We are a state agency with a main office here, then about 45 smaller offices throughout the state.
The small 1 person offices connect back here via a web provider (ISP) and VPN client.
The rest connect back here using either a Cisco PIX 501 (4 of our older small offices) or a Cisco ASA5505 - and in either case, use LAN-to-LAN connections back to an Altega concentrator. The PIX and ASA devices BOTH serve as their offices DHCP provider/server. Those offices get their IP address and DNS server and WINS server settings from the DHCP services of the PIX or concentrator.
The issue:
Those here locally that get their DHCP from our DCs are in the appropriate reverse lookup zones.
Those that use the VPN client to connect back here get their DHCP address, etc. from the DCs here in this building as well. They are also all in the reverse lookup zones.
Those that use the PIX devices to get back here show up in the reverse lookup zones!
Now the kicker - those that use the ASA to get back here and get their addresses from the ASA DHCP are NOT registered in reverse lookup zones here!
If the computer has a STATIC IP address and manually assigned DNS and WINS settings, it WILL register back here.
So, anything that has either a STATIC assigned IP and DNS info registers, anything that gets DHCP assigned info from a server here registers, anything using the PIX for DHCP registers, but anything using an ASA AND getting a DHCP assignment from said ASA is NOT in the reverse lookup zones back here!
We are ALL so confused! Our senoir staff, even the folks at ITE (IT Enterprise) who are levels way above me "don't get it".
Ideas????
Microsoft said it's a Cisco issue, either the device or our configuration (or lack there-of) and the test they have run make me believe them. But then why does the PIX send that info back here and the ASA not? There are NO SPECIAL settings in the PX at all. In fact, the ASAs are setup almost exactly like the PIXs - we basically converted the PIX settings for the ASA.
AARRG - (can I say that here?)
Software/Hardware used:
ASKED:
April 10, 2009 3:30 PM
UPDATED:
April 16, 2009 2:45 PM