Jump to content

Recommended Posts

Posted

Hello, all..

 

My workplace relatively recently introduced DirectAccess in a fairly big way (blanket hit of all schools with WiFi).

We now have round about 2200 wireless laptops configured for use with DA.

 

Which is splendid. Except..

 

I've spotted a few issues which I'm hoping someone will confirm is not right (we've no basis for comparison, y'see).

 

FYI - the DirectAccess setup we have means that an IPV4 PC can't talk to a DA laptop either via IP or by FQDN.

And vice versa.

We have a list of servers which the DA laptops are permitted to talk to.

Oh, and they're Windows 7 Enterprise laptops.

 

 

PING

If I attempt to PING a laptop that's connected via DA, I get an unknown host error.

As in, it doesn't even attempt to resolve the IP address (be it the IPV6 or the IPV4 one).

This happens if I try the ping from a wired IPV4 workstation, or another DA laptop.

I don't mean I can't get a reply (suggesting the firewall is stopping PING replies).

I mean it doesn't recognise the host name.

 

Certificates

When the laptop is configured to be in the correct AD group and the OU which says it gets the necessary DA settings, it gets a machine certificate.

That certificate lasts a year.

My understanding is that the certificate should be able to renew itself OVER DIRECT ACCESS.

Currently, when it expires, we need to hook the laptop up WIRED to get a new year long cert.

 

SCCM PUSH

I'm assuming this is related to the lack of host name resolving..

We've recently installed an SCCM environment.

The server is currently pushing out the agent to any/all PCs which it can locate.

It does not push out to DirectAccess clients.

 

Any advice on any of the above would be gratefully received.

Even if it's so I can present the information to my Infrastructure bods to say "this bit SHOULD work".

 

Cheers,

Gerard

Posted
Why are you using DirectAccess for on-site laptops? It should be used off-premise, much like a VPN...

It is used for devices that are used on site AND taken off site. It automatically detects if it is on the LAN or not (through DNS) and adjusts. It is intended to give you an onsite 'experience' where ever you are.

 

Not yet got it working so can't be more help sorry.

Posted
It is used for devices that are used on site AND taken off site. It automatically detects if it is on the LAN or not (through DNS) and adjusts. It is intended to give you an onsite 'experience' where ever you are.

 

Not yet got it working so can't be more help sorry.

 

I understand that, but I doubt he has 2200 laptops going off site.

Posted (edited)

1. You will never get a response from a DA connected client unless you are pinging the IPv6 address from a "DirectAccess manage out" machine (Google it), so that's working as intended.

 

2. I'd argue there are probably some communication problem or a certificate template problem if your certificates aren't autorenewing over DA, our's do.

 

3. It will not push to DA clients unless you set your SCCM boundaries up (you need to add the DA IPv6 address space as a boundary) and set up a manage out address on the SCCM site servers.

 

Fundamentally DirectAccess relies on IPv6 connectivity between the laptop and the DA server (even if they are 6in4 tunneling or whatever), the DirectAccess server will then do the translation between your IPv6 DA clients and the IPv4 on-premise servers/services.

 

Also for 2,200 laptops I hope you a) have a redundant DA location server, b) multiple site entry points c) maybe even load balancing, otherwise you're not going to get a good DA experience.

Edited by Blue_Cookeh
Posted
1. You will never get a response from a DA connected client unless you are pinging the IPv6 address from a "DirectAccess manage out" machine (Google it), so that's working as intended.

 

I could understand not getting a REPLY, but it doesn't even recognise the host name.

As in, if I ping dalaptop01.school.domain from either an IPv4 wired or another DirectAccess laptop, it returns Ping request could not find host.

 

If PING replies (or outgoing) were blocked, I'd expect to see something like

Request timed out (as in, it's resolved the host name to an IP address but the send/reply is blocked)

 

2. I'd argue there are probably some communication problem or a certificate template problem if your certificates aren't autorenewing over DA, our's do.

 

Yep, that's what I thought.

 

Also for 2,200 laptops I hope you a) have a redundant DA location server, b) multiple site entry points c) maybe even load balancing, otherwise you're not going to get a good DA experience.

 

I'm on the desktop side, so I can't say for certain.

 

In answer to one of the above - we have the 2000-odd laptops spread across 35 schools.

Most Primary schools have about 60, some high schools have a few hundred.

 

I don't know why it was implemented this way, but that's what was implemented.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...