAccess – NAT64 and DNS64 In Action</title><link>http://blogs.technet.com/b/edgeaccessblog/archive/2009/09/08/deep-dive-into-directaccess-nat64-and-dns64-in-action.aspx#3391478</link><pubDate>Thu, 03 Mar 2011 07:13:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3391478</guid><dc:creator>Arun</dc:creator><description>&lt;p&gt;Thanx Tom.&lt;/p&gt;
&lt;p&gt;The DNS query from the client can be sent to any server. The client can be configured to used publicly available DNS servers instead of the DirectAccess DNS64. &lt;/p&gt;
&lt;p&gt;In such case, the pre-defined prefix may be different and NAT64 will see an an IPv6 packet from which it is not able to identify if the IPv6 contains a mapped IPv4 address. &lt;/p&gt;
&lt;p&gt;How do we handle such a case.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3391478" width="1" height="1"&gt;</description></item><item><title>re: Deep Dive Into DirectAccess – NAT64 and DNS64 In Action</title><link>http://blogs.technet.com/b/edgeaccessblog/archive/2009/09/08/deep-dive-into-directaccess-nat64-and-dns64-in-action.aspx#3378544</link><pubDate>Wed, 05 Jan 2011 16:14:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3378544</guid><dc:creator>Thomas W Shinder - MSFT</dc:creator><description>&lt;p&gt;Hi Arun,&lt;/p&gt;
&lt;p&gt;NAT64 works with DNS64. When the client sends a name query request, the DNS64 (which is a DNS proxy) services fowards the query to the DNS server. If the DNS server returns an IPv6 address (such as an ISATAP address) it will forward the IPv6 address to the DirectAccess client; if an IPv4 address were returned, the NAT64 service would convert the IPv4 address to an IPv6 address and return that to the DirectAccess client. The DirectAccess client then sends a request to that address, The NAT64 services on the UAG DirectAccess server sees the request to that IPv6 address and is aware that this address is mapped to an IPv4 address - it then NATs this to the IPv4 address forwards the connection to the IPv4 address of the destination host.&lt;/p&gt;
&lt;p&gt;HTH,&lt;/p&gt;
&lt;p&gt;Tom&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3378544" width="1" height="1"&gt;</description></item><item><title>re: Deep Dive Into DirectAccess – NAT64 and DNS64 In Action</title><link>http://blogs.technet.com/b/edgeaccessblog/archive/2009/09/08/deep-dive-into-directaccess-nat64-and-dns64-in-action.aspx#3378533</link><pubDate>Wed, 05 Jan 2011 15:41:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3378533</guid><dc:creator>Arun</dc:creator><description>&lt;p&gt;How does NAT64 know if the dst-address to which packet is sent is an IPv6 address or IPv6 address with embedded IPv4 addrs&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3378533" width="1" height="1"&gt;</description></item></channel></rss>