SOLUTION: "network name no longer available" with VPN, DMZ, routed subnets

From: Carol Chisholm (carol.lists@smalldomain.ch)
Date: 08/20/02


From: Carol Chisholm <carol.lists@smalldomain.ch>
Date: Tue, 20 Aug 2002 09:00:59 +0200


SOLUTION: "network name no longer available" with VPN, DMZ, routed
subnets
For problems joining domains, promoting servers and so on, over VPNs,
routers and with machines in separate subnets or in DMZs.

Apologies for cross posts, but I have spent ages on this and it seems
pretty obscure.

Look for fragmented UDP packets being rejected by the router or
firewall.

This behavior has been caused by fragmentation of UDP Kerberos
traffic.

RESOLUTION
To work around this network problem, it is possible to
make a registry modification on the failing server to force Kerberos
to
communicate over TCP instead of UDP.

This can be accomplished by doing the following:

1. If necessary, add a parameters key under
HKLM/SYSTEM/CCS/control/lsa/kerberos

2. Add a MaxPacketSize dword with a value of 1 to

HKLM/SYSTEM/CCS/control/lsa/kerberos/parameters.

3. Reboot the server.

Thanks to John who provided the answer and Jason who remembered it!

Carol Chisholm



Relevant Pages

  • Re: Best approach for broadcasting a notifivation to another progr
    ... I think that normally routers block all broadcasts by default, ... I have found that many admins will allow broadcasts between them (at least ... As for the Terminal server issue, I don't know how that would do. ... I have a customer that has two subnets joined by Cisco pix ...
    (microsoft.public.vb.general.discussion)
  • Re: DHCP and WINS
    ... >> Is there a way that the dhcp server automatic upfate a wins server ... since they don't rely on the browser service. ... > locations) because NetBios broadcasts are stopped at the routers. ... If you have mutliple offices or subnets in your building, ...
    (microsoft.public.win2000.networking)
  • Re: forward lookup
    ... If you are PINGing by NetBIOS names, you need a WINS server. ... not forwarded over the routers. ... If you ping by fully qualified domain ... > I've got two subnets in my domain: ...
    (microsoft.public.windows.server.networking)
  • RE: Anonymizing Packets yet ensuring 0 % packet loss
    ... IBM, SUN SOLARIS, CISCO & MICROSOFT ... Tor is an open network you can use for this - this is frowned upon by Tor ... exit server traffic and block them the minute they see probes/attacks from ... enumerate the services, administration subnets, department subnets, ...
    (Pen-Test)
  • Re: Groklaws "Bias" and the SCO DDoS Attack
    ... >routers, with port 80 redirected to a web server on the LAN side. ... I've also used Sonicwall DMZ ...
    (comp.unix.sco.misc)